Data breaches are the stuff of nightmares, but if you want to manage your IT environment effectively, you have to be prepared for the worst. Most companies find out their data has leaked when a third party reports it, but according to the 2010 Verizon Data Breach Investigations Report, most companies have evidence of the break in their log files. Experts suggest that you pull transaction logs, OS records, and authentication logs for the servers or devices that were affected. Pinpointing the anomalies will help you plug the hole, investigate the crime, figure out what was stolen, and prevent it from happening again.
– Video Content.
Posts Tagged ‘breach’
Damage Control After a Security Breach
Online Trust Alliance Outlines Data Breach Guide
The guide recommends completing a privacy and security audit of all data collection activities, including cloud services. – The Online Trust Alliance, a nonprofit organization
representing the Internet ecosystem, announced the release of the quot;2011
Data Breach Incident Readiness Guide, quot; outlining key questions and
recommendations to help businesses with breach prevention and incident
management. In the wake …
Honda Data Breach Highlights Need to Set Strong Cloud Security Policies
In light of recent data breaches, including a December 2010 incident which affected 2.2 million Honda customers, IT managers need to limit what data is actually shared with cloud service providers. – Corporations partnering with cloud service providers need to
think carefully about what data is being shared to adequately protect consumer
privacy, according to security experts.
As companies outsource various business functions, which can
range from e-mail marketing to e-discovery and e-mail a…
Trapster Notifies Millions After Breach
Trapster is telling registered users to change their passwords due to an attack. – Trapster.com, creator of a
popular mobile application that warns users about speed traps, notified
users this week that their passwords may have been exposed due to an
attack.
The company released few
details about the incident. In an e-mail, the company said it understood how
the attack occ…
Hacked Laptop Causes Data Breach at Pentagon Federal Credit Union
Current and former members of the U.S. military were issued new bank account numbers and credit cards after attackers accessed a database containing bank account information at the Pentagons credit union. – An infected laptop was used to access the systems at the
Pentagons credit union, exposing the financial records of the members of the
United States military, according to a Kaspersky Lab report.
The Pentagon Federal Credit Union notified the New Hampshire
Attorney General of the breach, and said…
Microsoft Notifies BPOS Cloud Customers of Breach
Microsoft has notified all the customers affected by a configuration error that impacted the company’s cloud-based Business Productivity Online Suite and exposed corporate data. – A configuration error recently exposed corporate data belonging to
customers of Microsofts cloud-based Business Productivity Online Suite.
BPOS is a set of messaging and collaboration tools that
includes Microsoft Exchange Online, Microsoft
SharePoint Online, Microsoft Office Communications O…
Gawker Revamps Security After Breach
A Gawker Media memo outlines changes meant to bolster security in the wake of the recent attack. – Gawker Media has implemented a number of changes to tighten security,
according to a staff memo posted online on a Poynter Institute blog.
The changes follow a recent hack that compromised user passwords and corporate
communications. Gawker did not respond to a request for comment on the memo,…
Data Breach Prompts Indiana to Sue Health Insurer WellPoint
Indiana is suing health insurer WellPoint for $300,000 in damages from a data breach involving health care applicants. – Indiana Attorney General Greg Zoeller has filed
a lawsuit against insurance company WellPoint for delaying notification
of a data breach to the AG’s office and to the more than 32,000
customers in Indiana affected.
The suit claims that WellPoint violated two
Indiana notification laws with each …
Pirate Bay in court again over copyright breach
The operators of Pirate Bay, the world’s biggest free file-sharing website, are back in court to appeal against their conviction for breaching copyright laws.
A court in Stockholm found the group guilty last year of being accessories to copyright violations.
Sinwa unit granted leave by the Court of Appeal to act against JV partner for breach of …
Mainboard-listed logistics player, Sinwa, says the Court of Appeal has allowed an appeal by its subsidiary, Sinwa SS (HK) Co, and granted leave for the latter to start a derivative action in the name of Nordic International Limited (NIL) against Morten Innhaug (Morten) for breaches of fiduciary duties.
NIL is a joint venture between Sinwa and Morten. The breaches of fiduciary duties arose from a purported assignment of a 2D seismic survey vessel to an entity controlled by Morten.
AIA defeats Singaporean policyholder’s breach of contract claim
American International Assurance Co., won dismissal of a lawsuit by a Singapore policyholder who sought $1.95 million for breach of contract.
Singapore High Court Judge Tan Lee Meng upheld an earlier dismissal and struck out another claim by Zhu Yong Zhen who also alleged that her former lawyer colluded with the insurer against her, according to a ruling released publicly today.
Defense Department Confirms Critical Cyber-attack
A Defense Department official discusses details of a formerly classified cyber-attack that he described as the worst breach of U.S. military computers in history. – A senior Pentagon official has revealed details of a previously classified malware
attack he declared quot;the most significant breach of U.S.
military computers ever. quot;
In an article
for Foreign Affairs, Deputy Defense Secretary William J. Lynn III writes
that in 2008 a flash drive beli…
“Kosovo UDI not in breach of intl. law”
The International Court of Justice (ICJ) today announced its advisory opinion on the legality of the Kosovo’s unilateral independence proclamation. “International law does not have an active provision that limits independence declarations, therefore Kosovo’s declaration of independence is not in breach of international law,” the court president, Hisashi Owada of Japan, said.
Google WiFi Privacy Breach Challenged by 38 States
Connecticut Attorney General Richard Blumenthal is leading 38 states in an investigation into Google’s WiFi data collection, which was done with Street View cars. He will sue if he doesn’t receive answers from Google. –
Thirty eight states led by Connecticut Attorney General
Richard Blumenthal July 21 asked Google whether it had tested its Street View
software was intended to collect data from unsecured wireless computer
networks.
Blumenthal, who has aggressively defended Connecticut against …
Trustwave to Purchase Breach Security
Trustwave has purchased Breach Security. As a matter of fact, the price of the deal was not disclosed. Such an acquisition will bring Web application firewall of Breach Security as well as enterprise security tools of Trustwave together. Despite the acquisition, Tristwave is going to offer as well as provide support for the Web application [...]
Trustwave Buys Breach Security for Web Application Firewall
Trustwave acquired Breach Security for its web application firewall business, and is planning to integrate the technology into its application security suite. – Trustwave has acquired web application firewall provider Breach Security.
The deal, made for an undisclosed sum, will allow Trustwave to
integrate Breach Securitys Web app firewall technology into its
existing application security suite.
Breach Securitys WebDefend application firewall appliance,…
FBI Nabs iPad Hacker Allegedly Involved in Security Breach
The FBI has taken into custody a hacker who may be involved in the AT&T security breach that exposed the names of more than 100,000 Apple iPad 3G users, including high-profile government officials. – The FBI announced it detained a member
of a group of computer programmers allegedly involved in the Apple iPad
3G security breach
that exposed the identities of more than 100,000 iPad users, including
celebrities and top government officials. The breach occurred through
an exploit of AT amp;Ts …
ATandT Security Breach May Blight Business Use for the IPad
Goatse Security exploited a security hole on AT&T’s Website that enabled it to access the e-mail addresses of 114,000 owners of iPad 3G devices. The Federal Bureau of Investigation has opened an inquiry. That could cloud what was a previously fine forecast for the adoption of the tablets among businesses. Researchers at Citrix last month said 84 percent of 494 customers surveyed said they would allow their employees to use their personal iPads for work. Analysts discuss the various use cases for the iPad in businesses. – It’s too early to gauge what sort of hit the iPad will take among
enterprises and business leaders who previously believed Apple’s iPad was a
dandy device for corporate road warriors.
Goatse Security exploited a security hole on AT amp;T’s Website that enabled
it to access the e-mail addresses o…
Probe on leak of e-mail security breach begins
The Federal Bureau of Investigation has started probing the security beach that happened recently in AT&T Inc’s wireless network. A few days this network had revealed many email address of the users of Apple Inc’s iPad 3G. ;
FBI spokeswoman Lindsay Godwin said yesterday, ‘The FBI is aware of these possible computer intrusions and has [...]
ATandT Breach Could Reach Further than Thought
The AT&T security breach that exposed some Apple iPad owners’ e-mail addresses could help attackers more effectively launch a technically difficult attack known as IMSI catching, researchers tell eWEEK. – The security
breach at AT amp;T that exposed the e-mail addresses of a reported 114,000
owners of the iPad with Wi-Fi + 3G could potentially impact privacy
more than was initially thought.
Two security researchers told eWEEK that the ICCIDs (integrated circuit card
identifiers) of iPad own…



