The Security Eunoia

Blogging about Security Auditing, IdM & Access Mgmt, Web App Security etc

Entries for the ‘Data Loss Prevention’ Category

UK Prime Minister’s medical records breached

The UK Prime Minister’s medical records have been breached in a series of high profile ‘data violations’ involving UK politicians and others, the Sunday mail reports. Last week UK cabinet minister Jack Straw’s hotmail account was pwned by criminals trying to hoodwink the minister’s ‘friends’ into sending them money.

Comments (1)

Online payment site hijacked by crime gang

The Register has reported that an online payment service mycheckfree.com has lost control of at least two of its domains to a crime gang believed to be based in Eastern Europe.
Possible explanation?
It’s also unclear how the culprits managed to hijack the domains. While security experts say DNS poisoning wasn’t out of the question, the more [...]

Leave a Comment

Secunia Releases Personal Software Inspector v1.0

Secunia, a vulnerability management firm, has given home users an opportunity to improve their security with its release of Personal Software Inspector (PSI) version 1.0. Released for Windows, PSI aims to raise the security bar by checking and updating all the software installed on the home PC with the latest security patches. Download your copy [...]

Leave a Comment

No Crunch in the Underground Economy - Symantec reports

Symantec has published a survey - Underground Economy - detailing the activities of cyber criminals who through astute business models have managed to rake in hundreds of millions of dollars in a year. The cost to victims of these activities easily runs into billions of dollars. What do they sell?

Leave a Comment

Breach! Breach! Breach! - Now its Obama’s phone records

After many reported vulnerabilities and poor security practices on Obama’s web sites such as change.gov and barackobama.com, CNN reports that Obama’s phone records have also been improperly accessed by Verizon employees NOT authorised to do so.
The report quotes the President of Verizon Wireless saying “the personal wireless account of President-elect Barack Obama had been accessed [...]

Leave a Comment

What is security monitoring?

So what is security monitoring? It could be any of security (information, event, information & event) monitoring. Whatever name you choose to call it I’m referring to any kind of monitoring with the help of software and with the primary aim of detecting security policy violations possibly before it is too late to act. With any breach of security policy, there are cyber observables and an outcome.

Leave a Comment

Get out of jail free card

This prison inmate manages to exploit a vulnerability in a legal search software to obtain the username and password to the prison management system in addition to stealing inmates personal records. I wonder what the prison management system could be used for! e.g. could it be used to set prisoner release dates, move people to [...]

Leave a Comment