Cryptography


Top 20 ‘Critical Controls’ from SANS Institute

The SANS Institute has released critical security controls for cyber defense agreed to by a consortium of agencies including: “NSA, US Cert, DoD, DoD JTF-GNO, the Department of Energy Nuclear Laboratories, Department
of State, DoD Cyber Crime Center plus the top commercial forensics
experts and pen testers that serve the banking and critical
infrastructure communities,” according to the SANS website. Read the SANS Institute consensus audit guidelines.

ID Theft Services Domain Shut Down by Feds

Two Belarusian nationals suspected of operating a rent-a-fraudster
service for bank and identity thieves have been arrested overseas,
according to New York authorities, who unsealed an indictment for one of
the suspects. Read the full article. [Wired]

Network Solutions’ Customers Hacked Again

A week after Web hosting company Network Solutions dealt with a
large-scale infection of WordPress-driven blogs, the company
acknowledged that other sites it hosts have been compromised. Read the full article. [Computerworld]


US brokerage D.A. Davidson has agreed to pay $375,000 to settle charges
that lax security practices allowed criminal hackers from Latvia to
pilfer the confidential information of some 192,000 of its customers. Read the full article. [The Register]

The Black Hat security conference will kick off next week in Barcelona, with training sessions and briefings from some of the most talented security researchers in the industry. Facebook’s chief security officer, Max Kelly, is scheduled for a keynote presentation on Wednesday morning following two days of training sessions. Read the full article. [Computerworld]