Two security researchers have recently revealed vulnerabilities that can be exploited remotely to retrieve sensitive data stored inside special computer components known as HSMs (Hardware Security Modules). . HSMs are hardware-isolated devices that use advanced cryptography to store, manipulate, and work with sensitive information such as digital keys, passwords, PINs, and various other sensitive information. In the real world, they can take the form of add-in computer cards, network-connectable router-like devices, or USB-connected thumb drive-like gadgets. The link for this article located at ZDNet is no longer available. . HSM vulnerabilities pose significant risks to sensitive data confidentiality in financial institutions and cloud services. Explore the implications of these threats. HSM Threats, Data Exploits, Cryptographic Issues, Banking Security. . LinuxSecurity.com Team
A couple of 14-year-old computer whizzes have the Bank of Montreal upgrading its security after the teens hacked an ATM machine. Matthew Hewlett and Caleb Turon, both Grade 9 students, found an old ATM operators manual online that showed how to get into the machine's operator mode.. On Wednesday over their lunch hour, they went to the BMO's ATM at the Safeway on Grant Avenue to see if they could get into the system. The link for this article located at Toronto Sun is no longer available. . Two 14-year-old tech prodigies discover weaknesses in ATM systems, leading BMO to enhance the security of their terminals.. ATM Exploit, Bank Security Threats, Teenage Hackers, ATM Security Upgrades. . LinuxSecurity.com Team
Account holders with at least two Australian banks have become victims of a phishing scam in which malicious code reveals the physical location of affected IP addresses using Google Maps. Bank account holders in Germany and the USA have also been targeted. The software installs a Trojan capable of key-logging user activity, hijacking infected computers. . The scam was circulated as a false news report claiming the Australian prime minister had suffered a heart attack. It installs a trojan and backdoor code to capture all user input as well as compromising a Web server to allow the hacker to hijack the victim The link for this article located at ICT World is no longer available. . The scam was circulated as a false news report claiming the Australian prime minister had suffered a. account, holders, least, australian, banks, become, victims, phishing, which. . LinuxSecurity.com Team
For the fourth time in the past 30 months, Wells Fargo & Co. has begun notifying customers about the potential compromise of confidential information following the theft of a company computer containing data on mortgage customers and prospective clients. The San Francisco-based bank on Friday posted a statement on its Web site saying that a computer belonging to its mortgage group had been reported as missing while being transported between Wells Fargo facilities by a global express shipping company. . The stolen system contained information such as names, addresses, Social Security numbers and mortgage loan account numbers of Wells Fargo customers. "The computer has two layers of security, making it difficult to access the information," the bank said. So far, at least, there is no indication that the information kept on the computer has been misused in any way, said Alejandro Hernandez, a company spokesman. The link for this article located at ComputerWorld.com is no longer available. . Bank of America confronts security incident following the misplacement of a device containing sensitive loan records.. Data Breach,Wells Fargo,Confidential Information,Customer Notification. . LinuxSecurity.com Team
An independent expert has backed two Cambridge University students' claims to have uncovered a flaw in a key IBM cryptographic coprocessor that is at the heart of some of the world's most secure systems. IBM has been warned not to dismiss . . . . An independent expert has backed two Cambridge University students' claims to have uncovered a flaw in a key IBM cryptographic coprocessor that is at the heart of some of the world's most secure systems. IBM has been warned not to dismiss the two Cambridge University research students, who claim to have developed a system to hack bank security codes and potentially obtain thousands of PIN numbers. IBM had said the students' method could only work in laboratory conditions and that a bank's physical security measures would prevent attack. However, Dr Nicko van Someren, chief technical officer of Ncipher - one of the world's largest suppliers of cryptographical engines to financial institutions - told CW360.com: "This is a significant security breach. Security managers should be worried but not panicking." The link for this article located at ComputerWeekly.com is no longer available. . An independent expert has backed two Cambridge University students' claims to have uncovered a flaw . independent, expert, backed, cambridge, university, students', claims, uncovered. . LinuxSecurity.com Team
Last December, a bank in Southern California received a call from an online customer asking why one of the bank's computers was trying to hack into his system. It turned out that the machine doing the hacking belonged to the bank's . . . . Last December, a bank in Southern California received a call from an online customer asking why one of the bank's computers was trying to hack into his system. It turned out that the machine doing the hacking belonged to the bank's president and had been remotely commandeered by an employee. The president called Conqwest Inc., a Holliston, Mass.-based IT security services firm, which is now rolling out firewall software across the bank's 125 internal desktop, laptop and remote computers. Until recently, companies thought antivirus and virtual private network (VPN) technologies would keep remote worker connections safe. But as more workers have been accessing the Internet through broadband services such as cable modems, exposure to hacking attacks through those machines has increased. In October, for example, a hacker broke into a Microsoft Corp. employee's home computer and exploited the VPN connection to penetrate the company's internal network. The link for this article located at ITWorld is no longer available. . Understand the vital function of firewalls for remote workers, as they protect financial institutions against cyber threats by monitoring network traffic.. Remote Access Security, Banking Firewall, IT Security Practices, Network Protection, Cyber Threat Prevention. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.