Latest news

"During our investigation, we found a small number of computers, including some in our Mac business unit, that were infected by malicious software using techniques similar to those documented by other organizations," stated Matt Thomlinson, General Manager of Microsoft's Trustworthy Computing Security, and added that so far, they have found no evidence of customer data being affected, but that the investigation is still ongoing.
"This type of cyberattack is no surprise to Microsoft and other companies that must grapple with determined and persistent adversaries. We continually re-evaluate our security posture and deploy additional people, processes, and technologies as necessary to help prevent future unauthorized access to our networks," he concluded.
He shared no more details about the breach for the time being.
Twitter, Facebook and Apple have recently notified the public about the breaches into their internal networks, which were the result of a watering hole-type of attack.
The watering hole in question was the iPhoneDevSDK forum site, popular with mobile developers, and the attacker have managed to infect the visitors' computer by serving exploits for (at the time unpatched) Java vulnerabilities.
It is still unknown whether the attack was aimed at these high-profile targets, but what is known is that it wasn't limited to them - any visitor that still had Java enabled on his browser or computer was bound to be affected.
So let me reiterate once more: if you don't need Java, remove it from your devices. If you're not sure whether you need it or not, remove it and see how it goes. If you miss it and can't do without it, you can always install it again.


Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





