![]() |
Your Enterprise Database Security Strategy 2010 an Independent Analyst Report by Forrester Research Inc. Download here |
Ex-TSA Employee Indicted For Tampering With Database Of Terrorist Suspects
Case serves as a wake-up call about the potential dangers of malicious insider access to sensitive data
Voluntary Breach Disclosure Rare But Valuable
Most organizations won't go public about an attack unless they have to, but security experts say there are ways to collaborate without being stigmatized
Product Watch: Gemalto Rolls Out Secure Online Banking On A Stick
USB thumb drive helps protect against man-in-the middle attacks
New Massachusetts Data Privacy Law Adds Incentive For Strong Database Security
Massachusetts Data Privacy Law went into effect on March 1, focuses on prevention
Securing The Link Between Web Applications And Databases
Are insecure Web applications threatening the security of your database? New report outlines steps that could help reduce that threat
Database Security Metrics Project Needs Community Input
Project Quant to offer framework and a way to measure time, tools, and manpower for locking down databases
Comcast Goes DNSSEC, OpenDNS Adopts Alternative DNS Security
DNS provider OpenDNS selects DNSCurve over DNSSEC, but experts say the two technologies could eventually play together
Criminals Hide Payment-Card Skimmers Inside Gas Station Pumps
Wave of recent bank-card skimming incidents demonstrate how sophisticated the scam has become
SQL Injections Top Attack Statistics
Cybercriminals are increasingly using automated SQL injection attacks powered by botnets to hit vulnerable systems
Core Integrates Its Penetration Testing Product With Metasploit
Next version of Core Impact Pro commercial tool will work in concert with Metasploit
Shell Employee Directory Leaked, Allegedly By Activist Workers
Oil company acknowledges leak, but says it isn't sure current employees did the deed
Workarounds Abound While Oracle Scrambles To Patch Zero-Day Flaw
How to defend against attacks exploiting new privilege-escalation vulnerability in Oracle 10g, 11g databases
Product Watch: New Tool Automatically Examines Suspicious Code In Memory
HBGary Responder Professional 2.0 analyzed malware behavior in the Operation Aurora in five minutes
Database Account-Provisioning Errors A Major Cause Of Breaches
Database accounts are often managed manually -- if at all
Hospitality Industry Hit Hardest By Hacks
Trustwave report on data breach investigations shows hotels were breached more than financial institutions last year, and nearly all attacks were after payment-card data
Black Hat DC: Researchers Reveal Connection String 'Pollution' Attack
Tool released tests for so-called Connection String Parameter Pollution (CSPP) attack
Hack On Iowa Racing/Gaming Unit Jeopardizes Data Of 80,000 Employees
Hacked server contained casino employee information, state officials say
Computer Theft Adds Up To $7 Million For Blue Cross Of Tennessee
October break-in nets 57 computers for thieves -- and major headaches for healthcare firm
Report: More Than 560,000 Websites Infected In Q4
Web attacks get stealthier and more efficient; 5.5 million Web pages discovered to be infected
Flaws In The 'Aurora' Attacks
Security experts say targeted attacks could have been much worse, point out strategic errors made by the attackers
New Details On Targeted Attacks On Google, Others, Trickle Out
Meanwhile, Microsoft releases emergency patch for IE exploit used in the attacks
Enterprise Data Taken To The Cleaners -- Literally
Study of 100 U.K. dry cleaners finds more than 4,500 storage devices left in clothes in one year
Spear-Phishing Attacks Out Of China Targeted Source Code, Intellectual Property
Attackers used intelligence, custom malware to access Google, Adobe, and other U.S. companies' systems
U.S. Army Website Hacked
SQL injection, plain-text passwords leave databases exposed
Don't Wait To Lock Down DB2
Existing access control, trusted context features in DB2 are not widely deployed
Intel Website Hacked With SQL Injection
Hacker reveals major hole that exposes personal passport information on channel partner events Website
Social Networking Developer Site Database Hacked In SQL Injection Attack
32 million accounts exposed, Webmail accounts could be at risk as well
Databases In Peril
New report finds database security 'crisis' as many cash-strapped enterprises can't pass database compliance audits
Data Masking Helps Keep Live Data From Peeking Out, Experts Say
Emerging technology may prevent shared and test database content from appearing where it shouldn't
New Report Helps Enterprises Choose Their Own DAM Products
Study of database activity monitoring offers insights on how DAM products work -- and how to choose between them
Product Watch: IBM Buys Database Security Firm Guardium
Big Blue plans to integrate Guardium's database activity monitoring technology into its information management software products
T-Mobile: Employee Data Theft Leads To U.K.'s Largest Data Breach
Employee sold millions of customer records to data brokers, reports say
Thwarting SQL Injection Threats
New Dark Reading report explores what database developers and database administrators can do about the pervasive SQL injection attack
New Honeypot Mimics The Web Vulnerabilities Attackers Want To Exploit
New open-source Honeynet Project tool toys with attackers by dynamically emulating apps with the types of bugs they're looking for
FTC Orders ChoicePoint To Pay $275,000 For 2008 Data Breach
Agency alleges that data broker didn't do enough to protect information after massive breach in 2005
Six Steps Toward Better Database Security Compliance
Discovery, assessment, and monitoring play key roles in compliance efforts, experts say
Databases' Most Serious Vulnerability: Authorized Users
New Dark Reading report outlines threats posed to databases by end users -- and how to protect your data
New Trojan Evades Banks' Anti-Fraud Systems
'URLZone' calculates how much money to steal from a victim's account without raising suspicion
PCI DSS Update Could Include Virtualization Security
PCI Virtualization Special Interest Group (SIG) is drafting guidelines and a mapping tool for applying PCI to virtualized systems
Couple's Lawsuit Against Bank Over Breach To Move Forward
Case raises questions about banks' liability in breach of customers' online accounts
Smart Card Alliance: End-To-End Encryption Won't Stop Credit-Card Fraud
Industry association proposes contactless chip cards, says end-to-end encryption isn't enough
Accused Superhacker Pleads Guilty
Gonzalez admits helping to lead gang that stole some 40 million credit and debit card numbers
Hacker Hits RBS WorldPay Systems Database
Romanian hacker says he discovered a SQL injection flaw on a WorldPay application, but RBS says no merchant or cardholder data was compromised
DuPont Alleges Second Insider Breach In Two Years
Chemical giant claims former employee was headed to China with company secrets
Flaw In Sears Website Left Database Open To Attack
Business-logic flaw in Sears.com Web application could have let hackers brute-force attack the retailer's gift card database
Hacker Ring Tied To Major Breaches Just Tip Of The Iceberg
TJX-Heartland attacker and cohorts also reportedly hacked ATM machines in 7-Elevens, but their wide net is likely just one of many
Tech Insight: SQL Injection Demystified
Attackers are using the old standby SQL injection en masse -- a look at the attack and how to protect your applications from it
Eight Indicted For $22M Identity Theft Scam Against AT&T, T-Mobile
Defendants allegedly hijacked customers' identities to steal millions of dollars in wireless gear
Alleged TJX Hacker Indicted For Heartland, Hannaford Hacks
Albert "Segvec" Gonzalez may have played role in many other data thefts as well, prosecutors say
National Retail Federation Poll: Small Retailers Struggling To Understand PCI
Nearly 86 percent are familiar with PCI, but nearly half can't demonstrate their compliance with the payment card standard
Database Administrators Playing Increasingly Crucial Role In Security
Long left out of the security picture, DBAs now find themselves performing key tasks in the enterprise
Nine U.K. Workers Fired For Tapping Into National Identity Database
Thirty-four U.K. government employees accessed Customer Information System for personal reasons, report says
Researcher Uncovers Massive, Sophisticated Trojan Targeting Top Businesses
Trojan may already have infected hundreds of thousands of PCs, botnet expert says
Nearly Half Of Companies Lack A Formal Patch Management Process
Microsoft-sponsored Project Quant survey finds patch management expensive, immature
Network Solutions Breached For 574,000 E-Commerce Account Records
Popular domain services provider says it doesn't know how rogue malware was planted on its servers
Healthcare Industry Weak In Security And Worried About Insider Threats
New Deloitte survey says healthcare and life sciences companies need to 'catch up' in security
Making A Federal Case About Sharing Security Data
Department of Energy initiative offers 'Federated Model' for exchanging, diagnosing security information among trusted partners
More Money, More Web Scams
At Black Hat USA, WhiteHat Security researchers to highlight more and bigger-dollar hacks that don't use malware or security bugs
Database Of Stolen Identities Contains More Than 40 Million Names
Lucid Intelligence lets users search against more than 120 million stolen records to see if their identities are at risk
Brothers In U.K. Convicted In Massive Credit Card Data Scam
Identity theft operation highlights need to protect card data at the source, experts say
PCI Group Spells Out Guidelines For Deploying PCI-Compliant WiFi
'Operator's guide' provides security recommendations for merchants, auditors
Report: CEOs, CIOs Still On Different Security Pages
Many top executives don't recognize key security issues, study says
Report: Cybercriminals Take Lessons From Business School
Online bad guys building specialized businesses along with sophisticated marketing and distribution strategies, Cisco study says
Report: Encryption Adoption Steadily Growing
While more organizations consider encryption as an overall strategic security solution, breaches keep rising, according to Ponemon Institute
Tech Insight: It's About DAM Time
Given today's threats to data from targeted attacks and unsavory insiders, it's no longer a question of whether or not to adopt database activity monitoring
IBM Researchers Unveil New Data-Masking Technology
'MAGEN' technology automatically shields sensitive customer, patient data
Oracle Report: Consumers Fickle About Ecommerce Security Controls
Nearly one-third of U.K.'s online shoppers don't trust online security measures, but most don't want additional controls if it affects ease and speed of transactions
Tech Insight: Database Security -- The First Three Steps
Protecting sensitive data means locating and enumerating the information in your databases -- and finding the right method to secure it
Massachusetts Worker Accused Of Using Database In ID Theft Scheme
Employee at medical cost management firm allegedly used doctors' personal information to obtain credit cards
Oracle Users Struggle With Patch Management
Despite new tools that speed deployment, many administrators are still far behind
New Injection Attack Compromises More Than 40,000 Websites
'Nineball' exploit is distinct from Gumblar, Beladen, researchers say
Despite High Value Of Information, Many Companies Lag On Database Security
Administrators often fail to patch promptly, configure securely
Report: No Magic Bullet For Database, Server Security
New Forrester report says encryption, data monitoring technologies key tools for now
More Than 530,000 Patients Notified In Data Ransom Scare
"Kidnapper" who held data for ransom still at large, Virginia authorities say
NSA-Funded 'Cauldron' Tool Goes Commercial
Vulnerability analysis tool aggregates, correlates, and visually maps attack patterns and possibilities
Report: Growth Of Digital Data Could Overwhelm Security
IDC "Digital Universe" study says volume of data is vastly outgrowing the resources available to protect it
Protecting Databases from Web Applications
Most external hacks of databases occur because of flaws in Web applications that link to those databases. Yet, enterprises are increasingly exposing their most valuable data to these outward-facing interfaces. In this Dark Reading Tech Center report, we'll discuss how security teams, database administrators and application developers can work together to improve the defenses of both front-end Web applications and back-end databases to prevent these attacks from succeeding, and offer a look at the most frequent Web-borne database attacks.
Database Activity Monitoring: Emerging Technology Keeps Tabs on Assets
You can read about the consequences of not protecting critical data in the daily headlines. In response, security-conscious organizations are tackling the complexities involved in effectively monitoring their databases for potential leaks and compromises. Fortunately, an emerging class of software is stepping up to help. Here’s what enterprises need to know about selecting, deploying, and managing DAM technology.
SQL Injection: A Major Threat to Data Security
Of all the attacks taking place on Web sites across the Internet today, SQL injection is the most popular for cybercriminals trying to hack their way into corporate data stores. But for such a pervasive threat, there is still little understanding within the development and database communities about what constitutes a SQL injection vulnerability, how attacks against a SQL injection bug work, and how to mitigate the risk. We examine how these exploits work and what you can do to stop them.
Protecting Your Databases From Careless End Users
While much attention is paid to outside attackers' efforts to crack enterprise databases, IT organizations often overlook an even greater threat: end users. Ignorance and disregard of company security policies may lead employees to expose their organizations' databases to compromise, often without even knowing that they’re doing so. In this report, we offer advice on how to educate users on database security, and some common-sense recommendations on how to limit the damage.
A Database Administrator's Guide to Security
While most security pros have become painfully aware of the threats posed to their organizations' databases, many of those who create and maintain the databases still don't fully understand the danger. This "security primer" is designed to open the eyes of the DBA to the risks posed by poor database security – and to current "best practices" that can help prevent those risks from becoming reality.
Why Your Databases Are Vulnerable To Attack - And What You Can Do About It
Most of an enterprise’s most sensitive and valuable information resides in databases. Yet, in many organizations, database security is often neglected, misunderstood, or even ignored. In this report, we discover why databases have become one of the most popular targets for hackers - and how everyday mistakes in database administration contribute to these attacks. We also offer some advice on what your organization can do to protect your most critical data - and to stop hackers in their tracks.
| Sponsored by: | ![]() |
HOWTO Secure and Audit Oracle 10g and 11g
Read the "Hardening Your Database" chapter from the 454-page book "HOWTO Secure and Audit Oracle 10g and 11g" and learn how to navigate the many security options within Oracle (authored by database security expert and Guardium CTO, Ron Ben Natan, Ph.D.)
HOWTO Monitor Database Activity
Read the "Database Activity Monitoring (DAM)" chapter from "HOWTO Secure and Audit Oracle 10g and 11g" (CRC Press, 2009) and learn how to leverage DAM to prevent cyberattacks, monitor privileged users and track access to sensitive data.
8 Steps to Holistic Database Security
Get the 8 essential best practices for a holistic approach to both safeguarding databases and achieving compliance with key regulations such as SOX, PCI-DSS, NIST 800-53 and data protection laws.
Essential Steps to Implementing Database Security and Auditing
Learn best practices and specific tips for effectively securing Oracle, SQL Server, DB2, MySQL and Sybase environments, including tracking security vulnerabilities, the anatomy of buffer overflow vulnerabilities and database auditing.
Databases at Risk: Current State of Database Security (ESG Research)
This recently published ESG report analyzes the current state of database security -- concluding it depends upon too many manual processes -- and also offers concrete steps to improve database security across the enterprise.