IT Security and Compliance Blog Archive

Read the news, developments and opinion pieces from years gone by about IT security and compliance from industry experts New Net Technologies.

A free extension to Google Chrome that has been downloaded by 1.3 million users has been caught stealing personal information and sending it back to a single server in the US.

Linux Breach

Linux Australia president Joshua Hesketh announced in a statement that a "malicious individual" had used a RAT to access Linux Australia's main conference database resulting in a data breach.

PCI DSS Compliance

E-commerce firms will be forced to migrate their web servers from SSL to TLS support later this month or face non-compliance with the latest version of industry standard PCI DSS.

As part of a week-long series on the changing face of IT Security, Channelnomics Europe spoke to our CTO, Mark Kedgley on a number of key security topics, including what are the biggest challenges facing the IT industry, what are the biggest opportunities for IT security providers, and will hackers always be one step ahead of IT security providers?

From Target to Home Depot and most recently the Carbanak APT – estimated to have stolen $1B from banks around the world – the fallout of a major breach is horrendous.

Earlier this month BlueCoat and Experian released independent reports which painted a bleak picture of UK firms' information security practices, finding in particular that companies didn't have appropriate incident response plans, or carry out appropriate risk and security assessments.

PCI DSS Compliance

Miles Technologies, a US based IT company is using New New Technologies’ (NNT) Change Tracker Enterprise to ensure the high levels of PCI DSS compliance required by its customers.

However strong the perimeter security, in the vast majority of organizations there are far too many opportunities for hackers or malware attacks to slide in undetected.

ICS-CERT NERC CIP Version 5

The latest ICS-CERT report includes some analysis of cyber security incidents reported to them in Fiscal Year 2014. Of the 245 incidents reported, 55% were attributed to some form of Advanced Persistent Threat (APT), but overall 38% of the 245 incidents remain unexplained:

 Three new breaches have been reported in the past week showing that payment card data theft is still an ever-present threat.

Comguard

IT security and compliance software solutions provider, NNT has sealed a strategic partnership with ComGuard, the information security VAD in the Middle East and Asia Pacific region.

An article on SC Magazine reports that 40 percent of large organizations will have formal plans to address “aggressive” cyber-security business disruption attacks by 2018, according to research outfit Gartner.

TalkTalk breach

The TalkTalk breach fallout shows how the theft of Personally Identifiable Information (PII) can be exploited to cause huge loss and damage to individuals and why we should all be demanding proper protection of any personal information we share with others.

SIM card maker Gemalto has responded to claims made in recent Snowden leaks that government spies hacked encryption keys it used to protect cell phone communications.

Details have emerged of three new breaches affecting Big Fish Games' website, Jefferson National Park Association's gift shop POS systems and a spear-phishing attack targeting employees of State of Franklin Healthcare Associates. NNT provide more details of what and how happened, and how other organizations can protect themselves.

We wrote about the Anunak/Carbanak hacker gang in a previous entry but there is a nicely detailed and illustrated report now available on-line. 

The_Whitehouse

The United States is creating a new cyber security agency to focus on cyber-threats and centralize threat intelligence for use by existing federal agencies.

Anunak: APT against financial institutions

Worth taking time to read the report published by Fox-IT and Group iB regarding the activities and operations of the Anunak/Carbanak hacker gang. The report provides a fascinating expose of the scale and range of theft perpetrated, including the cheeky hacking of ATM settings to issue 5,000 Ruble notes when 100 Ruble notes were requested.

The Lizard Squad hacking group has again targeted Microsoft’s online gaming service, taking it offline for hours.

BCH Logo

BCH Digital, an established provider of IVR-based call management services, is using New Net Technologies' (NNT) Change Tracker Enterprise solution to ensure the compliance of its telephone card payment service with the stringent Level 1 Payment Card Industry Data Security Standard (PCI-DSS).

Contact Us

Corporate Headquarters

Netwrix
6160 Warren Parkway, Suite 100
Frisco, Texas, 75034

Phone 1: 1-949-407-5125

Phone 2: 888-638-9749 (toll-free)


[email protected]
 

United Kingdom

Netwrix
5 New Street Square
London EC4A 3TW

Phone: +44 (0) 203 588 3023


 [email protected]
SC Magazine Cybersecurity 500 CSGEA Winners 2021 CIS benchmarking SEWP Now Certified IBM Security
Copyright 2024, New Net Technologies LLC. All rights reserved. 
NNT and Change Tracker are registered trademarks of New Net Technologies LLC.
All other product, company names and trademarks are the property of their respective owners.