Researchers at Mac security firm Intego have uncovered a new tool hackers can use to steal data from jailbroken Apple iPhones. The tool leverages the same default password issue as the ikee worm targeting iPhone users in Australia.
Article link
Computerworld - A massive bot-based attack has been hitting Facebook users, with nearly three-quarters of a million users receiving fake password reset messages, according to security researchers.
The Monthly Chosun reports that a certified password to the Chemical Accident Response Information System (CARIS) set up by the National Institute of Environmental Research (NIER) was stolen by hackers on March 5 from a computer used by an officer at South Korean Army command.
Article link
Users need to be able to recognize illicit attempts to elicit their account information.Microsoft recommends customers use the following protective security measures:
A Twitter employee just learned a very hard lesson. The employee's personal email account was hacked, and now, the Internet is abuzz because documents—both personal and business related—are being circulated in the blogosphere. Apparently, he (or she) used the same password on multiple accounts. Sound familiar? Thing is, this isn't the first person to fall victim to such an attack—and it certainly won't be the last.
Default passwords are a common and easy way for hackers to attack systems. It's important for you to use strong passwords to protect your systems.
Article link
I'm sure you've used websites that ask you to select "secret" questions and provide your own answer to be used in case you ever forget your password. Well, a new study released yesterday says those questions are much less secure than your password.
It's no secret that passwords are no longer sufficient as the sole means of granting access to critical networks, applications, and data, particularly as the number of applications requiring passwords at any given firm has skyrocketed.
Article link
One of the various security-related email lists I'm on had a message about forced password expiration. This is a subject which I've been mildly interested in for a number of years and I continue to review research and articles on it as I come across them. I have of course formed my own opinion on this topic which I am going to share with you.