Facebook acknowledges it exposed 6 million members' phone numbers and e-mail addresses to unauthorized viewers, the latest example of IT security incidents creating mistrust of corporations and governments.
In defending against distributed-denial-of-service attacks, enterprises must comprehend the motives of the cyber-assailant, Booz Allen Hamilton's Sedar Labarre says. He outlines how organizations should assess their risks.
The federal government has identified dozens of cases of alleged falsification of reports submitted by investigators - federal employees and contractors - examining individuals being considered for security clearances.
An HHS inspector general report on the shortcomings of a government contractor's USB drive security practices is a reminder of why all healthcare organizations need to control the use of mobile storage media and ports.
To prevent leaks, the National Security Agency is considering a number of measures, including reducing the number of systems administrators it employs, Director Keith Alexander tells a House committee.
The participation of Microsoft and other software vendors in an operation to take down 1,400 Citadel botnets illustrates why more public-private collaboration is needed to tackle emerging cybercrimes, operation participants say.
National Security Agency Director Keith Alexander declined to say that the agency would stop using contractors in top secret IT positions to prevent a leak such as the one that exposed NSA programs to collect metadata on American citizens.
Another organized cyber-attack and subsequent cash-out scheme illustrates increasing risks to the U.S. payments chain. One fraud expert says this trend "is of grave concern" for banking institutions and their accountholders.
Having the right log and access management tools in place - and not all tools are used by all agencies at all times - doesn't mean that the proper authorities are alerted in a timely manner to activities that could jeopardize the nation's security.