Expect more cyber-espionage, sophisticated malware in ’12, experts say: The security industry expects the number of cyber-espionage attacks to increase in 2012 and the malware used for this purpose to become increasingly sophisticated. ComputerWorld, December 26, 2011
6 Credit Card Mistakes that can ruin your holidays: Credit cards can help make a breeze out of holiday shopping. A few missteps, though, and that breeze can turn into a storm of financial headaches. Dr. Stahl is quoted in this story. creditcards.com, December 2011
Using Starbucks’ WIFI? Security Pro Issues Warning and Security Checklist, an article featuring Dr. Stahl, has been the number one article on Terry Corbell’s site ‘The Biz Coach’ since the portal was launched in 2009.
Double wham bam: AntiSec hacks, dumps CA & NY law enforcement emails: Almost like an echo from retired hackers, those from the 90s who long ago faded into the ether, the motto for 2011 may have been along the lines of “hack the planet.” Yet there are some who obviously learned nothing about the consequences of maintaining sloppy security in 2011. In the cyber world, 2012 was not greeted by the boom of fireworks but by a double wham bam to law enforcement in California and New York. ComputerWorld, January 3, 2012
Saudi hackers leak personal information of thousands of Israelis: Saudi hackers who identified themselves as members of the online Anonymous network claimed on Monday to have leaked files containing personal information, including credit card numbers and expiration dates, belonging to more than 400,000 Israelis. Ynet News, January 3, 2012
Huge Security Breach at Security Firm Symantec No Threat to Consumers, Analyst Says: One of the biggest security firms in the world may need to boost its own security: A hacker stole the source code behind Symantec’s industry-leading antivirus program. Fox News, January 6, 2012
Hackers reveal personal data of 860,000 Stratfor subscribers: A computer hacking group has revealed email addresses and other personal data from former Vice President Dan Quayle, former Secretary of State Henry A. Kissinger, and hundreds of U.S. intelligence, law enforcement and military officials in a high-profile case of cyber-theft. LA Times, January 4, 2012
Army warns of ID theft from Stratfor hack: The Army is warning users of its Army Knowledge Online portal to beware of identity theft following the recent Anonymous hack of intelligence analysis company Strategic Forecasting. GNC, January 3, 2012
Questions About Motives Behind Stratfor Hack: When hackers used the Christmas holiday to attack Stratfor, a security group based in Austin, Tex., they initially said they were aiming to steal the credit card numbers of its clients and use them to make $1 million in donations to charity. New York Times, December 27, 2011
Major security hole in most modern wireless routers: According to a vulnerability notice issued by the US Computer Emergency Readiness Team (US-CERT) on December 27th, just about every Wi-Fi router that supports Wi-Fi Protected Setup (WPS) is vulnerable to a brute force attack. IT Wire, December 27, 2011
New Tools Bypass Wireless Router Security: Security researchers have released new tools that can bypass the encryption used to protect many types of wireless routers. Ironically, the tools take advantage of design flaws in a technology pushed by the wireless industry that was intended to make the security features of modern routers easier to use. KrebsOnSecurity, December 28, 2011
Ramnit Computer Worm Compromises 45K Facebook Logins: A computer worm that has traditionally targeted the financial industry has set its sights on social networking, recently stealing over 45,000 Facebook login credentials, according to security firm Seculert. PC Magazine, January 5, 2012
Report: Phishing attack targets Apple customers: A “vast phishing attack” that attempts to capture the credit card information of Apple customers was launched on Christmas day, according to a report from Mac security-software company Intego. ComputerWorld, December 26, 2011
Turkish hackers avenge France’s ‘genocide bill’: The websites of the French Senate and a National Assembly lawmaker who introduced a bill that would outlaw the denial of the 1915 Turkish ‘genocide’ of Armenians, have been attacked by Turkish hackers. France24, December 29, 2011
Spam Campaign following Kim Jong-il’s Demise Serves Malware: The telecommunications regulator of South Korea alerted that a malicious spam campaign, by capitalizing on Kim Jong-il’s death who was the Workers Party of Korea’s general secretary in North Korea, is striking users’ mailboxes. Help Net Security published this, December 20, 2011. Spamfighter.com, December 27, 2011
Websites targeting Olympics visitors closed down by police: Detectives from the UK’s leading cyber crime unit have identified hundreds of websites that could be used to dupe visitors to next year’s London Olympics. The Guardian, December 26, 2011
GSM phones vulnerable to hijack scams -researcher: Flaws in a widely used wireless technology could allow hackers to gain remote control of phones and instruct them to send text messages or make calls, according to an expert on mobile phone security. Reuters, December 27, 2011
Chamber of Commerce Cyber Attack a Wake-Up Call for In-House Counsel: The extent of the cyber-damage caused by China-based hackers who tapped into the U.S. Chamber of Commerce in 2010 is not yet known. But following the recently publicized information about the attack, the message to in-house counsel is clear: protect yourselves. And that may mean having your company work more closely with the government. Law.Com, December 23, 2011
Cyber strike rampage: White-hot Israel vows to treat hackers like terrorists: In the wake of a massive online dump of Israeli credit card details by “Saudi” hackers, Tel Aviv says it will treat cyber attacks as acts of terror. It has also commended the US, who has hinted at retaliating for such assaults with military action. RT News, January 7, 2012
Dept. of Energy developing project to reinforce grid cybersecurity: The government is trying once again to whip the key players behind the country’s electrical grid into a security force that can defend against mounting cyber threats. Network World, January 5, 2012
Happy 2nd Birthday, KrebsOnSecurity.com!: This past year, KrebsOnSecurity.com has featured more than 200 blog posts, and attracted 5,000+ reader comments. It has been humbling to watch the audience here steadily grow and mature into a community. The expertise and conversations offered by readers in the blog comments have added immeasurably to the value and usefulness of this site. KrebsOnSecurity, December 25, 2011