The BBC reports that NHS Dumfries and Galloway in south west Scotland improved its security after the loss of two memory sticks carrying patient data in May 2008. It now uses USB devices with built-in security, and is nearing completion on a program to fully encrypt all other portable devices. Patient groups had called for…
TX: Computers With NEISD Personal Information Stolen
Personal information, resumes, photos of students and other information was found on computers from the North East Independent School District that were scheduled for destruction, but ended up for sale online and in flea markets. District officials said the computers, including three computers and two hard drives obtained by KSAT 12 News, were sent to…
Experts Debate the Value of Breach Notification Laws
Kim Zettner of Threat Level discusses the different views expressed at a seminar last week on whether data breach notification laws do any good. As expected, the upshot was “we don’t know” because there are not enough data, surveys may not be reliable indicators, etc. Of course, there is another way to frame the issue…
USAID.gov compromised, malware and exploits served
Dancho Danchev of ZDnet reportsthat the Azerbaijan section at the United States Agency for International Development (azerbaijan.usaid.gov) has been compromised and is embedded with malware and exploits serving scripts since approximately March 1. He also provides a dissection of the attack. There’s a YouTube video from AVG as well, although it’s either somewhat blurry or…
Telegraph.co.uk hacked, SQL injection (updated)
The HackersBlog crew, who had previously exposed vulnerabilities in a number of security vendor sites and a social networking site, now reports that they were able to exploit an SQL injection vulnerability to access The Telegraph‘s databases, including one that has 700,000 email addresses and passwords of those receiving the paper’s newsletter. Given how many…
Bits ‘n Pieces
In the justice system: Ehud Tannenbaum, the hacker known as “The Analyzer,” may be extradicted to the U.S. from Canada. A hearing is tentatively set for May 7. More. Karl Gallagher, who worked for a British Airways’ call center in the UK, has been jailed for 2 1/2 years after admitting he stole customer credit…