Welcome Guest. | Log In | Register | Membership Benefits

All Privacy Stories

Layered Tech Becomes First Hosting And Cloud Provider Offers Compliance Guarantee

    February 16, 2012
Company is adding an SLA so that all of its compliance services are guaranteed to pass 100 percent of every audit or assessment

Symantec Control Compliance Suite 11 Release

    February 14, 2012
Symantec Control Compliance Suite 11 features the new Control Compliance Suite Risk Manager module

ID Experts Announces New Breach Product

    February 14, 2012
RADAR 2.0 meets federal and state risk assessment and reporting requirements for privacy, security, and data breach incidents

SIA Comments To FTC On Benefits Of Facial Recognition Technology

    February 08, 2012
SIA addressed when privacy could be a concern with facial recognition

Zappos, Amazon Sued Over Data Breach

    January 23, 2012
Lawsuit against shoe retailer alleges security negligence, seeks millions in compensatory and exemplary damages

Symantec Announces Intelligent Information Governance To Mitigate Risks And Free Information

    January 17, 2012
In addition, Symantec also announced the acquisition of LiveOffice

Free PCI Compliance Task List Provides Structure To Help Maintain PCI Security Standards

    January 11, 2012
Free whitepaper from KSC Enterprises can help ID deficiencies in existing process

2012 Ponemon Report On Trends In Security Of Data Recovery

    January 10, 2012
Eighty-seven percent of respondents experienced a data breach in the past two years

Guardian Analytics Releases Anomaly Detection Toolkit Inbox

    January 10, 2012
White paper, video and case studies illustrate how anomaly detection prevents millions in fraud loss

Stratfor Taps CSID To Protect Identities Breached In Cyberattack

    December 29, 2011
Attacks resulted in the unauthorized disclosure of personal information

Anonymous Nabs 50,000 Credit Card Numbers From Security Think Tank

    December 27, 2011
Hacktivist group Anonymous attacks private security think tank Stratfor, makes off with 50,000 credit card numbers, 44,000 passwords

New Tokenization White Paper Answers Merchant Questions On PCI DSS Guidelines And Scope Reduction

    December 22, 2011
Paper provides practical guidance to merchants on how to use tokenization to reduce scope

Nearly 2 Million Users Affected By New Breach At Square Enix

    December 19, 2011
Japanese gaming giant Square Enix is hacked for the second time this year

FTC Investigating Carrier IQ's Data-Collection Practices

    December 15, 2011
Carrier IQ's initial failure to fully detail what its software did, and why, had led many to question whether its software might be breaking wiretap or privacy laws

Personal Data Of 60,000 Telstra Customers Exposed To Web

    December 12, 2011
Australian telecommunications giant Telstra says it is "investigating" proprietary customer lists found with simple browser search

Investor Lyceum Capital Acquires Clearswift

    November 29, 2011
Clearswift’s products manage inbound threats, data loss prevention, Web access policies, and compliance

More Than 13 Million Users' Data At Risk Following Hack Of Korean Gaming Firm

    November 28, 2011
Nexon says hack of popular Korean online game Maple Story included IDs and passwords of users, but no financial data

RockYou Lawsuit Settlement Leaves Question Marks On Breach Liability

    November 23, 2011
Data breach lawsuite settlement against RockYou is small, but legal experts say case might pave way for more lawsuits against breached companies

Google Ratchets Up Security Of HTTPS

    November 22, 2011
'Forward secret' HTTPS feature now protects Gmail, SSL Search, Google Docs and Google+

AT&T Discloses Hack Attempt On Customer Data

    November 21, 2011
'Organized and systemic' hack of AT&T customer records was designed to collect online account information, telecom giant says

PCI Security Standards Council Announces Special Interest Groups

    November 15, 2011
Cloud computing, e-commerce security, and risk assessment voted priority issues by PCI community

Breach Of University Server Threatens Personal Data Of More Than 175,000

    November 14, 2011
Attackers at VCU use one server to launch an attack on a second server containing sensitive info

Research: Small Merchants Don't Believe PCI Compliance Will Protect Them

    November 11, 2011
Study finds a continued lack of knowledge on PCI DSS

Children's Hospital Oakland Research Institute Deploys Centrify To Centrally Manage Security And HIPAA Compliance

    November 09, 2011
Centrify Suite 2012 solution to centralize all security and policy controls for center's growing Macintosh and Linux user populations

Study: Users Are Mad About Breaches, And They're Not Going To Take It Anymore

    November 02, 2011
More than 75 percent of users say they would close their account in the event of a breach; more than half say they would take legal action

Hacks In Sweden Might Affect Personal Data Of 180,000 Users

    November 01, 2011
Attackers penetrate some 58 websites in Sweden, including popular blogging site Bloggtoppen.se

New Survey Finds Consumers Are Cautious About Being Online But Need More Vigilance When Protecting Privacy

    October 24, 2011
Anonymizer infographic illustrates dangers of online privacy breaches

Contract Worker Steals Personal Data On 9 Million Israelis

    October 24, 2011
Worker stole data on Israeli citizens and created a searchable database in order to sell it to private buyer, officials say

Sony Falls Under Attack Again As Hackers Crack 93,000 User IDs

    October 13, 2011
Sony locks up 93,000 accounts after attackers gain access to user IDs and passwords

Trend Micro Teams With HyTrust To Enable Cloud Security And Control

    October 12, 2011
Companies deliver new PCI DSS 2.0 compliance reporting tool for virtual machines and cloud infrastructures

CA Technologies Introduces CA Access Control For Virtual Environments

    October 11, 2011
Solution helps customers virtualize critical applications by addressing security and compliance concerns

Trend Micro And HyTrust Team To Advance PCI Compliance Reporting For VMware And Cloud Environments

    October 11, 2011
Companies will provide integrated reporting tools that reduce audit response times

InCommon And Comodo Partnership Secures Colleges And Universities

    September 28, 2011
Companies have issued tens of thousands of certificates

Survey Shows Consumers Leave Businesses That Suffer Security Breach

    September 22, 2011
SailPoint survey finds customers are losing confidence in the organizations they once trusted

Centrify Awarded Patent In Identity And Access Management

    September 22, 2011
Patented technology is a method and apparatus for maintaining multiple sets of identity data

Consumers Primed For Online Shopping Despite Fraud Concerns

    September 21, 2011
Nearly half of consumers say they already have fallen victim to cybercrime, but most plan to shop online this holiday season

FireHost Secures $10 Million In Series B Funding

    September 15, 2011
Company specializes in protecting websites and applications with compliance and high-traffic needs

CIA Fights Back Against 'Visual Eavesdroppers'

    September 13, 2011
Invests in technology that protects sensitive and classified data

Researchers: 'Cybercrime Is Much More Prevalent Than People Realize'

    September 09, 2011
Cost of online crime estimated at $114 billion annually; victim costs are much higher, Norton says

Two Alleged High-Profile Members Of Anonymous Arrested

    September 02, 2011
Meanwhile, Anonymous hacks on, dumping online what appears to be incriminating emails, personal information of Texas law enforcement officers

Changes To OAuth 2.0 Security Standard For Social Sharing At 'Last Call' Stage

    August 31, 2011
OAuth 2.0 is mostly down to arguments over individual words in its requirements and recommendations

Facebook Gives Users Some Privacy

    August 23, 2011
More granular control over privacy settings

Transaction Wireless Earns Highest PCI Level 1 Certification

    August 23, 2011
Company is one of the first digital gift card providers to meet the PCI Data Security Standard (DSS) v2.0

McAfee Announces Mobile Support For iOS

    August 16, 2011
McAfee WaveSecure enables users to protect their privacy and mobile data

GlobalSign Launches CloudSSL For On-demand Cloud Security

    August 15, 2011
GlobalSign’s CloudSSL Web service allows service providers instant access to multidomain SSL Certificates

AntiSec's Dump Of Law Enforcement Data Includes Personal Data Of Thousands

    August 10, 2011
Data published by AntiSec contains more than 2,500 SSNs, 15,000 dates of birth, 8,000 passwords, and 45,000 personal addresses, study says

UCF And LockPath To Introduce Compliance Resource

    August 03, 2011
Compliance Dictionary includes unique search functions that standardizes and unifies compliance terms and governance requirements

Lieberman Software, Hewlett-Packard Integration Controls Privileged Access To Lights-Out Management Devices

    July 21, 2011
Solution makes it easier for organizations to comply with government and industry regulations

Survey: Merchants Driven By Brand Protection, Not Fines, In Payment Security Investments

    July 19, 2011
CyberSource and Trustwave release survey results on how merchants are managing their payment security

Adobe Acquires EchoSign

    July 18, 2011
EchoSign’s electronic signature solution will be a key component of Adobe’s document exchange services platform










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)