Iranians faced mass man-in-the-middle on August 28
On 28 August Iranian citizens were subjected to a far reaching cyber snooping operation made possible by an attack on Dutch certificate authority DigiNotar.
On 28 August Iranian citizens were subjected to a far reaching cyber snooping operation made possible by an attack on Dutch certificate authority DigiNotar.
The impact of the breach of Dutch Secure Sockets Layer (SSL) certificate authority (CA) DigiNotar has widened as Dutch authorities confirm its own certificate program was compromised in the attack, likely meaning a massive clean up job for its websites.
Besides the fraudulent security certificates Dutch authority DigiNotar issued for Google.com, more were made for Yahoo.com, Mozilla.org, torproject.org, wordpress.org and an Iranian blogging platform, Baladin, according to a Dutch report.
Self-exiled, gun-loving ex-Anon, who goes by the name SparkyBlaze on Twitter, claims that skilled liars are the number one concern for information security.
Big business and government need to invest in data forensics and skills if they intend on fending off targeted attacks, according to analyst firm Gartner.
WikiLeaks made public thousands of US diplomatic cables on Wednesday hours after its Californian DNS host was ordered to hand to authorities everything it had on Julian Assange and WikiLeaks.
A former US Department of Health purchasing agent who claimed to be a victim of identity theft faces 10 years jail after pleading guilty to stealing $114,000 of government funds to purchase goods on Amazon.
The inability for network defenders to tell between a human-led attack and one that was led by automated malware is crucial to defending against advanced persistent threats (APTs), according to US security firm, HB Gary.
Fujitsu has released a new tablet and mobile security browser aimed at scrubbing the oft-lost devices of valuable data.
Recent efforts by Microsoft and law enforcement to take down the biggest spamming botnets may have helped fight pharmaceutical companies but they have had little effect on overall spam levels.
Symantec believes animal rights protestors against the “Dog Wars” app for Android were behind a fake version that has been laced with a Trojan.
Besides humans that don't change default passwords, the lowest hanging fruit are embedded Linux devices in routers.
Despite Google’s efforts to bolster internal privacy initiatives after its Street View fiasco, there was still room for improvement, according to the UK’s Information Commissioner.
Google has added virtual private network (VPN) and secure WiFi support in its latest stable Chrome OS release for its pay-as-you-go laptops.
Multi-tenant cloud providers might promise greater resiliency, ‘five nines’ uptime and better security than some in-house managed infrastructure, but organisations would be wise not to assume the provider has covered all bases.