Data Broker LexisNexis said Personal Data of 310, 000 U.S. citizes feared stolenApril 12th, 2005 An investigation by the firm's Anglo-Dutch parent Reed Elsevier determined that its databases had been fraudulently breached 59 times using stolen passwords, leading to the possible theft of personal information such as addresses and Social Security numbers. This is the second biggest breach after Bank of America incident.
Major ID theft uncovered, affecting thousands of CaliforniansFebruary 17th, 2005 ChoicePoint is working with the California authorities on this, assuming that the impact is on Californian residents only. However security experts diasgree.
Privacy is Easy to Breach - Exposing an Undercover CIA OperativeJuly 16th, 2005 After Karl Rove, one of Jr. Bush's most trusted advisers, publicly outed an undercover CIA operative, David Lazarus of SF Gate takes it a step further by uncovering the full details of the operative, including her address, personally identifiable information and complete with a detailed map of her home.
Critical WordPress Security Defect Found and Fixed in 2.0.7January 11th, 2007 While WordPress 2.0.6 is still hot a serious security defect (SQL injection attack) was found and fixed in WordPress 2.0.7, which is currently available as RC1 (release candidate 1). The key defects fixed are:
Security defect
Worked around a PHP bug for PHP 4.x less than 4.4.3 and PHP 5.x less than 5.1.4 with register_globals ON that could potentially lead to SQL injection and other security breaches.
Hacking the 'smart grid': New generations of meters could be vulnerable to attackJuly 31st, 2009 Security researchers offer caution on smart gridsLAS VEGAS β The race to build a "smarter" electrical grid could have a dark side. Security experts are starting to show the dangers of equipping homes and businesses with new meters that enable two-way communication with utilities.
Security Software: What Buyers Look for...October 12th, 2005 According to Forrester:
The majority of enterprises worry most about reliability when acquiring security technologies β thus, only 19% experience shaky deployments. In contrast, just 13% consider cost a top priority when buying, which means that more than one-third suffer from implementation sticker shock.
Is PHP Secure?July 8th, 2005 After recent reports of several critical security vulnerabilities of PHP based software. I decided to take a closer look at the current state of security with PHP based products.
WordPress 2.0.4 Security Update ReleasedJuly 31st, 2006 WordPress 2.0.4 is available for download. This release contains several important security fixes, so itβs recommended upgrade for all users.
WordPress Wins Pwnie Award for Mass 0wnage (For Many Many Security Vulnerabilities)August 7th, 2008 WordPress wins the dubious distinction of Mass 0wnage Pwnie Award for an unbelievable number of WordPress vulnerabilities, over 140 as of today. It seems like hardly a week goes by without a new vulnerability in WordPress or one of its many plugins.
Free Sun Security Administrator Certification ExaminationJune 26th, 2006 Sun Certified Security Administrator for Solaris 10 OS (311-303)
If you are an expert security administrator, this is your golden opportunity to get certified for free by taking Solaris 10 Sun Certified Security Administrator exam. Sun beta exams count towards official Security Certification.
Pligg (Digg Clone) Releases Security Update 9.9.5July 31st, 2008 Pligg is a popular Digg clone. This week has been a stressful week for many Pliggers due to a security vulnerability discovered and exploited by a few hackers.
Generous Microsoft unveils new security software, but remains a miser stillJune 24th, 2009 SAN FRANCISCO - Hoping to dispel fears about the vulnerability of Windows to viruses and other malware, Microsoft Tuesday released a trial version of a new free security package called Microsoft Security Essentials. The software is designed to replace the Windows Defender tool that Microsoft released in 2007, but which was widely derided as being inadequate to protect computers from the constant and ever-evolving threats posed by hackers.
Reuter's Admits Doctoring (Photoshopped) Beirut Photographs, Fires Photographer Adnan HajjAugust 7th, 2006 Reuters withdrew all 920 photographs by a freelance Lebanese photographer from its database on Monday after an urgent review of his work showed he had altered two images from the conflict between Israel and the armed group Hizbollah. Global Picture Editor Tom Szlukovenyi called the measure precautionary but said the fact that two of the images by photographer Adnan Hajj had been manipulated undermined trust in his entire body of work.
Microsoft to release full version of free Security Essentials antivirus software for PCsSeptember 30th, 2009 Microsoft to release free antivirus PC softwareREDMOND, Wash. β Microsoft Corp.
Java Application Security Through Static AnalysisJune 28th, 2008 Extendable (by plugins, ...) Static Analysis tools like FindBugs can enhance the security of your Java applications (web as well as standalone or client-servers applications) in several significant ways. Enforcing security policy compliance
Security policies are espoused by security experts such as OWASP and mandated for compliance by many regulations such as Sarbanes-Oxley that require organizations to demonstrate they have done "due diligence" in safeguarding application security and information privacy.