Diane Rado reports: Just hours after the state launched a new, multimillion-dollar teacher licensing system last year, an educator logging in was shocked to find a serious security breach. “I discovered that by doing a public search using any educator’s name, ALL of our personal information is available to everyone. This is alarming!” the educator…
Category: U.S.
Is delaying notification for law enforcement purposes ever unreasonable?
Over on Security Bistro, Linda Musthaler discusses the recently disclosed Spec’s breach and the fact that Spec’s knew about the breach but was asked not to disclose it by law enforcement. We’ve seen this many times – delays in notification so as not to interfere with a law enforcement investigation. But should there be some…
Federal court ruling in Carnegie Strategic Design Engineers v. Cloherty applies narrow interpretation of CFAA
Robert R. Baron, Jr., David S. Fryman, Corinne Militello, and Philip N. Yannella of Ballard Spahr write: A Pennsylvania federal magistrate judge has tossed an employer’s claims under the Computer Fraud and Abuse Act (CFAA), holding that the CFAA does not extend to punish employees for the misuse of information that was accessed with permission….
RK Internet notifies customers after malware snags their information
When RK Internet (“Rural King”) became suspicious on March 7th that their web server had been compromised, they brought in forensic investigators. Those investigators discovered that malware had been injected, and for transactions that occurred between February 6 until March 12, customers names, debit or credit card number with security code and expiration date, telephone…
5-year-old Ocean Beach boy exposes Microsoft Xbox vulnerability
Michael Chen reports: A young Ocean Beach boy is in the spotlight after he discovered a back door in to one of the most popular gaming systems in the world. When 5-year-old Kristoffer Von Hassel is playing his Xbox, his feet don’t touch the ground. But something he did has made the smartest guys at…
At least two states investigating data breach involving Court Ventures, an Experian unit
Jim Finkle of Reuters reports: U.S. attorneys general have launched a multi-state investigation into a breach in which criminals gained access to a repository of some 200 million social security numbers through a unit of data provider Experian Plc. “We are investigating,” said Maura Possley, a spokeswoman for Illinois Attorney General Lisa Madigan. “It’s part…