<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Info Security News</title>
    <link>http://seclists.org/#isn</link>
    <atom:link href="http://seclists.org/rss/isn.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>Carries news items (generally from mainstream sources) that relate to security.</description>
    <pubDate>Wed, 23 May 2012 11:45:06 GMT</pubDate>
    <lastBuildDate>Wed, 23 May 2012 11:45:06 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Anatomy of a hack: 6 separate bugs needed to bring down Google browser (Updated)</title>
    <link>http://seclists.org/isn/2012/May/69</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 23&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://arstechnica.com/security/2012/05/anatomy-of-a-hack-6-separate-bugs-needed-to-bring-down-google-browser/&quot;&gt;http://arstechnica.com/security/2012/05/anatomy-of-a-hack-6-separate-bugs-needed-to-bring-down-google-browser/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Dan Goodin&lt;br&gt;
Ars Technica&lt;br&gt;
May 22 2012&lt;br&gt;
&lt;br&gt;
An exploit that fetched a teenage hacker a $60,000 bounty targeted six &lt;br&gt;
different security bugs to break out of the security sandbox fortifying &lt;br&gt;
Google&amp;apos;s Chrome browser.&lt;br&gt;
&lt;br&gt;
The extreme lengths taken in March by a hacker identified only as Pinkie &lt;br&gt;
Pie underscore the difficulty of piercing this...&lt;br&gt;</description>
    <pubDate>Wed, 23 May 2012 11:32:00 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/69</guid>
  </item>
  <item>
    <title>New White House cybersecurity chief largely an unknown</title>
    <link>http://seclists.org/isn/2012/May/68</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 23&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.csoonline.com/article/706824/new-white-house-cybersecurity-chief-largely-an-unknown&quot;&gt;http://www.csoonline.com/article/706824/new-white-house-cybersecurity-chief-largely-an-unknown&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Taylor Armerding&lt;br&gt;
CSO&lt;br&gt;
May 21, 2012&lt;br&gt;
&lt;br&gt;
Named late last week to replace Howard Schmidt as the top White House &lt;br&gt;
cybersecurity adviser, Michael Daniel is a 17-year veteran of the Office &lt;br&gt;
of Management and Budget (OMB) and has been its intelligence branch &lt;br&gt;
chief for the past 11 years. But he has stayed largely under the radar, &lt;br&gt;
even in the cybersecurity...&lt;br&gt;</description>
    <pubDate>Wed, 23 May 2012 11:30:47 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/68</guid>
  </item>
  <item>
    <title>Banking malware spies on victims by hijacking webcams, microphones, researchers say</title>
    <link>http://seclists.org/isn/2012/May/67</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 23&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.computerworld.com/s/article/9227387/Banking_malware_spies_on_victims_by_hijacking_webcams_microphones_researchers_say&quot;&gt;https://www.computerworld.com/s/article/9227387/Banking_malware_spies_on_victims_by_hijacking_webcams_microphones_researchers_say&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Lucian Constantin&lt;br&gt;
IDG News Service&lt;br&gt;
May 22, 2012&lt;br&gt;
&lt;br&gt;
A new variant of SpyEye malware allows cybercriminals to monitor &lt;br&gt;
potential bank fraud victims by hijacking their webcams and microphones, &lt;br&gt;
according to security researchers from antivirus vendor Kaspersky Lab.&lt;br&gt;
&lt;br&gt;
SpyEye is a computer Trojan horse that specifically...&lt;br&gt;</description>
    <pubDate>Wed, 23 May 2012 11:29:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/67</guid>
  </item>
  <item>
    <title>NSA Teams Up With Colleges to Train Students for Secret Cyber-Ops Jobs</title>
    <link>http://seclists.org/isn/2012/May/66</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 23&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.wired.com/threatlevel/2012/05/nsa-college-students/&quot;&gt;http://www.wired.com/threatlevel/2012/05/nsa-college-students/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Kim Zetter&lt;br&gt;
Threat Level&lt;br&gt;
Wired.com&lt;br&gt;
May 22, 2012&lt;br&gt;
&lt;br&gt;
The National Security Agency is partnering with select universities to &lt;br&gt;
train students in cyber operations for intelligence, military and law &lt;br&gt;
enforcement jobs, work that will remain secret to all but a select group &lt;br&gt;
of students and faculty who pass clearance requirements, according to &lt;br&gt;
Reuters.&lt;br&gt;
&lt;br&gt;
The cyber-operations curriculum is...&lt;br&gt;</description>
    <pubDate>Wed, 23 May 2012 11:28:26 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/66</guid>
  </item>
  <item>
    <title>Security vulnerability reporting framework upgraded for researchers</title>
    <link>http://seclists.org/isn/2012/May/65</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 23&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://news.techworld.com/security/3359074/security-vulnerability-reporting-framework-upgraded-for-researchers/&quot;&gt;http://news.techworld.com/security/3359074/security-vulnerability-reporting-framework-upgraded-for-researchers/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By John E Dunn&lt;br&gt;
Techworld&lt;br&gt;
21 May 2012&lt;br&gt;
&lt;br&gt;
The security industry’s Common Vulnerability Reporting Framework (CVRF) &lt;br&gt;
framework for reporting and sharing security vulnerabilities in a &lt;br&gt;
machine-readable format has been given a promised revamp to make it &lt;br&gt;
easier to use for third-party researchers.&lt;br&gt;
&lt;br&gt;
Managed by industry body, the Industry...&lt;br&gt;</description>
    <pubDate>Wed, 23 May 2012 11:27:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/65</guid>
  </item>


  <item>
    <title>Hackers take down Chicago website</title>
    <link>http://seclists.org/isn/2012/May/64</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 21&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.chicagotribune.com/news/local/ct-met-nato-website-down-20120521,0,5070454.story&quot;&gt;http://www.chicagotribune.com/news/local/ct-met-nato-website-down-20120521,0,5070454.story&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Hal Dardick&lt;br&gt;
Chicago Tribune&lt;br&gt;
May 21, 2012&lt;br&gt;
&lt;br&gt;
Anti-NATO hackers brought down the city of Chicago&amp;apos;s home page for hours &lt;br&gt;
Sunday as leaders of the military alliance met in Chicago and thousands &lt;br&gt;
of protesters took to the streets.&lt;br&gt;
&lt;br&gt;
The page, cityofchicago.org, went down from midmorning until early &lt;br&gt;
afternoon after a shadowy group posted a YouTube video...&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 06:35:59 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/64</guid>
  </item>
  <item>
    <title>RSA SecurID software token cloning: a new how-to</title>
    <link>http://seclists.org/isn/2012/May/63</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 21&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://arstechnica.com/security/2012/05/rsa-securid-software-token-cloning-attack/&quot;&gt;http://arstechnica.com/security/2012/05/rsa-securid-software-token-cloning-attack/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
by Dan Goodin&lt;br&gt;
Ars Technica&lt;br&gt;
May 21 2012&lt;br&gt;
&lt;br&gt;
A researcher has devised a method attackers with control over a victim&amp;apos;s &lt;br&gt;
computer can use to clone the secret software token that RSA&amp;apos;s SecurID &lt;br&gt;
uses to generate one-time passwords.&lt;br&gt;
&lt;br&gt;
The technique, described on Thursday by a senior security analyst at a &lt;br&gt;
firm called SensePost, has important implications for the...&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 06:34:51 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/63</guid>
  </item>
  <item>
    <title>Is cloud-based security really cheaper?</title>
    <link>http://seclists.org/isn/2012/May/62</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 21&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.csoonline.com/article/706738/is-cloud-based-security-really-cheaper-&quot;&gt;http://www.csoonline.com/article/706738/is-cloud-based-security-really-cheaper-&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Antone Gonsalves&lt;br&gt;
CSO&lt;br&gt;
May 21, 2012&lt;br&gt;
&lt;br&gt;
Businesses in new study were five times more likely to have decreased &lt;br&gt;
spending on managing security over three years.&lt;br&gt;
&lt;br&gt;
As part of its marketing strategy for selling to small- and medium-size &lt;br&gt;
businesses (SMBs), Microsoft this week released the results of a study &lt;br&gt;
on the use of cloud-bases security. The survey of SMBs, whether...&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 06:33:43 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/62</guid>
  </item>
  <item>
    <title>Iranian Hackers Claim They Compromised NASA SSL Digital Certificate</title>
    <link>http://seclists.org/isn/2012/May/61</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 21&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.darkreading.com/security-monitoring/167901086/security/attacks-breaches/240000784/iranian-hackers-claim-they-compromised-nasa-ssl-digital-certificate.html&quot;&gt;http://www.darkreading.com/security-monitoring/167901086/security/attacks-breaches/240000784/iranian-hackers-claim-they-compromised-nasa-ssl-digital-certificate.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Kelly Jackson Higgins&lt;br&gt;
Dark Reading&lt;br&gt;
May 21, 2012&lt;br&gt;
&lt;br&gt;
A self-professed Iranian hacker gang announced in an online post that it &lt;br&gt;
compromised an SSL certificate belonging to NASA and subsequently &lt;br&gt;
accessed information on &amp;quot;thousands&amp;quot; of NASA researchers.&lt;br&gt;
&lt;br&gt;
Word of the alleged...&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 06:32:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/61</guid>
  </item>
  <item>
    <title>Anonymous hacks Bureau of Justice, leaks 1.7GB of data</title>
    <link>http://seclists.org/isn/2012/May/60</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 21&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.zdnet.com/blog/security/anonymous-hacks-bureau-of-justice-leaks-17gb-of-data/12260&quot;&gt;https://www.zdnet.com/blog/security/anonymous-hacks-bureau-of-justice-leaks-17gb-of-data/12260&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Emil Protalinski&lt;br&gt;
Zero Day&lt;br&gt;
ZDNet May 21, 2012&lt;br&gt;
&lt;br&gt;
The hacktivist group Anonymous claims to have leaked 1.7GB of data &lt;br&gt;
belonging to the United States Bureau of Justice Statistics (BJS). The &lt;br&gt;
file, which has been uploaded as a torrent and posted on The Pirate Bay, &lt;br&gt;
reportedly contains internal e-mails as well as the website’s “entire &lt;br&gt;
database...&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 06:31:12 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/60</guid>
  </item>


  <item>
    <title>Obama Cybersecurity Czar Schmidt Steps Down</title>
    <link>http://seclists.org/isn/2012/May/59</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 18&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.darkreading.com/compliance/167901112/security/news/240000583/obama-cybersecurity-czar-schmidt-steps-down.html&quot;&gt;http://www.darkreading.com/compliance/167901112/security/news/240000583/obama-cybersecurity-czar-schmidt-steps-down.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Kelly Jackson Higgins&lt;br&gt;
Dark Reading&lt;br&gt;
May 17, 2012&lt;br&gt;
&lt;br&gt;
The nation&amp;apos;s first cybersecurity czar, Howard A. Schmidt, has resigned &lt;br&gt;
his historic post and will be succeeded by Michael Daniel, chief of the &lt;br&gt;
White House budget office&amp;apos;s intelligence branch.&lt;br&gt;
&lt;br&gt;
Schmidt said in a statement that he is leaving to spend more time with...&lt;br&gt;</description>
    <pubDate>Fri, 18 May 2012 10:12:16 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/59</guid>
  </item>
  <item>
    <title>How Stuxnet Came Back to Haunt the U.S.</title>
    <link>http://seclists.org/isn/2012/May/58</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 18&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.theatlanticwire.com/technology/2012/05/how-stuxnet-came-back-haunt-us/52466/&quot;&gt;http://www.theatlanticwire.com/technology/2012/05/how-stuxnet-came-back-haunt-us/52466/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Megha Rajagopalan&lt;br&gt;
ProPublica&lt;br&gt;
May 17, 2012&lt;br&gt;
&lt;br&gt;
Last week, the Department of Homeland Security revealed a rash of cyber &lt;br&gt;
attacks on natural gas pipeline companies. Just as with previous cyber &lt;br&gt;
attacks on infrastructure, there was no known physical damage. But &lt;br&gt;
security experts worry it may only be a matter of time.&lt;br&gt;
&lt;br&gt;
Efforts to protect pipelines and other...&lt;br&gt;</description>
    <pubDate>Fri, 18 May 2012 10:11:11 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/58</guid>
  </item>
  <item>
    <title>KSE site hacked on day of launching</title>
    <link>http://seclists.org/isn/2012/May/57</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 18&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.arabtimesonline.com/NewsDetails/tabid/96/smid/414/ArticleID/183360/reftab/36/t/KSE-site-hacked-on-day-of-launching/Default.aspx&quot;&gt;http://www.arabtimesonline.com/NewsDetails/tabid/96/smid/414/ArticleID/183360/reftab/36/t/KSE-site-hacked-on-day-of-launching/Default.aspx&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Arab Times&lt;br&gt;
18/05/2012&lt;br&gt;
&lt;br&gt;
KUWAIT CITY, May 17: The website of Kuwait Stock Exchange (KSE) was &lt;br&gt;
hacked on the day it was launched, reports Al-Jaridah daily quoting &lt;br&gt;
reliable sources.&lt;br&gt;
&lt;br&gt;
They disclosed that the hackers managed to copy all data from the &lt;br&gt;
website before deleting them. The website administration team...&lt;br&gt;</description>
    <pubDate>Fri, 18 May 2012 10:10:01 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/57</guid>
  </item>
  <item>
    <title>Fake Google Chrome Installer Steals Banking Details</title>
    <link>http://seclists.org/isn/2012/May/56</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 18&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.informationweek.com/news/security/vulnerabilities/240000575&quot;&gt;http://www.informationweek.com/news/security/vulnerabilities/240000575&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Mathew J. Schwartz&lt;br&gt;
InformationWeek&lt;br&gt;
May 17, 2012&lt;br&gt;
&lt;br&gt;
Beware fake Chrome installers for Windows.&lt;br&gt;
&lt;br&gt;
A file named &amp;quot;ChromeSetup.exe&amp;quot; is being offered for download on various &lt;br&gt;
websites, and the link to the file appears to be legitimately hosted on &lt;br&gt;
Facebook and Google domains. In reality, the software won&amp;apos;t install &lt;br&gt;
Google&amp;apos;s Chrome browser, but an...&lt;br&gt;</description>
    <pubDate>Fri, 18 May 2012 10:08:55 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/56</guid>
  </item>
  <item>
    <title>UK now a top ten nation for hacking traffic, logs show</title>
    <link>http://seclists.org/isn/2012/May/55</link>
    <description>&lt;p&gt;Posted by InfoSec News on May 18&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://news.techworld.com/security/3358334/uk-now-top-ten-nation-for-hacking-traffic-logs-show/&quot;&gt;http://news.techworld.com/security/3358334/uk-now-top-ten-nation-for-hacking-traffic-logs-show/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By John E Dunn&lt;br&gt;
Techworld&lt;br&gt;
17 May 2012&lt;br&gt;
&lt;br&gt;
A growing volume of attempted hacks and probes has propelled the UK into &lt;br&gt;
the global top ten for this type of traffic, the NCC group has reported.&lt;br&gt;
&lt;br&gt;
For the first three months of 2012, the UK was at number seven on the &lt;br&gt;
list with 2.4 percent of hacking traffic according to intrusion &lt;br&gt;
detection log data sourced from...&lt;br&gt;</description>
    <pubDate>Fri, 18 May 2012 10:07:32 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/isn/2012/May/55</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>

