Review of 2007: Lost in translation
- Article 12 of 33
- SC Magazine, February 2008
Large-scale data breaches across both the private and public sectors dominated the news throughout the year. Rob Buckley looks back.
Page 1 | Page 2 | Page 3 | Page 4 | Page 5 | All 5 Pages
Meanwhile, the stolen data market thrived, according to reports, with Gartner saying that ID theft had risen 50 per cent in the past three years in - which was handy, because several UK banks were found to be putting sensitive data into bins outside their premises and a Halifax branch had a number of its customers' details stolen. It seemed only the attorney general wanted to do something about leaked data: he took out an injunction stopping the BBC from airing a news segment about the “cash for honours” scandal.
APRIL
Porn was back. Britney Spears, Paris Hilton and porn star Jenna Jameson were among the lures used in 450 exploits of the animated Windows cursor vulnerability uncovered in March. After Microsoft finally managed to patch the flaw in April, Britney et al remained irresistible to Skype users, propagating a new IM worm. Never missing an opportunity to use a large-scale loss of life as a hook, hackers also used the Virginia Tech shootings to help propagate another worm to curious email users. Windows Server's DNS service became an attraction for hackers that was to last for most of the year, while some spammers began to combine their emails with malware.
Globally, 40 per cent of companies reported suffering disruptions from malware, according to research. However, more earth-shattering than the 4.3 magnitude earthquake that hit Kent, was a survey from Network Box that found 99 per cent of SMEs said they did not know how often their AV software was updated.
Websense acquired rival SurfControl for $400 million (£193 million).
Alleged hacker Gary McKinnon (pictured) lost his High Court appeal against extradition to the US. However, he didn't give up the fight.
MAY
In the same month that a young girl called Madeleine disappears while on holiday with her parents in Portugal, cyberwar broke out between Russia and Estonia. The Baltic state blamed its neighbour for launching DDoS attacks against its websites in revenge for the removal of a war memorial.
Following April's “month of MySpace Bugs”, a “month of ActiveX Bugs” begins with revelations of yet more flaws in MS Office. More worryingly, flaws are found in McAfee's, Symantec's and Trend Micro's security products, as well as Cisco's IOS.
It was a case of all change in the world of security vendors, with Google making its first security acquisition, GreenBorder Technologies; VeriSign CEO Stratton D Sclavos resigning; nCircle acquiring Cambia Security; Cisco agreeing to buy BroadWare; and Verizon announcing plans to acquire CyberTrust.
The month was full of embarrassing data breaches: Marks & Spencer lost some of its employee data, PlusNet admitted it had suffered “a security breach” and the Foreign Office suffered its own breach with its online visa application service - although this was not to remain the worst government data loss of the year by any means.
JUNE
While image spam had worried some since its arrival last year, by June it was proving to be a spent force, with the number of such messages starting to decrease substantially, according to Symantec. Never ones to give up easily, spammers tried other techniques, swapping images for PDFs and Excel files in “pump-and-dump” campaigns - with little more success.
Page 1 | Page 2 | Page 3 | Page 4 | Page 5 | All 5 Pages
