Latest news

"During our investigation, we found a small number of computers, including some in our Mac business unit, that were infected by malicious software using techniques similar to those documented by other organizations," stated Matt Thomlinson, General Manager of Microsoft's Trustworthy Computing Security, and added that so far, they have found no evidence of customer data being affected, but that the investigation is still ongoing.
"This type of cyberattack is no surprise to Microsoft and other companies that must grapple with determined and persistent adversaries. We continually re-evaluate our security posture and deploy additional people, processes, and technologies as necessary to help prevent future unauthorized access to our networks," he concluded.
He shared no more details about the breach for the time being.
Twitter, Facebook and Apple have recently notified the public about the breaches into their internal networks, which were the result of a watering hole-type of attack.
The watering hole in question was the iPhoneDevSDK forum site, popular with mobile developers, and the attacker have managed to infect the visitors' computer by serving exploits for (at the time unpatched) Java vulnerabilities.
It is still unknown whether the attack was aimed at these high-profile targets, but what is known is that it wasn't limited to them - any visitor that still had Java enabled on his browser or computer was bound to be affected.
So let me reiterate once more: if you don't need Java, remove it from your devices. If you're not sure whether you need it or not, remove it and see how it goes. If you miss it and can't do without it, you can always install it again.


Spotlight

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

To hack back or not to hack back?
Posted on 12 June 2013. | If you think of cyberspace as a new resource for you and your organization, it makes sense to protect your part of it as best you can. But is it a good idea?

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.







