Security Experts:

long dotted

NEWS & INDUSTRY UPDATES

From approximately 2008 until May 2011, the hackers conspired to hack into more than 200 U.S.-based merchants’ point-of-sale (POS) systems in order to steal customers’ credit card data.
Now in the control of the federal government, users that attempt to visit any of the 150 seized domains will be greeted with a large notice, alerting them that the domain name has been seized.
The Philippines Criminal Investigation and Detection Group (CIDG) said on Saturday that with the help of the FBI, four people have been arrested and stand accused of running remote toll scam in order to fund terrorism.
On Wednesday, Nov. 23, Attila Nemeth, a 26 year-old Hungarian citizen pleaded guilty after hacking into Marriott computer systems, and threatening to reveal confidential company information he obtained if Marriott didn’t offer him a job.
FBI Director Robert Mueller laid out some of the challenges posed by terrorists, spies, and hackers to group at the Commonwealth Club of California in San Francisco.
Operation Ghost Click: The FBI and international authorities have disrupted a massive cybercrime scheme that infected more than four million computers with malware around the world and generated an estimated $14 million for a group of cybercriminals over a period of several years.
Investigators have identified several false document manufacturing networks in multiple cities that supported a variety of criminal activity, including credit and bank fraud, tax fraud, identity theft, and pharmaceutical diversion schemes.
Attackers have been targeting chemical and defense companies around the world in a cyber-campaign designed to steal information. At least 48 companies are believed to have been targeted across various verticals and used the well-known PoisonIvy Trojan as part of the attack.
After one of their own was kidnapped while participating in Operation PaperStorm, Anonymous has threatened to expose the Zetas drug cartel unless the Anon is released.
In Mumbai, Indian authorities seized components from servers in a data center, after Symantec informed them that they were communicating with the command and control (C&C) infrastructure used by Duqu, the Trojan that is touted as the precursor to the next Stuxnet.

FEATURES, INSIGHTS // Tracking & Law Enforcement

Chris Poulin's picture
To effectively defend yourself against an enemy, you have to think like your adversary. Put yourself in their mind, their shoes. What’s the motive? How determined are they? Will they stop at a well-hardened network perimeter or move on to other tactics, including social engineering? Once you suffer a breach, how do you share your analysis?
Idan Aharoni's picture
The worlds of counter terrorism and fraud prevention should increase their ties. Systems that are already implemented in one world may be applied to the other. Solution providers and policy makers from both worlds need to meet up and share ideas, thoughts and experience for the benefit of both.
Noa Bar-Yosef's picture
This week, we highlight a mix of tools and tool types that security researchers should have in their weapons in arsenal, including tools unveiled for the first time at the Black Hat conference.
Michael Goff's picture
Once a Software Vendor discovers that their software has been pirated, the gut reaction is to put an immediate stop to it. If piracy is discovered, it’s best to react, but don’t overreact. Be proactive, yet patient.
Idan Aharoni's picture
Crowd sourcing investigations could harness the power of the web and its population to track down cybercriminals. But such a community effort of a cyber investigation comes with big challenges....
Idan Aharoni's picture
There are many security companies, individual researchers and certain circles in academia that hold a wealth of information on cybercrime activities that could be the difference between a bust and a cybercrime investigation that leads to a dead end. It’s not just about collaboration with other law enforcement agencies, but also about collaboration with the security industry.
Mike Lennon's picture
Enjoy this selection of top picks for 2010, listed in no particular order. Happy New Year!
Idan Aharoni's picture
Cybercriminals are constantly going up against anti-fraud measures designed to stop their efforts and they need to bypass them in order to make a profit.
Zeus 2.1 now boasts features that help it avoid analysis and hostile takeover from law enforcement, researchers, or competing cybercriminal organizations.
Idan Aharoni's picture
When it comes to infrastructure, money mules are important - if not more important - than having a botnet or a phishing attack set up. After all, what use are online banking credentials if you can’t cash them out?

Delivered Twice Each Week, the SecurityWeek Briefing Won't Flood Your InBox, But Will Keep you Well Informed on What's Happening in the Industry, Along with Insightful Columns from Industry Experts.

Privacy: We never sell or share your personal information or email address with any other company and you can unsubscribe instantly at any time.