Security experts are sounding warnings that a flaw known as POODLE, revealed Oct. 14, can now be used to decrypt some Internet communications secured using TLS. Vendors have begun describing workarounds and issuing patches.
Payment solutions provider Charge Anywhere is warning merchants and cardholders of a data breach that may have exposed information related to payment card transactions dating back as far as Nov. 5, 2009.
Ten months after NIST issued a draft report proposing changes on how it develops cryptographic standards, following reports that the NSA tampered with a NIST cryptographic algorithm, the institute has yet to finalize that guidance.
Federal regulators are sending a powerful message about the importance of applying software patches by slapping an Alaska mental health services providers with a $150,000 HIPAA sanction. Learn what's included in the corrective action plan.
The "wiper" malware attack against Sony Pictures Entertainment has numerous commonalities with previous wiper attacks in Saudi Arabia and South Korea. This infographic summarizes the attacks and highlights their similarities.
TD Bank has agreed to a second state settlement tied to a data breach involving the loss of two backup tapes that may have exposed information about 260,000 customers. Find out the size of the latest financial penalty.
The hacking gang Lizard Squad has claimed credit for knocking Sony's PlayStation Network offline. Meanwhile, investigators continue to suspect North Korea may have launched the recent, "unprecedented" hack of Sony Pictures Entertainment.
A New York radiologist faces three misdemeanor charges for allegedly stealing health information of 97,000 patients. Find out why a district attorney is advocating a change in state law to permit tougher charges in such cases.
Security practitioners must change their mindset, says Dave Merkel of FireEye. We have to stop thinking we're preserving peace and realize that we're responding to warfare from well-armed attackers, he contends in this video interview.
Leading this week's industry news roundup, Soltra, an FS-ISAC and DTCC joint venture, launches a threat intelligence platform, while Tripwire and Palo Alto Networks announce the integration of APT technologies.
Women's apparel retailer Bebe has confirmed a data breach that may have exposed payment card details for a yet-to-be-revealed number of customers. Learn more about the payment processing system attack.
Except for the leak of celebrities' private data, the "wiper" malware attack against Sony Pictures Entertainment shares "extraordinary" similarities with previous wiper attacks in Saudi Arabia and South Korea, a security researcher finds.
The National Health ISAC is making available to its members a new intelligence platform that aims to ease cyberthreat information sharing. Find out how it compares with a similar offering from HITRUST.
At a time of growing anxiety over cybercrime, especially among businesses victimized by cyber-attacks, the Justice Department is creating a cybersecurity unit aimed, in part, to better engage the private sector to battle online crime.