<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/wikileaks"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Wikileaks ]]></title>
                <link>https://www.itpro.com/uk/tag/wikileaks</link>
        <description><![CDATA[ All the latest wikileaks content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Fri, 01 Sep 2017 08:39:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Wikileaks 'hacked' by OurMine ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29366/wikileaks-hacked-by-ourmine</link>
                                                                            <description>
                            <![CDATA[ The whistleblowing site was supposedly breached, but the attack was found to be a simple DNS spoof ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qbbMJdkAA7sukKN58jTXLW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/q5gdYZP2cZ3avYBsCKyKuP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Sep 2017 08:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/q5gdYZP2cZ3avYBsCKyKuP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/q5gdYZP2cZ3avYBsCKyKuP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Notorious whistleblowing site Wikileaks drew the attention of the cyber security community this week, as the organisation fell victim to an apparent hack.</p><p>Visitors to the Wikileaks homepage were greeted with a message from security company OurMine, proclaiming that it had hacked WikiLeaks in response to a challenge supposedly issued by the organisation.</p><p>"Hi, it's OurMine," the message read. "Don't worry we are just testing your... blablablab [sic], Oh wait, this is not a security test! Wikileaks, remember when you challenged us to hack you?"</p><p>The same statement also taunted cyber vigilante group Anonymous, indicating that this hack was partly in revenge for an incident in which Anonymous allegedly attempted to dox the group for attacking Wikileaks, which has been accused of being a front for Russian intelligence. "There we go" the message read. "One group beat you all!"</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/26797/hackers-take-over-google-ceo-sundar-pichai-s-social-media" data-original-url="/hacking/26797/hackers-take-over-google-ceo-sundar-pichai-s-social-media">Hackers take over Google CEO Sundar Pichai’s social media</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/26678/mark-zuckerbergs-social-media-accounts-have-been-hacked" data-original-url="/security/26678/mark-zuckerbergs-social-media-accounts-have-been-hacked">Mark Zuckerberg's social media accounts have been hacked</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/29163/us-charges-iranian-man-with-game-of-thrones-leaks" data-original-url="/hacking/29163/us-charges-iranian-man-with-game-of-thrones-leaks">US charges Iranian man with Game of Thrones leaks</a></p></div></div><p>However, it quickly emerged that OurMine had not actually broken into Wikileaks' servers at all. Instead, the group used a tactic known as 'DNS poisoning', whereby an attacker gains control of the DNS server that controls how traffic is routed to an IP address, and redirects it to a location of their choosing, in this case, a page hosted on OurMine's own server.</p><p>The attack has now apparently been thwarted, and the Wikileaks site appears to be fully operational once again.</p><p>The statement left by the group echoed the message it commonly left on the social media accounts of its other victims, which usually state that the group is "just testing [the victim's] security". These victims include various high-profile companies and individuals, including <a href="https://www.itpro.com/security/26678/mark-zuckerbergs-social-media-accounts-have-been-hacked" target="_blank" data-original-url="https://www.itpro.com/security/26678/mark-zuckerbergs-social-media-accounts-have-been-hacked">Facebook founder Mark Zuckerberg</a>, <a href="https://www.itpro.com/hacking/26797/hackers-take-over-google-ceo-sundar-pichai-s-social-media" target="_blank" data-original-url="https://www.itpro.com/hacking/26797/hackers-take-over-google-ceo-sundar-pichai-s-social-media">Google CEO Sundar Pichai</a> and, most recently, <a href="https://www.itpro.com/hacking/29163/us-charges-iranian-man-with-game-of-thrones-leaks" target="_blank" data-original-url="https://www.itpro.com/hacking/29163/us-charges-iranian-man-with-game-of-thrones-leaks">Game Of Thrones creators HBO</a>.</p><p>These hacks are apparently operated as promotional stunts for the group's cyber security consultancy and penetration testing business, with victims advised to contact the group if they wish to improve their security.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sweden drops rape charges against Julian Assange ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/28691/sweden-drops-rape-charges-against-julian-assange</link>
                                                                            <description>
                            <![CDATA[ Assange may still remain in hiding, however ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dp2MfQ5aVQQSC6hn49vXZ6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/q5gdYZP2cZ3avYBsCKyKuP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 May 2017 09:48:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/q5gdYZP2cZ3avYBsCKyKuP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/q5gdYZP2cZ3avYBsCKyKuP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Wikileaks founder Julian Assange has successfully waited out rape charges, after Sweden decided to drop its investigation. </p><p>Assange was accused with rape in the lesser degree in 2012, living in the Ecuador embassy to avoid extradition to face the charges, arguing Sweden could send him on to the US for his leaks of military files.</p><p>The Swedish prosecutor said the chargers were dropped because the investigation could not continue without Assange's prescence in court, and that the investigation could be reopened if he visits Sweden before the statute of limitations is up in 2020. Assange has always denied the charges. </p><p>Whether this means Assange will leave the embassy remains to be seen, as noted by the Wikileaks Twitter account - which is assumed to be run by Assange. "UK refuses to confirm or deny whether it has already received a US extradition warrant for Julian Assange. Focus now moves to UK," it <a href="https://twitter.com/wikileaks/status/865497032722530304">said</a>. However, Assange's own Twitter account simply posted an image of <a href="https://twitter.com/JulianAssange/status/865496201839337472">him smiling</a>. </p><p>The Metroplitan Police has issued a statement saying that the warrent for his arrest for failing to surrender to the court in June 2012 still stands. "The Metropolitan Police Service is obliged to execute that warrant should he leave the Embassy," the statement said.</p><p>However, the Met added: "Whilst Mr Assange was wanted on a European Arrest Warrant (EAW) for an extremely serious offence, the MPS response reflected the serious nature of that crime. Now that the situation has changed and the Swedish authorities have discontinued their investigation into that matter, Mr Assange remains wanted for a much less serious offence. The MPS will provide a level of resourcing which is proportionate to that offence."</p><p>The US attorney general Jeff Sessions said last month that he considered <a href="https://www.theguardian.com/media/2017/apr/21/arresting-julian-assange-is-a-priority-says-us-attorney-general-jeff-sessions">arresting Assange a priority.</a> </p><p>The announcement follows Assange's lawyer filing for the court to drop a detention order against the Wikileaks founder, with today the deadline for prosecutors to respond with a request to arrest him. </p><p>Assange's charges being dropped come the same week as the release from prison of Chelsea Manning, the US army private who leaked military records to Wikileaks. She served seven years of a 35-year sentence, which was commuted to time served by Barack Obama before his term as US president ended. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/22912/julian-assange-to-leave-ecuadorian-embassy-soon" data-original-url="/strategy/22912/julian-assange-to-leave-ecuadorian-embassy-soon">Julian Assange to leave Ecuadorian Embassy "soon"</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/27421/julian-assange-cut-off-from-accessing-internet" data-original-url="/strategy/27421/julian-assange-cut-off-from-accessing-internet">Julian Assange cut off from accessing internet</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco discloses Vault 7 vulnerabilities ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28342/cisco-discloses-vault-7-vulnerabilities</link>
                                                                            <description>
                            <![CDATA[ Internal analysis seems to have identified bug revealed by WikiLeaks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gBQiKF2o3THbY5FHR4tVAd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TP8wPiU4TUYp7pMGbngKdE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Mar 2017 11:48:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TP8wPiU4TUYp7pMGbngKdE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacking Hacker Security]]></media:description>                                                            <media:text><![CDATA[Hacking Hacker Security]]></media:text>
                                <media:title type="plain"><![CDATA[Hacking Hacker Security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TP8wPiU4TUYp7pMGbngKdE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cisco has identified a major vulnerability in its Cluster Management Protocol (CMP), which formed part of the <a href="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel" target="_blank" data-original-url="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel">WikiLeaks "Vault 7" document cache</a>.</p><p>On 7 March, Omar Santos, principal engineer at Cisco's product security incident response team, published <a href="http://blogs.cisco.com/security/the-wikileaks-vault-7-leak-what-we-know-so-far" target="_blank">a blog post</a> acknowledging that Cisco devices were among those allegedly targeted by the CIA.</p><p>At that time, little was known about the actual method of attack, other than it was a type of malware targeting multiple devices, including routers and switches, which allowed for the attacker to carry out data collection and exfiltration, HTML traffic redirection, DNS poisoning and other malicious actions.</p><p>Further analysis of the documents, though, has now enabled the company to identify <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp" target="_blank">what it thinks is the vulnerability in question</a>.</p><p>In an update to the blog post, Santos said: "Based on the "Vault 7" public disclosure, Cisco launched an investigation into the products that could potentially be impacted by these and similar exploits and vulnerabilities.</p><p>"As part of the internal investigation of our own products and the publicly available information, Cisco security researchers found a vulnerability in the Cluster Management Protocol code in Cisco IOS and Cisco IOS XE Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges."</p><p>In a security advisory, the company explained that the vulnerability, which affects scores of devices, is due to the fact the Cluster Management Protocol (CMP) uses Telnet internally.</p><p>According to the company, there are two factors that combine to create the problem:</p><ul><li>A failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process them over any Telnet connection to an affected device;</li><li>Incorrect processing of malformed CMP-specific Telnet options</li></ul><p>"An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device," the company explained.</p><p>Unfortunately there is, for now, no patch or workaround per se. Cisco has advised users that <a href="http://www.cisco.com/c/en/us/support/docs/ip/access-lists/13608-21.html" target="">disabling the Telnet protocol</a> for incoming connections and using SSH would mitigate the risk. This is the approach recommended by the company.</p><p>Cisco does recognise, however, that this approach may not be acceptable to all, or indeed may be impossible for some. In this case, the company advises <a href="http://www.cisco.com/c/en/us/support/docs/ip/access-lists/43920-iacl.html" target="_blank">implementing infrastructure access control lists</a>.</p><p><a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp" target="_blank">The advisory, including a list of all affected deviced, can be found in full here.</a></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel" data-original-url="/security/28276/apple-ios-1021-protects-users-from-weeping-angel">Apple iOS 10.2.1 protects users from Weeping Angel</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28273/wikileaks-files-expose-alleged-cia-hacking-tools" data-original-url="/security/28273/wikileaks-files-expose-alleged-cia-hacking-tools">WikiLeaks files expose alleged CIA hacking tools</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple iOS 10.2.1 protects users from Weeping Angel ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel</link>
                                                                            <description>
                            <![CDATA[ Security community says Vault 7 content is "no surprise", but reckless ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8p4U6CoWxQC6smwJLutqwg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Dzv5UtZUMMMTPXZBcHUrFc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Mar 2017 15:36:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Dzv5UtZUMMMTPXZBcHUrFc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Dzv5UtZUMMMTPXZBcHUrFc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Most iOS devices are protected against the CIA's alleged Weeping Angel attacks <a href="https://www.itpro.com/security/28273/wikileaks-files-expose-alleged-cia-hacking-tools" target="_blank" data-original-url="https://www.itpro.com/security/28273/wikileaks-files-expose-alleged-cia-hacking-tools">revealed by WikiLeaks last night</a>, Apple has claimed.</p><p>In a statement sent to <em>IT Pro</em>, the Cupertino company said: "The technology built into today's iPhone represents the best data security available to consumers, and we're constantly working to keep it that way.</p><p>"While our initial analysis indicates that many of the issues leaked were already patched in the latest iOS, we will continue work to rapidly address any identified vulnerabilities. We always urge customers to download the latest iOS to make sure they have the most recent security updates."</p><p>What proportion of the issues "many" represents is unclear.</p><p>Microsoft and Samsung both said they are currently "looking into" the matter, but gave no further information on the current scope or validity of the attacks detailed in the so-called Vault 7 cache.</p><h2 id="no-surprises">No surprises</h2><p>While hardware makers rush to investigate and patch the alleged vulnerabilities, the security community has raised an eyebrow at the surprise the leaks have generated with regard to the vulnerabilities themselves.</p><p>Slawek Ligier, VP of security engineering at Barracuda, said: "The types of capabilities described in the WikiLeaks [files] are not new and many of the exploits were demonstrated as technically possible for a while now."</p><p>Matthew Ravden, VP at security systems specialist Balabit, added: "Assuming these revelations are true (and they certainly appear to be authentic), it's probably fairly shocking to the general public to see the lengths to which a sophisticated government-sponsored organisation will go to find ways of 'listening in', through TVs, smart-phones or other 'connected' devices.</p><p>"For those of us in the security industry, however, none of this is particularly surprising. The resources available to the CIA, MI5, or the FSB are such that they can do pretty much anything. They live by a different set of rules from the rest of us."</p><h2 id="fake-news-and-questionable-morals">Fake news and questionable morals</h2><p>Although it has been reported that the the Vault 7 files show the CIA can break the encryption of secure apps like WhatsApp, Signal and Telegram, this is based on a misunderstanding of the content of the leaks.</p><p>Ed Johnson-Williams, a campaigner for the Open Rights Group, said <a href="https://www.openrightsgroup.org/blog/2017/yes-the-cia-can-hack-phones-but-signal-and-whatsapp-are-still-safe-for-nearly-everyone" target="_blank">in a blog post</a>: Some journalists ... have reported this story as showing that the CIA can bypass the encryption on messaging apps like Signal and WhatsApp. This is emphatically not accurate. The apps themselves are secure. They are probably uncritically repeating a WikiLeaks tweet to that effect.</p><p>"There is a big difference between phone operating systems being hacked and message encryption being broken. If a messaging app's encryption has been broken, that would affect every user of the app. The encryption in Signal and WhatsApp has not been broken ... [they] remain very good ways to communicate when using a mobile phone for nearly everyone. The worst thing to do would be to throw our hands up in the air and give up on our digital security."</p><p>Johnson-Williams pointed out that if the CIA and other intelligence agencies "hoard" these vulnerabilities, then they are also open to use by criminals and the intelligence agencies of non-friendly countries.</p><p>Ligier sounded a similar note, saying: "To me the disturbing part of the report is that it appears that spy agencies ... are more interested in stockpiling the vulnerabilities for a future exploit rather than working with vendors to close the gaps. If the CIA knows of the specific exploit, chances are that the MI6, FSB, MSS, and Mossad are aware of it as well.</p><p>"Not working on closing the gap and hoping that we will be the only ones able to exploit it, puts all of us at risk. And frankly, the United States has much more to lose through potential industrial espionage than other countries."</p><h2 id="digital-personal-safety">Digital personal safety</h2><p>Although the encryption of WhatsApp, Signal and Telegram hasn't been broken, devices themselves remain vulnerable. There are still ways consumers can keep themselves safe or at least safer from hacking of all types.</p><p>Johnson-Williams said: "From a personal security point-of-view it's important to keep all of this in perspective. Most people are at far greater risk of their devices being infected from clicking a link in a phishing email than they are of being hacked by the CIA using a vulnerability in their device."</p><p>Similarly, Ligier said that while there's no way to stop devices being turned into "little spies", the risks can be mitigated.</p><p>Reflecting Apple's comment, he said users should always update to the latest firmware and software "especially if the update lists security fixes". He also warned against rooting or jailbreaking phones, as well as being careful when opening email attachments or clicking on links as "more than 90% of attacks start with the email".</p><p>"We all need to work together to protect the advantages the global internet offers to all of us and assure that the dark side does not win," he said.</p><p><em>Image credit: Bigstock</em></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28273/wikileaks-files-expose-alleged-cia-hacking-tools" data-original-url="/security/28273/wikileaks-files-expose-alleged-cia-hacking-tools">WikiLeaks files expose alleged CIA hacking tools</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/27287/edward-snowden-warns-against-using-google-allo" data-original-url="/strategy/27287/edward-snowden-warns-against-using-google-allo">Edward Snowden warns against using Google Allo</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WikiLeaks files expose alleged CIA hacking tools ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28273/wikileaks-files-expose-alleged-cia-hacking-tools</link>
                                                                            <description>
                            <![CDATA[ CIA's tools can break into any kind of operating system, smart device or digital machine ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2WeSsTKjMeJVNZPv6Q8kt5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hFGqsnfx34S6pk3GEseu4W-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Mar 2017 09:47:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hFGqsnfx34S6pk3GEseu4W-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hFGqsnfx34S6pk3GEseu4W-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>WikiLeaks has claimed the CIA can pretty much hack into any device, even smart TVs, with its range of hacking tools, designed to read and lift data from electronic devices.</p><p>The information obtained is "the largest ever publication of confidential documents on the agency," according to a statement <a href="https://wikileaks.org/ciav7p1" target="_blank">released by WikiLeaks</a>.</p><p>The first batch to be leaked, dubbed 'Year Zero' is comprised of 8,761 documents and files that reportedly detail how authorities have discovered a way to bypass the encryption in highly secure messaging platforms such as WhatsApp, Telegram and Signal. This is done by accessing the data on devices before encryption is applied on Android and using other methods on the iPhone, Microsoft Windows and even Samsung smart TVs. However, <a href="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel" target="_blank" data-original-url="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel">privacy campaigners dispute this claim</a>.</p><p>The files were accessed via an internal network inside the CIA's Center for Cyber Intelligence in Langley, Virgina.</p><p>The engineering development group (EDG) is responsible for developing, testing and supporting the tools that the CIA uses for this type of surveillance. The EDG sits within the Center for Cyber Intelligence (CCI), which itself is a sub-department of the Directorate for Digital Innovation (DDI), one of the CIA's five major directorates. </p><p>One particular method of surveillance, dubbed "Weeping Angel", was developed by the CIA's embedded devices branch (EDB) and focused on turning Samsung smart TVs into covert microphones. When users think the TV is off, it's actually a 'fake-off' mode that records conversations and send them to a covert CIA server. It is believed that the CIA didn't act alone for this attack and worked in co-operation with MI5/BTSS (British Security Service). </p><p>WikiLeaks explained that the agency "lost control" of its hacking weapons, including malware, viruses, trojans, weaponised "zero day" exploits, malware remote control systems and associated documentation. Anyone finding the information could use it to launch a serious attack on anyone. However, the notes don't include the hacking files themselves, merely the information about how the CIA is believed to be using them.</p><p>The anonymous source who sent the materials to WikiLeaks is apparently hoping that the documents will trigger a conversation about "whether the CIA's hacking capabilities exceed its mandated powers and the problem of public oversight of the agency," WikiLeaks said. </p><p>"There is an extreme proliferation risk in the development of cyber 'weapons'," said Julian Assange, WikiLeaks editor. "Comparisons can be drawn between the uncontrolled proliferation of such 'weapons', which results from the inability to contain them combined with their high market value, and the global arms trade.</p><p>"But the significance of 'Year Zero' goes well beyond the choice between cyberwar and cyberpeace. The disclosure is also exceptional from a political, legal and forensic perspective."</p><p><a href="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel" target="_blank" data-original-url="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel"><strong><em>Read our analysis of the WikiLeaks revelations here.</em></strong></a></p><p><em>Picture: Bigstock</em></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28276/apple-ios-1021-protects-users-from-weeping-angel" data-original-url="/security/28276/apple-ios-1021-protects-users-from-weeping-angel">Apple iOS 10.2.1 protects users from Weeping Angel</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27125/was-an-insider-behind-the-nsa-hack" data-original-url="/hacking/27125/was-an-insider-behind-the-nsa-hack">Was an insider behind the NSA hack?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/28251/liberty-launches-legal-challenge-against-investigatory-powers-act" data-original-url="/it-legislation/28251/liberty-launches-legal-challenge-against-investigatory-powers-act">Liberty launches legal challenge against Investigatory Powers Act</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WikiLeaks ‘exposes people’s personal data’ in leaked files ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/27128/wikileaks-exposes-people-s-personal-data-in-leaked-files</link>
                                                                            <description>
                            <![CDATA[ Rape victims and other innocent people named in WikiLeaks documents, says AP ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nhqwTJjUSf4HeqSsmxFjXb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Aug 2016 10:49:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Julian Assange]]></media:description>                                                            <media:text><![CDATA[Julian Assange]]></media:text>
                                <media:title type="plain"><![CDATA[Julian Assange]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hundreds of people's personal information has been published online by WikiLeaks, including those of rape victims, according to the<a href="http://bigstory.ap.org/article/b70da83fd111496dbdf015acbb7987fb/private-lives-are-exposed-wikileaks-spills-its-secrets?utm_campaign=SocialFlow&utm_source=Twitter&utm_medium=AP" target="_blank"><em>Associated Press</em></a>.</p><p>Their exposure is a byproduct of WikiLeaks' stated commitment to revealing government secrets across the globe, the newswire found while investigating files published by the organisation in the last year.</p><p>The transparency group has published people's medical files, while others have had "sensitive family, financial or identity records posted to the web", AP claimed.</p><p>AP said it has verified 23 people's leaked details by contacting them, mostly in Saudi Arabia.</p><p>One man, whose paternity dispute with a former partner allegedly appeared in WikiLeaks' trove of documents, told the newswire: "They published everything: my phone, address, name, details. If the family of my wife saw this ... Publishing personal stuff like that could destroy people."</p><p>WikiLeaks did not comment on the article, but <em>IT Pro</em> has approached it to ask how it vets the documents it publishes, and whether AP's claims are accurate. No reply was received at the time of publication.</p><p>The group's documents <a href="https://wikileaks.org/What-is-Wikileaks.html" target="_blank">are all publically available</a>, with its homepage offering a search bar and categories such as Intelligence', Global Economy', Government', and War & Military'.</p><p>People can also search within recently published documents such as the <a href="https://www.itpro.com/hacking/26988/us-officially-accuses-russia-of-leaking-dnc-emails" target="_blank" data-original-url="https://www.itpro.com/hacking/26988/us-officially-accuses-russia-of-leaking-dnc-emails">Democratic National Committee's 19,252 leaked emails</a>, or Hillary Clinton's archive of emails that were stored on her own private server.</p><p>WikiLeaks founder Julian Assange is quoted on the organisation's website as saying: "WikiLeaks is a giant library of the world's most persecuted documents. We give asylum to these documents, we analyze them, we promote them and we obtain more."</p><p>The organisation claims to have published more than 10 million documents "and associated analyses" so far.</p><p>But the leaked DNC emails included dozens of social security numbers and credit card numbers, according to the AP, while a Saudi Foreign Ministry data dump included more than 500 passport details and academic and employment files.</p><p>There were also two instances in which teenage rape victims were named, according to the AP.</p><p>WikiLeaks is yet to respond to a request for comment.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/26988/us-officially-accuses-russia-of-leaking-dnc-emails" data-original-url="/hacking/26988/us-officially-accuses-russia-of-leaking-dnc-emails">US officially accuses Russia of leaking DNC emails</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Julian Assange to leave Ecuadorian Embassy "soon" ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/strategy/22912/julian-assange-to-leave-ecuadorian-embassy-soon</link>
                                                                            <description>
                            <![CDATA[ Wikileaks founder claims his two-year stay at the embassy in London will soon be over ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2aFzTQwbE2a4FbC49SenYR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Aug 2014 11:03:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Julian Assange]]></media:description>                                                            <media:text><![CDATA[Julian Assange]]></media:text>
                                <media:title type="plain"><![CDATA[Julian Assange]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Wikileaks founder Julian Assange plans to leave the Ecuadorian embassy in London "soon", after taking refuge there two years ago.</p><p>Assange was granted diplomatic asylum by the embassy in June 2012 to avoid being extradited to Sweden where he is wanted for questioning over sexual misconduct allegations.</p><p>He announced his intention to leave the embassy during a press conference earlier today, where he hit out at the fact he's not been charged with any offences in the UK or Sweden since seeking refuge.</p><p>"I am leaving the embassy soon, but perhaps not for the reasons [the press] are saying at the moment," he said.</p><p>In the lead up to the announcement, press speculation had suggested Assange was planning to hand himself over to the authorities and leave the embassy on health grounds.</p><p>When pressed for more information on what he meant by "soon", Asssange declined to give any further details.</p><p>During the conference, Assange acknowledged his health may have suffered as a result of being holed up in the embassy for two years, but stopped short of stating this as his sole motivation for leaving.</p><p>"As you can imagine, being detained for various ways in this country for four years and in this embassy for two years, which has no outside area and therefore no direct sunlight... it is an environment in which any healthy person would find themselves soon enough with certain difficulties," he explained. </p><p>Speaking alongside Assange, Ecuador's foreign minister, Ricardo Patino, said justice hasn't been done for anyone over the past two years.</p><p>"It is time to respect human rights... it is time to free Julian Assange," he said.</p><p>"We continue to offer Assange our protection," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pressure mounts on US justice department to drop Wikileaks investigation  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-leakage/22527/pressure-mounts-on-us-justice-department-to-drop-wikileaks-investigation</link>
                                                                            <description>
                            <![CDATA[ Human rights organisations claim investigation could put all journalists at risk of prosecution ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jWbGviRfTJDy5Kj2cjRQGD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Jun 2014 09:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Julian Assange]]></media:description>                                                            <media:text><![CDATA[Julian Assange]]></media:text>
                                <media:title type="plain"><![CDATA[Julian Assange]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of Justice (DoJ) has come under pressure from a slew of human rights groups to drop its four-year investigation into Wikileaks and its founder Julian Assange.</p><p>The DoJ began its investigation into the website in November 2010 after more than 200 confidential American diplomatic cables were posted on Wikileaks, which is famed for providing sources with a means of leaking information anonymously.</p><p>Shortly afterwards, cloud giant Amazon stopped hosting the site on its web servers, while PayPal seized processing payments used to support the site's operations.</p><div><blockquote><p>A prosecution of WikiLeaks or Mr. Assange for publishing classified material could criminalise the news-gathering process and put all editors and journalists at risk.</p></blockquote></div><p>Four years on, 52 press freedom and human rights organisations have called on the US Attorney General Eric Holder to close the investigation into Wikileaks and its founder Julian Assange.</p><p>The latter has spent the past two years holed up in the Ecuadorian embassy in London, and faces the risk of extradition to Sweden should he leave, where he is wanted over allegations of sexual misconduct.</p><p>The letter calls on the DoJ to stop the "harassment" and "persecution" of Wikileaks, given that Holder is reportedly to have vowed in a recent media briefing that "as long as I am attorney general, no reporter who is doing his job is going to go to jail."</p><p>The group claim this statement is at odds with the DoJ's decision to pursue the criminal investigation into Wikileaks and its editor-in-chief Assange.</p><p>"Well-respected legal scholars across the political spectrum have stated that a prosecution of WikiLeaks or Mr. Assange for publishing classified material or interacting with sources could criminalise the news-gathering process and put all editors and journalists at risk of prosecution," the letter states.</p><p>It then closes by claiming that taking action against Wikileaks would "undermine the commitment of the US Government to freedom of speech."</p><p>Time will tell if the group's missive has any impact on the DoJ's ongoing investigation into Wikileaks and Assange.</p><p>Meanwhile, in a news conference yesterday to mark the second anniversary of the start of his stay in the embassy, Assange claimed to have a stash of documents primed for release on Wikileaks pertaining to 50 countries and their "international negotiations."</p><p>He also said his legal team will contest the Swedish extradition case against him next week, in the light of new, undisclosed evidence, coming to light.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Julian Assange unlikely to be charged by US government ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/21101/julian-assange-unlikely-be-charged-us-government</link>
                                                                            <description>
                            <![CDATA[ No way to prosecute Assange without also taking legal action against journalists. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o1AKX1Z48PS5n2PX1juxfU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cbQ4qbjMpV3EdvFEaPsMcZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 Nov 2013 10:28:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Khidr Suleman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cbQ4qbjMpV3EdvFEaPsMcZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Julian Assange]]></media:description>                                                            <media:text><![CDATA[Julian Assange]]></media:text>
                                <media:title type="plain"><![CDATA[Julian Assange]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cbQ4qbjMpV3EdvFEaPsMcZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Justice Department is unlikely to charge Julian Assange with any offence despite his WikiLeaks website publishing classified documents.</p><p>If the decision to prosecute Assange is taken, authorities will also have to take legal action against news organisations that have published top secret data.</p><p>"The problem the department has always had in investigating Julian Assange is there is no way to prosecute him for publishing information without the same theory being applied to journalists," former Justice Department spokesman Matthew Miller told <a href="http://www.washingtonpost.com/world/national-security/julian-assange-unlikely-to-face-us-charges-over-publishing-classified-documents/2013/11/25/dd27decc-55f1-11e3-8304-caf30787c0a9_story.html" target="_blank"><em>The Washington Post</em></a>.</p><p>"And if you are not going to prosecute journalists for publishing classified information, which the department is not, then there is no way to prosecute Assange."</p><p>A formal decision on whether to bring charges has not been made, but there is little possibility of Assange having a case to answer unless he is implicated in other criminal activity.</p><p>Assange is currently holed up in the Ecuadorian embassy in London. The Supreme Court in the UK ruled he should be extradited to Sweden, where he is wanted for questioning in relation to sexual offences.</p><p>The plight of Assange is different from former US government employees including Edward Snowden and Bradley Manning from a legal standpoint. The intelligence analysts have both been charged under the Espionage Act - and sentenced in the case of Manning - because they provided confidential information to news outlets.</p><p>However, until the US confirms it will not pursue charges against Assange, it is likely he will remain in the Ecuadorian embassy.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bradley Manning found guilty of espionage  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security-breaches/20309/bradley-manning-found-guilty-espionage</link>
                                                                            <description>
                            <![CDATA[ US Soldier Bradley Manning could face up to a 136-year jail sentence. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vpLk6XMz3M7tQ8uYW8h2VW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/naPe4vR6dEMiQSC99ZffKb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 31 Jul 2013 10:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Khidr Suleman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/naPe4vR6dEMiQSC99ZffKb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/naPe4vR6dEMiQSC99ZffKb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US soldier Bradley Manning is facing up to 136-years in prison after being found guilty of perpetrating the biggest leak in US government history.</p><p>Judge Denise Lind found Private Manning guilty of 17 counts, but he was cleared of the most serious charge of "aiding the enemy", which carries a maximum sentence of life in prison.</p><p>The 25-year-old soldier is due to be sentenced later today. The court martial heard how Manning leaked hundreds of thousands of classified documents to the whistleblowing website WikiLeaks, which then published them in conjunction with five of the world's biggest newspapers. </p><div><blockquote><p>The US Government's priorities are upside down.</p></blockquote></div><p>During his trial, prosecutors argued that Manning was a traitor and not just a whistle-blower.</p><p>However, prominent rights groups including Amnesty International believe the US government used Manning's trial to send a strong message to anyone thinking of leaking confidential information.</p><p>"The government's pursuit of the aiding the enemy' charge was a serious overreach of the law, not least because there was no credible evidence of Manning's intent to harm the USA by releasing classified information to WikiLeaks," said Widney Brown, senior director of International Law and policy at Amnesty International in a statement.</p><p>"The government's priorities are upside down. The US government has refused to investigate credible allegations of torture and other crimes under international law despite overwhelming evidence."</p><p>Private Manning had already pleaded guilty to three counts Failure to obey a lawful order or regulation along with two counts of violating the Computer Fraud and Abuse Act.</p><p>Altogether Manning is believed to have leaked 470,000 battlefield reports from the US invasions in Iraq and Afghanistan and 250,000 secured cables between the White House and foreign embassies.</p><p>Manning, who trained as an intelligence analyst, was also responsible for obtaining a <a href="http://www.youtube.com/watch?v=5rXPrfnU3G0" target="_blank">video from a US Apache helicopter attack in Iraq</a>. The footage showed eleven people including a Reuters photographer and his driver being gunned down.</p><p>Julian Assange, founder of WikiLeaks, who is facing extradition to Sweden, released a video statement from the Ecuadorian embassy in London.</p><p>"Bradley Manning's alleged disclosures have exposed war crimes, sparked revolutions, and induced democratic reform. He is the quintessential whistleblower," he said.</p><p>"This is the first ever espionage conviction against a whistle blower in the United States. It is a dangerous precedent and it an example of national security extremism."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anonymous attacks UK gov websites in Assange protest ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/642385/anonymous-attacks-uk-gov-websites-in-assange-protest</link>
                                                                            <description>
                            <![CDATA[ ‘Hacktivists’ target Ministry of Justice website over handling of Wikileaks founder asylum case. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ksq7sckDKY3T8hs3PwgcYo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aFyTUQ4y3pBtGADjdMjyRe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Aug 2012 12:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aFyTUQ4y3pBtGADjdMjyRe-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image: vg-design, Fotolia]]></media:description>                                                            <media:text><![CDATA[Image: vg-design, Fotolia]]></media:text>
                                <media:title type="plain"><![CDATA[Image: vg-design, Fotolia]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aFyTUQ4y3pBtGADjdMjyRe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anonymous has launched an attack to bring down a number of UK Government websites in protest at the handling of the Julian Assange case.</p><p>The loose collective of hackers and internet activists claimed responsibility for bringing down the Ministry of Justice website via a distributed denial of service (DDoS) attack and said it is also targeting Number 10. The website had reportedly been experiencing disruption since the evening of 20 August.</p><p>Investigation by <em>IT Pro</em> found service to be intermittent at justice.gov.uk but number10.gov.uk to be currently unaffected.</p><p>Anonymous has long supported Assange, founder of Wikileaks, who is currently taking refuge inside the Ecuadorian embassy in London to avoid extradition to Sweden for questioning over alleged sexual misconduct allegations, which he denies.</p><p>In a statement issued to <em>IT Pro</em>, a Ministry of Justice spokesperson sought to allay fears as to the nature of the attack.</p><p>"This is a public information website and no sensitive data is held on it. No other Ministry of Justice systems have been affected," the spokesperson said.</p><p>"Measures put in place to keep the website running mean that some visitors may be unable to access the site intermittently.</p><p>"We will continue to monitor the situation and will take measures accordingly."</p><p>A DDoS attack involved overloading servers with requests, making it inaccessible. Such attacks are illegal in most countries, but have become a favourite method of protest for groups such as Anonymous, Team Poison and AntiLeaks over the past two years.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Supreme Court unanimously decides to extradict Wikileaks founder ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/641179/supreme-court-unanimously-decides-to-extradict-wikileaks-founder</link>
                                                                            <description>
                            <![CDATA[ Julian Assange likely to be questioned in Sweden. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t1WNoRmDonxaKdc8KELmG7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Jun 2012 16:17:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Khidr Suleman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Julian Assange]]></media:description>                                                            <media:text><![CDATA[Julian Assange]]></media:text>
                                <media:title type="plain"><![CDATA[Julian Assange]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qTb7MFf6yRYQ4JZvVMkvpT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Wikileaks founder Julian Asssange has had his appeal against extradition unanimously dismissed by the justices at the Supreme Court in the UK, making it look increasingly likely he will be extradited to Sweden.</p><p>The Supreme Court originally ruled that Assange should be extradited on 30 May 2012, but gave him 14 days to appeal.</p><p>Having considered the arguments put forward by his legal counsel, Dinah Rose QC, the justices have rejected the appeal and ruled the extradition can go ahead.</p><p>"[The] Court has ordered that, with the agreement of the respondent and pursuant to section 36(3)(b) of the Extradition Act 2003, the required period for extradition shall not commence until the 14th day after today."</p><p>It remains to be seen whether Assange will lodge an appeal with the European Court of Human Rights in Strasbourg.</p><p>The Swedish authorities want to question Assange after allegations of rape and sexual molestation were brought against him by two women.</p><p>The original judgment had suggested Assange had been charged, but this will be amended to read "offences in respect of which his extradition is sought".</p><p>Assange has always maintained his innocence, claiming the allegations are politically motivated and there are no charges to answer to in Sweden.</p><p>He founded WikiLeaks in 2006 and since then it has became a notorious whistle-blowing website leaking confidential diplomatic cables.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Assange allowed to continue extradition fight ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/637696/assange-allowed-to-continue-extradition-fight</link>
                                                                            <description>
                            <![CDATA[ Assange won't have his hearing in the Supreme Court, but it will look into the case. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">enESN3AoWM8kARcXcjyRBN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cVxJXU4fQbdXDKWgsXmZia-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 05 Dec 2011 15:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cVxJXU4fQbdXDKWgsXmZia-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WikiLeaks]]></media:description>                                                            <media:text><![CDATA[WikiLeaks]]></media:text>
                                <media:title type="plain"><![CDATA[WikiLeaks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cVxJXU4fQbdXDKWgsXmZia-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>WikiLeaks founder Julian Assange has been given permission to petition the UK Supreme Court as he bids to avoid extradition to Sweden.</p><p>Assange is wanted for questioning in his home country, after two female former WikiLeaks volunteers accused him of sexual assault during their time with the organisation in August 2010.</p><p>The WikiLeaks chief could have been sent home within 10 days if he had not been granted some leeway after his hearing today. Although judges denied Assange permission to have an appeal heard at the Supreme Court, he can ask the court to look at the case.</p><p>The long struggle for justice for me and others continues.</p><p>Judges concluded his case raised "a question of general public importance."</p><p>"I think that is the correct decision and I am thankful. The long struggle for justice for me and others continues," the <a href="http://www.bbc.co.uk/news/uk-16027942" target="_blank">BBC</a> quoted Assange as saying.</p><p>Assange denies the accusations, claiming the allegations are politically motivated. WikiLeaks upset various Governments after releasing classified communications documents in 2010.</p><p>If the Supreme Court denies Assange a hearing, he could take his case to the European Court of Human Rights in Strasbourg.</p><p>He is currently residing at the country house of a supporter in eastern England, having been released on bail late last year.</p><p>MPs are currently looking into extradition legislation in the UK, following high-profile cases such as the one surrounding <a href="https://www.itpro.com/623755/qa-janis-sharp-speaks-out-about-her-son-gary-mckinnon" target="_blank" data-original-url="https://www.itpro.com/623755/qa-janis-sharp-speaks-out-about-her-son-gary-mckinnon">Gary McKinnon</a>.</p><p>The insider threat</p><p>The man accused of handing over documents to WikiLeaks, Bradley Manning, is due in court this month.</p><p>Manning, a 23-year-old US army analyst, has been in military custody in the US since May 2010, but reports of mistreatment have received negative attention across the globe.</p><p>It was alleged Manning had been held in solitary confinement for 23 hours a day during his time in prison at Wuantico, Virginia, without clothing or bedding.</p><p>Last week, over 60 members of the European Parliament sent an open letter to President Barack Obama, asking him to allow Manning to meet the UN's special rapporteur on torture Juan Mendez.</p><p>"We have questions about why Mr Manning has been imprisoned for 17 months without yet having had his day in court. We are troubled by reports that Mr Manning has been subjected to prolonged solitary confinement and other abusive treatment tantamount to torture," the letter read.</p><p>"And we are disappointed that the US government has denied the request of the United Nations special rapporteur on torture to meet privately with Mr Manning in order to conduct an investigation of his treatment by US military authorities."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WikiLeaks' Julian Assange loses appeal ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/637135/wikileaks-julian-assange-loses-appeal</link>
                                                                            <description>
                            <![CDATA[ Assange is facing extradition back to Sweden if his lawyers can't do anything about it. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4ix771mxavem4CGGpF7UkN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/n2DUjSFLZgmqL8acJFDaHA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Nov 2011 16:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Eva Martin ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/n2DUjSFLZgmqL8acJFDaHA-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WikiLeaks]]></media:description>                                                            <media:text><![CDATA[WikiLeaks]]></media:text>
                                <media:title type="plain"><![CDATA[WikiLeaks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/n2DUjSFLZgmqL8acJFDaHA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Julian Assange, WikiLeaks founder, lost his appeal today against extradition to Sweden.</p><p>In December 2010, Assange was accused of raping one woman and molesting and coercing another. Two Swedish women made accusations after his visit to Stockholm in August.</p><p>In preparation for an appeal, Assange's legal team needs to seek permission from the High Court. They will have 14 days to do so and bring the case to the Supreme Court, on the grounds his case raises issues of public importance.</p><p>I have not been charged with any crime in any country.</p><p>Assange sat silently through the judgment and gave no sign of emotion as the judges gave reasons for their decision, according to reports.</p><p>"It is clear that the allegation is that he had sexual intercourse with her when she was not in a position to consent and so he could not have had any reasonable belief that she did," the judges said.</p><p>Although the President of the Queen's Bench Division Sir John Thomas said the issuing of the European arrest warrant (EAW) was "lawful" and "proportionate", 40-year-old Assange denies allegations, claiming they are politically motivated.</p><p>"I have not been charged with any crime in any country," said Assange in his speech outside the High Court after the hearing.</p><p>He also urged people to go to swedenversusassange.com to "know what is really going on in this case."</p><p>Supporters outside the court held banners reading "Free Assange! End the wars" and vented their outrage at the judges' decision.</p><p>Last month, WikiLeaks pleaded for funding so it could continue to publish Government diplomatic cables after major financial institutions cut off support for the organisation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WikiLeaks hit by cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/635842/wikileaks-hit-by-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ The site is now back up but claims it was hit yesterday. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6iVxCynP9ZSwPpUoUR1hoz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UV86n6cZUmRNnPVCF9Lmxn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 31 Aug 2011 10:07:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UV86n6cZUmRNnPVCF9Lmxn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[security attack]]></media:description>                                                            <media:text><![CDATA[security attack]]></media:text>
                                <media:title type="plain"><![CDATA[security attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UV86n6cZUmRNnPVCF9Lmxn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>WikiLeaks fell under attack this week as it released of thousands of previously unpublished US diplomatic cables, some still classified.</p><p>"WikiLeaks.org is presently under attack," said a message on WikiLeaks' Twitter page, which is believed to be controlled by Julian Assange, the controversial Australian-born founder and chief of the whistle-blowing organisation.</p><p>WikiLeaks later described the problem as "a cyber attack." In a subsequent message on its Twitter feed, it said the website was back up though some users were having problems accessing it.</p><p>The US cables which the website said it is dumping onto the public record appear to be from a cache of more than 250,000 State Department reports leaked to the group. WikiLeaks began releasing the cables in smaller batches late last year, but until now had made them public in piecemeal fashion.</p><p>Several news organisations around the world, including Reuters, have had complete sets of the cables for months. But for the most part, media outlets have only cited or published cables when publishing specific news or investigative stories based on them.</p><p>A person in contact with Assange's inner circle told Reuters recently that dismay among WikiLeaks activists over media organisations lost interest in publishing stories based on the material was the rationale for the mass release of documents.</p><p>The source described Assange and his associates as "frustrated" at the lack of media interest.</p><p>Last year WikiLeaks and Assange were celebrated after their release of State Department cables, tens of thousands of other secret US files, and a classified video of a contested American military operation in Iraq.</p><p>Since then public interest in WikiLeaks has waned. It may have suffered from publicity related to Assange's flight to Britain after sexual misconduct allegations were made against him in Sweden and a subsequent protracted extradition fight.</p><p>Assange, who has denied any wrongdoing, has also publicly feuded with former collaborators.</p><p>A person close to Assange said a British appeals court is due to rule early next month on his appeal against Sweden's extradition request. The source was unaware of any link between the latest document dump and the anticipated court decision.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK teen detained as FBI makes PayPal attack arrests ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/635053/uk-teen-detained-as-fbi-makes-paypal-attack-arrests</link>
                                                                            <description>
                            <![CDATA[ Anonymous is being hunted by police across the world, with 20 arrests made in relation to high profile cyber attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tCcbT86QJpkdfGT9MwtybR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GGfVKkANSgua87WcfNqM6o-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Jul 2011 10:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GGfVKkANSgua87WcfNqM6o-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Arrest]]></media:description>                                                            <media:text><![CDATA[Arrest]]></media:text>
                                <media:title type="plain"><![CDATA[Arrest]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GGfVKkANSgua87WcfNqM6o-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A 16 year old male has been arrested in the UK on suspicion of breaching the Computer Misuse Act 1990, as the FBI confirmed arrests as part of investigations into attacks on PayPal.</p><p>It is believed the teenager was apprehended in suspicion of being part of Anonymous. He remains in custody, the Metropolitan Police confirmed.</p><p>The FBI said 16 people had been detained for alleged hacking offences, 14 suspected of involvement in attacks on PayPal.</p><p>Anonymous claimed responsibility for a distributed denial of service (DDoS) hit on PayPal last year, saying it attacked the payments firm due to its withdrawal of support for WikiLeaks. Anonymous said the attack was part of "Operation Avenge Assange."</p><p>A total of 21 arrests across the UK, US and the Netherlands were confirmed yesterday as part of a coordinated operation with the FBI. Investigations into Anonymous and loosely related splinter group LulzSec are thought to be ongoing.</p><p>The teenager in the UK was arrested at a south London address yesterday.</p><p>The 14 individuals arrested in the US were found across the country in Alabama, Arizona, California, Colorado, the District of Columbia, Florida, Massachusetts, Nevada, New Mexico and Ohio.</p><p>Anonymous hit a number of organisations for dropping WikiLeaks support in 2011, including <a href="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge" target="_blank" data-original-url="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge">MasterCard</a> and Visa, as well as PayPal.</p><p>The eBay subsidiary had its Twitter account hijacked earlier this month, as the perpetrators sent out messages criticising PayPal. Attackers put out tweets promoting paypalsucks.com.</p><p>Earlier this year, <a href="https://www.itpro.com/630424/police-make-anonymous-arrests" target="_blank" data-original-url="https://www.itpro.com/630424/police-make-anonymous-arrests">UK police arrested five males</a>, all under the age of 30, in relation to pro-WikiLeaks Anonymous attacks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Visa and MasterCard WikiLeaks donations reopened ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/634777/visa-and-mastercard-wikileaks-donations-reopened</link>
                                                                            <description>
                            <![CDATA[ Julian Assange will be happy to see Visa and MasterCard donations can now be made via WikiLeaks partner DataCell. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rfkfgs4FiDS8gckenrzz5N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nnTY59wAa26nd6cFA2KwHC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Jul 2011 10:47:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nnTY59wAa26nd6cFA2KwHC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WikiLeaks]]></media:description>                                                            <media:text><![CDATA[WikiLeaks]]></media:text>
                                <media:title type="plain"><![CDATA[WikiLeaks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nnTY59wAa26nd6cFA2KwHC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Donations to <a href="https://www.itpro.com/634651/anonymous-claims-apple-login-theft" target="_blank" data-original-url="https://www.itpro.com/634651/anonymous-claims-apple-login-theft">WikiLeaks</a> can now go through Visa and MasterCard, a partner of Julian Assange's enterprise has revealed.</p><p>On 7 December, DataCell's payment gateway, provided by a company called Teller A/S, blocked Visa and MasterCard payments on the request of the credit card companies.</p><p>Last month, DataCell, a WikiLeaks partner, announced it was planning to file a complaint with the EU Commission on the decision to block payments to WikiLeaks. It also planned to commence a lawsuit in Denmark to claim damages.</p><p>Without contacting DataCell, it appears Visa and MasterCard have allowed payments to WikiLeaks, albeit through a gateway provided by a different company, not Teller A/S.</p><p>"We have observed that an alternative payment processor that we have contracted with, has in fact opened the gateway for payments with Visa and Mastercard, and now also for American Express Card payments, which is an option we did not had before," explained DataCell chief executive (CEO), Andreas Fink.</p><p>"We choose to interpret this, as that Visa and Mastercard has in fact given in to our demand that the payment services was reinstated. In other words DataCell is happy to report that we are now able again to process donations to Wikileaks."</p><p>Despite the developments, DataCell said it would go ahead with the lawsuit in Denmark and most likely still lodge a complaint with the European Commission.</p><p>When Visa and MasterCard started blocking payments to WikiLeaks, <a href="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge" target="_blank" data-original-url="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge">hacking group Anonymous responded by targeting the two firms</a>, taking down the latter's website.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anonymous claims Apple login theft ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/634651/anonymous-claims-apple-login-theft</link>
                                                                            <description>
                            <![CDATA[ Anonymous claims to have taken Apple users' passwords and logins, whilst a loosely affiliated group takes control of a Fox News Twitter feed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oNHiJBD19BLnMnig4iCEFw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cNmdVKKg4aYrWKbCpAgWmW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Jul 2011 15:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Apple]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cNmdVKKg4aYrWKbCpAgWmW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Anonymous]]></media:description>                                                            <media:text><![CDATA[Anonymous]]></media:text>
                                <media:title type="plain"><![CDATA[Anonymous]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cNmdVKKg4aYrWKbCpAgWmW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hacktivist group Anonymous claims to have stolen logins and passwords from Apple.</p><p>Yesterday, <a href="https://www.itpro.com/634132/anonymous-warns-of-spain-arrest-revenge" target="_blank" data-original-url="https://www.itpro.com/634132/anonymous-warns-of-spain-arrest-revenge">Anonymous</a> placed 26 logins and passwords on <a href="http://pastebin.com/tkmZDG9m" target="_blank">Pastebin.com</a>, claiming they came from an Apple server.</p><p>The group indicated the attack was part of the AntiSec campaign, recently launched by the now disbanded LulzSec. Some believed LulzSec was a spin-off of Anonymous.</p><p>"Apple could be target too. But don't worry, we are busy elsewhere," the AnonymousIRC <a href="https://twitter.com/#!/AnonymousIRC" target="_blank">Twitter feed</a> read.</p><p>At the time of publication, Apple had not confirmed whether it had been hacked.</p><p>Anonymous has also leaked details of this year's election in Australia, yesterday posting the fifth of five releases on the Pirate Bay website. That attack also formed part of the AntiSec campaign, which appears to be raging on.</p><p>Fox News Obama death fake</p><p>A group associated with Anonymous has claimed responsibility for taking control of a Fox News politics <a href="https://twitter.com/#!/foxnewspolitics" target="_blank">Twitter feed</a>.</p><p>Earlier today, Independence Day in the US, the account began posting claims Barack Obama had been assassinated.</p><p>"@BarackObama has just passed. The President is dead. A sad 4th of July, indeed. President Barack Obama is dead," one tweet read.</p><p>"We wish @joebiden the best of luck as our new President of the United States. In such a time of madness, there's light at the end of tunnel," said another.</p><p>The Script Kiddies told Stony Brook University's <a href="http://thinksb.com/2011/07/think-talks-with-the-group-that-hacked-a-fox-news-twitter-account" target="_blank">Think Magazine</a> it had taken control of the feed, revealing it had ties with Anonymous.</p><p>"I would consider us to be close in relation [to Anonymous], 2 of the members of our group were members of Anonymous," a representative of the Script Kiddies said.</p><p>"We are looking to find information about corporations to assist with antisec. Fox News was selected because we figured their security would be just as much of a joke as their reporting."</p><p>It appears the Fox News account has not been recovered by the true owner yet.</p><p>WikiLeaks revenge?</p><p>Elsewhere in Anonymous land, WikiLeaks has announced it is planning to take legal action against Visa and MasterCard.</p><p>It is looking at lodging a complaint with the EU Commission after the two credit card firms chose not to allow donations for WikiLeaks to pass through them.</p><p>Anonymous hit Visa and MasterCard last year as a result of the financial institutions' actions.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Most IT departments ‘clueless’ over sensitive files ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/632602/most-it-departments-clueless-over-sensitive-files</link>
                                                                            <description>
                            <![CDATA[ Sensitive files don't appear to mean much to security pros, an Imperva survey suggests. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g5AyYwtzdWSy3KXLMfcwuM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/guQDmdrcMSRjQ6NJjfWRnL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Apr 2011 11:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/guQDmdrcMSRjQ6NJjfWRnL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sensitive data]]></media:description>                                                            <media:text><![CDATA[Sensitive data]]></media:text>
                                <media:title type="plain"><![CDATA[Sensitive data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/guQDmdrcMSRjQ6NJjfWRnL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The majority of IT departments have little idea about how many sensitive files they have or where they are stored, research has revealed.</p><p>Two-fifths of respondents to an Imperva survey carried out at this year's RSA Conference said they were completely clueless about the volume of sensitive files in their organisation.</p><p>Furthermore, almost two-thirds of the security professionals quizzed said they weren't even aware of who had access to such files.</p><p>Nearly a third said their company had lost data due to employees abusing access rights, on purpose or by accident.</p><p>"With so many respondents unsure of how many sensitive files they have and how accessible they are, it indicates a general lack of control over sensitive data, which increases the likelihood of an insider breach," said Amichai Shulman, chief technology officer (CTO) of Imperva.</p><p>"The first step to a solid data security plan is taking inventory of your sensitive files and knowing where they are and who has access to them at all times. Only with this complete picture will you be able to guard against insider threat by detecting when sensitive data is being added or removed, or when an employee is improperly accessing files."</p><p>In more positive findings, 82 per cent of respondents said breaches such as <a href="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us" target="_blank" data-original-url="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us">WikiLeaks</a> inspired them to reconsider security policies.</p><p>However, 57 per cent said they would not be investing more money into data security following the WikiLeaks saga.</p><p>Read on for our look at the <a href="https://www.itpro.com/632590/businesses-must-guard-against-the-enemy-within" target="_blank" data-original-url="https://www.itpro.com/632590/businesses-must-guard-against-the-enemy-within">insider threat</a> and what businesses need to do to protect themselves.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top 10 most embarrassing data breaches ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/632452/top-10-most-embarrassing-data-breaches</link>
                                                                            <description>
                            <![CDATA[ Inspired by a notable security gaffe at BP, we give our rundown of the most embarrassing data breaches in recent memory. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mvzvGMbqjA7b6GT21dtLJm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uyM48mqtNdgxNiRkZp9tGn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Apr 2011 17:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uyM48mqtNdgxNiRkZp9tGn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data security]]></media:description>                                                            <media:text><![CDATA[Data security]]></media:text>
                                <media:title type="plain"><![CDATA[Data security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uyM48mqtNdgxNiRkZp9tGn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Every data breach brings the risk of embarrassing not only the company involved but also those whose information is compromised.</p><p>All too often we see breaches where truly sensitive data, such as medical information, is leaked, harming the organisation's reputation and infringing people's privacy simultaneously.</p><p>As a case in point, this week <a href="https://www.itpro.com/632365/bp-loses-oil-spill-claimant-data" target="_blank" data-original-url="https://www.itpro.com/632365/bp-loses-oil-spill-claimant-data">BP was guilty of losing a laptop</a> containing personal data on around 13,000 claimants from the disastrous Deepwater Horizon oil spill of 2010.</p><p>Given the furore surrounding the oil spill, that particular loss was made all the more embarrassing for the firm.</p><p>Inspired by such epic gaffes, we've drawn together the 10 most mortifying breaches in recent memory.</p><p>10. First ICO fines</p><p>There have been far worse breaches than those that <a href="https://www.itpro.com/628864/ico-deals-out-160000-in-data-breach-fines" target="_blank" data-original-url="https://www.itpro.com/628864/ico-deals-out-160000-in-data-breach-fines">occurred at Hertfordshire County Council and employment services company A4e</a> last year.</p><p>The reason why these two have been included in the list (making it a top 11 really) is that they were the first to be punished with an Information Commisioner's Office fine.</p><p>The anticipation in the lead up to the ICO's first monetary punishments meant whoever was forced to pay up would be left blushing.</p><p>Admittedly, their errors were fairly shaming in themselves. The council was reprimanded for two serious incidents when employees faxed highly sensitive personal information to the wrong recipients.</p><p>A4e had an unencrypted laptop stolen, which contained personal data on 24,000 people who had used community legal advice centres in Hull and Leicester.</p><p>If and when the ICO hands out the maximum 500,000 fine, the guilty organisation can expect to be even more shamefaced.</p><p>This one brings a wry smile to the face. Early last year, a <a href="https://www.itpro.com/620488/shell-hit-by-massive-data-breach" target="_blank" data-original-url="https://www.itpro.com/620488/shell-hit-by-massive-data-breach">database containing contact details of 170,000 workers of oil giant Royal Dutch Shell was emailed to campaigning groups</a> opposed to the company's activities.</p><p>As for how the data was leaked, it was thought to be the work of a disgruntled insider a threat all businesses need to look out for.</p><p>Seven non-governmental groups including human rights groups and environmental campaigners, such as Greenpeace plus anti-Shell campaigning website royaldutchshellplc.com received the database details.</p><p>The data included names, telephone numbers and further details on permanent and contract employees. Not hugely important data in itself, but you can't deny the recipients of the leak makes this a rather interesting case.</p><p>8. BNP breach</p><p>It was another disaffected employee who embarrassed the British National Party back in 2008 when they published a membership list online.</p><p>Following the leak by an ex-senior member of the party, members of the controversial political group said they received threatening and abusive phone calls and emails.</p><p>It came at a time when the BNP was looking to make a name for itself as a viable entity. The breach only made them look a little unstable from within.</p><p>When party leader Nick Griffin started claiming the Labour Party was behind the threatening calls as part of a "dirty tricks campaign," it came across as somewhat desperate.</p><p>You see, managing the aftermath of a data breach is as important as how you deal with it at the time. Griffin didn't come across as the calm and collected leader many IT heads and CEOs manage to pull off following data losses.</p><p>7. English Defence League hack</p><p>Well if we were going to mention the BNP breach we had to do the English Defence League (EDL) one too, right?</p><p>In this more recent incident, <a href="https://www.itpro.com/629611/right-wing-edl-group-hacked" target="_blank" data-original-url="https://www.itpro.com/629611/right-wing-edl-group-hacked">an EDL database was hacked</a> and members' information was stolen by a group known as the Mujahideen Hacking Unit.</p><p>Admittedly, the EDL handled the breach somewhat better than Griffin did. The far-right group simply apologised and warned members names and addresses had been taken both from its clothing site and the organisation's donation database.</p><p>The hack may have been inspired by the EDL's involvement in the furore surrounding the Koran-burning American preacher Pastor Terry Jones, who was due to attend an EDL rally in February.</p><p>The EDL decided to cancel the rally but no reasons were given at the time as to why. Either way, the group's opponents were left smirking, whilst the EDL had to pick up the pieces looking a little rosy around the cheeks and not in the good way.</p><p>6. ACS:Law</p><p>ACS:Law was under enough scrutiny as it was before <a href="https://www.itpro.com/627259/ico-to-investigate-acslaw-data-breach" target="_blank" data-original-url="https://www.itpro.com/627259/ico-to-investigate-acslaw-data-breach">suffering a harmful data breach</a>.</p><p>The firm had been sending out thousands of letters to people its clients suspected of illegally sharing copyrighted content an action that brought heavy criticism from numerous sides.</p><p>The leaked data was actually stored by the law firm to track P2P users sharing copyrighted pornographic films, possibly illegally.</p><p>Activists from 4chan, the image board website where Anonymous often hangs out, were behind the hack, but many pointed the finger at ACS:Law itself.</p><p>Privacy International claimed ACS:Law breached the Data Protection Act by allowing an archive containing sensitive data to be stored on a public facing web server, and the ICO said it was going to investigate.</p><p>The breach was another nail in the coffin for the law firm, which has now folded altogether.</p><p>"The slurping of AT&T data on the early iPad 3G adopters by Goatse was pretty embarrassing too," Rik Ferguson, director of security research and communication at Trend Micro, told <em>IT PRO</em>, and indeed it was.</p><p>The hackers from Goatse Security, who claimed they were only trying to expose flaws on AT&T's side, exploited holes in AT&T servers to siphon off personal info of around 114,000 customers.</p><p>Among the possible victims were celebrities, business executives and government officials, including New York City Mayor Michael Bloomberg.</p><p>When that amount of data goes missing, it's always going to be bad for the company on the wrong end of the breach.</p><p>What made matters worse was the murkiness that surrounded the aftermath.</p><p>Daniel Spitler and Andrew Auernheimer were arrested in January, but Auernheimer, who claimed to have only publicised the flaws rather than exploit them, had already been apprehended in 2010 on drug charges.</p><p>There was plenty of <a href="https://www.itpro.com/625000/att-ipad-hack-exposer-breaks-gag-order" target="_blank" data-original-url="https://www.itpro.com/625000/att-ipad-hack-exposer-breaks-gag-order">back and forth between Goatse and investigators</a>, with Auernheimer claiming his civil liberties had been "grossly violated." The Goatse member said the authorities had treated him unfairly and had even denied him a public defence lawyer.</p><p>The defendants were eventually each charged with one count of fraud and one count of conspiracy to access a computer without authorisation.</p><p>Whatever happens to the two young men, for everyone involved, the breach was one mightily unpleasant event.</p><p>4. RSA recent, mention Kaspersky</p><p>It's always bad when a security company gets hit by a cyber attack, but when it threatens the effectiveness of one of their products, then it becomes all the more humiliating.</p><p>We saw last year the impact a <a href="https://www.itpro.com/627817/updated-kaspersky-hit-by-cyber-criminals" target="_blank" data-original-url="https://www.itpro.com/627817/updated-kaspersky-hit-by-cyber-criminals">hack on a Kaspersky website</a> had. In that case, hackers exploited a vulnerability in a third party app used for website admin.</p><p>Just last month, though, a much more serious hack led to a rather significant data breach. When RSA, the security arm of EMC, had its <a href="https://www.itpro.com/632023/rsa-servers-hacked-as-securid-data-stolen" target="_blank" data-original-url="https://www.itpro.com/632023/rsa-servers-hacked-as-securid-data-stolen">servers hacked</a>, data on its two-factor authentication product SecurID was compromised.</p><p>The firm admitted the data could have been used to "reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack," and RSA urged customers to take immediate remedial action.</p><p>But RSA will need to take its own remedial action something that could cost the company plenty of money and time.</p><p>There are a number of questions still hanging over the breach, like how many, if any, tokens will need to be replaced?</p><p>As with many breaches, this one could turn out to be worse than initially feared. For RSA's sake, and for it's customers, let's hope not.</p><p>3. HBGary vs. Anonymous</p><p>Another security company, HBGary, was <a href="https://www.itpro.com/631042/anonymous-empire-strikes-back-against-hbgary" target="_blank" data-original-url="https://www.itpro.com/631042/anonymous-empire-strikes-back-against-hbgary">hounded by hacktivist group Anonymous</a> and ended up looking fairly red in the face.</p><p>It all started when HBGary started going after Anonymous and tried to uncover who was running the show. When chief executive (CEO) Aaron Barr, who eventually left the firm, said he had information on those in the upper echelons of the activist organisation, Anonymous went after HBGary.</p><p>It was when Anonymous started leaking tens of thousands of emails from the firm that the embarrassment levels went up a notch. No one likes to see their dirty laundry aired in public, but that's what happened.</p><p>Details emerged on how HBGary worked with Government bodies in the US, showing how they had created malware and rootkits. Nothing truly awful emerged, but it was bad enough that the firm had its private conversations revealed to the world.</p><p>Anonymous also defaced HBGary's website and gained control over Rootkit.com, a site launched by HBGary founder Greg Hoglund, just to add to the security firm's woes.</p><p>Anyone going after Anonymous will want to ensure their security is really up to scratch, or they could suffer like HBGary has.</p><p>The <a href="https://www.itpro.com/140490/hmrc-data-breach-affects-25-million" target="_blank" data-original-url="https://www.itpro.com/140490/hmrc-data-breach-affects-25-million">breach at HM Revenue and Customs</a> (HMRC) in 2007 was one of the most significant in the history of the UK. Many have seen it as a watershed moment in the security industry.</p><p>Two disks went missing containing personal and banking data of 25 million people, leading to the resignation of HMRC head Paul Gray. It was the ultimate data boo-boo.</p><p>"It affected every single family with children in the UK and as far as I'm aware the lost data has never been located," said Ferguson.</p><p>"It led to the Hannigan report and a series of recommendations for improving data handling in government."</p><p>If anything like this happens again, it will only be worse for the Government department involved. Now people recognise the value of data on a broader scale, the Coalition needs to ensure it doesn't slip up like Labour did.</p><p>1. WikiLeaks</p><p>We hardly need go into detail about the embarrassment the WikiLeaks saga has caused. Of course, the US Government was left looking silly simply because it let the various pieces of classified information escape its grasp. It was astonishing such data could get out, allegedly through one person's actions.</p><p>However the breach happened it surely wasn't as simple as someone downloading data to a CD and then walking out of Government buildings it provided plenty of potentially damaging information for everyone to get hold of.</p><p>Amongst the highlights was the revelation the US Government refused to allow Gary McKinnon to serve his sentence in the UK even after a <a href="https://www.itpro.com/629008/wikileaks-brown-requested-uk-sentence-for-mckinnon" target="_blank" data-original-url="https://www.itpro.com/629008/wikileaks-brown-requested-uk-sentence-for-mckinnon">plea from former Prime Minister Gordon Brown</a>.</p><p>Last month, the US Army brought 22 new charges against Bradley Manning, the soldier accused of leaking the cables, so this is another case that is far from closed.</p><p>What's clear is that data breaches don't disappear for a long time after they occur. Indeed, the most significant ones may never be forgotten.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google accuses China of Gmail tampering ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/632050/google-accuses-china-of-gmail-tampering</link>
                                                                            <description>
                            <![CDATA[ Google suggests the Chinese Government is to blame for Gmail disruptions. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eUGiDy5tT5d1xvYbMRzseq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iTN9dReCHZkAZFfTrKqRdk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Mar 2011 10:44:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iTN9dReCHZkAZFfTrKqRdk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[China]]></media:description>                                                            <media:text><![CDATA[China]]></media:text>
                                <media:title type="plain"><![CDATA[China]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iTN9dReCHZkAZFfTrKqRdk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has accused China of targeting its Gmail service in the country, claiming the Government had carefully engineered problems with the client.</p><p>Chinese companies and customers had complained about disruptions to their Gmail accounts in recent weeks, reports suggested.</p><p>"There is no technical issue on our side. We have checked extensively," a Google spokesperson said.</p><p>"This is a Government blockage carefully designed to look like the problem is with Gmail."</p><p>The claims come after China reportedly clamped down on internet protests, some calling for a "Jasmine Revolution," following similar campaigns across the Middle East.</p><p>Earlier this month, <a href="https://www.itpro.com/631879/google-patches-webkit-flaw-post-pwn2own" target="_blank" data-original-url="https://www.itpro.com/631879/google-patches-webkit-flaw-post-pwn2own">Google complained about a number of politically motivated attacks</a> on its users, although there was no mention of Gmail then.</p><p>Google said a vulnerability affecting Internet Explorer (IE) was exploited in the attacks.</p><p>The flaw in MIME HTML (MHTML) a protocol used by applications to render certain kinds of documents and bring together different content onto one HTML file - was <a href="https://www.itpro.com/630508/microsoft-warns-of-windows-zero-day" target="_blank" data-original-url="https://www.itpro.com/630508/microsoft-warns-of-windows-zero-day">publicly disclosed in January</a>.</p><p>This isn't the first time Google has blamed China for attacks on its users.</p><p>In what became known as the Aurora saga, the web giant threatened to pull out of the country, claiming Google data had been stolen and Gmail accounts of human rights activists had been compromised.</p><p>Businesses were also reportedly targeted by the same hackers, including financial services firm Morgan Stanley.</p><p>The Chinese administration has denied the accusations, however, calling them "groundless aims to denigrate China."</p><p>A WikiLeaks cable released by the <a href="http://www.nytimes.com/2010/11/29/world/29cables.html?_r=2" target="_blank">New York Times</a> towards the end of last year <a href="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us" target="_blank" data-original-url="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us">further implicated China in the attacks</a>.</p><p>The leak claimed to cover communications from a Chinese contact telling the American Embassy in Beijing the Politburo had ordered a hack attack on Google.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anonymous empire strikes back against HBGary ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/631042/anonymous-empire-strikes-back-against-hbgary</link>
                                                                            <description>
                            <![CDATA[ Anonymous leaks more emails as its tussle with HBGary heats up. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j33HEimdgkaX4JRL7Kv8hV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/o3MDTGNSgRuuXrH6sBvMJo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Feb 2011 17:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alvaro Guzman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/o3MDTGNSgRuuXrH6sBvMJo-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data security]]></media:description>                                                            <media:text><![CDATA[Data security]]></media:text>
                                <media:title type="plain"><![CDATA[Data security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/o3MDTGNSgRuuXrH6sBvMJo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anonymous has leaked another set of emails from security firm HBGary, with revenge being the chief motivation.</p><p>The hacker group used Swedish website The Pirate Bay as its platform to leak the data in the form of a torrent archive. The 27,606 HBGary emails come from the total 71,802 that Anonymous had at its disposal.</p><p>HBGary had been working with the FBI to identify Anonymous' members. Earlier this month, HBGary's chief executive, Aaron Barr, said in an interview with the Financial Times that he had discovered the identities of Anonymous members. The <a href="https://www.itpro.com/630754/anonymous-hackers-hit-fbi-collaborator" target="_blank" data-original-url="https://www.itpro.com/630754/anonymous-hackers-hit-fbi-collaborator">hacktivist group responded instantly</a>, infiltrating HBGary's network and website, as well as Barr's Twitter account.</p><p>Anonymous leaked much but not all - of the information it found. Now the group has leaked what seems to be the remaining data.</p><p>The reason? Judging from the message Anonymous posted as the torrent's description, there seems to have been a combination of two causes: revenge and responsibility.</p><p>Anonymous devoted most of its message directly addressed to HBGary - to attacking the cyber security firm.</p><p>After referring to the 'humiliation' it made HBGary suffer with the first attack, Anonymous went on to justify the second leak.</p><p>"We were willing to stop attacking you," the group said. "We were even willing to leave you be entirely - but now you have provoked us, and there will be no mercy."</p><p>The purported provocation was a public threat, coming from Greg Hoglund, chief operating officer of HBGary, who had reportedly been pushing legal action against Anonymous.</p><p>"Let's not forget that the first time you tried to do something like this, we did not overlook it, and we are not overlooking it now," Anonymous warned.</p><p>But what seems to have upset Anonymous most was the claim that it falsified information.</p><p>Anonymous' response was straight: "Anonymous has falsified nothing."</p><p>The hacktivist group said it had leaked the full content of HBGary's inboxes, with no edits and defended itself by saying most of the leaked emails contained digital signatures, proving they were authentic.</p><p>"This information is now free to the public, and you honestly think you can wriggle your way out of it by accusing Anonymous of tampering with your data?" the group concluded.</p><p>Going a step forward in defence of Julian Assange's organisation, Anonymous added that it will fight those firms which work against the likes of WikiLeaks.</p><p>Elsewhere, a member of Anonymous has bragged about acquiring the code for <a href="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet" target="_blank" data-original-url="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet">Stuxnet</a>. A tweet from atopiary read: "Anonymous is now in possession of Stuxnet - problem, officer?"</p><p>However, Snorre Fagerland, a senior threat researcher at Norman IT Security, claimed in a tweet that Anonymous only had Stuxnet binaries and disassembly, not the original source.</p><p>"Nothing new from what is already public," Fagerland added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Western Europe spam drop ‘significant’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/630664/western-europe-spam-drop-significant</link>
                                                                            <description>
                            <![CDATA[ A significant spam drop was seen across Western Europe in December, Kaspersky says. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uwiB9Q9pfN4dGPJxLgY5Ya</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NozcAbBtaNSMRZfnqPj9x8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Feb 2011 12:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NozcAbBtaNSMRZfnqPj9x8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NozcAbBtaNSMRZfnqPj9x8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Both Western Europe and the US have seen a notable fall in spam, according to Kaspersky Lab.</p><p>Despite seeing declines, the UK still put out more than both France and Germany, being responsible for 4.3 per cent of all global spam in December, the Russian security giant found.</p><p>India was the biggest spamming offender, sending out nearly 10 per cent of all spam, whilst Russia came in second place.</p><p>Kaspersky praised the anti-botnet campaigns undertaken in the West for contributing to the fall in spam.</p><p>Last November, <a href="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns" target="_blank" data-original-url="https://www.itpro.com/628522/spam-falls-after-giant-botnet-takedowns">a drop in spam</a> was largely attributed to the closure of over 20 control centres used by the Pushdo/Cutwail botnet, as well as the <a href="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down" target="_blank" data-original-url="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down">Bredolab shutdown</a>.</p><p>The UK also saw its share of all malware detected in email traffic drop to below three per cent, meaning the nation fell to 10th place overall, having been in the top three until October.</p><p>"Immediately before the start of the holidays we witnessed a dip in the amount of spam," said Maria Namestnikova, senior spam analyst at Kaspersky Lab.</p><p>"This is a seasonal phenomenon at the end of the year the amount of spam mailings always falls off because a lot of the infected botnet computers are switched off."</p><p>WikiLeaks</p><p>Spammers still used current affairs in December, hitting on the WikiLeaks affair in particular.</p><p>Kaspersky noted numerous cases where spammers had called on users to spread WikiLeaks links, supposedly in support of democracy.</p><p>To get around spam filters, spammers included WikiLeaks in background noise texts, including material actually published from the site.</p><p>Sometimes the culprits had included WikiLeaks in links to try and evade filters.</p><p>"Spam is usually dominated by the Christmas and New Year holiday theme in December, but in 2010 it had to share the limelight with WikiLeaks, which once again underlines just how serious the scandal surrounding the website was at the end of the year," Namestnikova added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security threats to beware in 2011 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629674/security-threats-to-beware-in-2011</link>
                                                                            <description>
                            <![CDATA[ We take a look ahead to what threats await us in 2011. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nAKwDcS1izxt9tHd4b7C7u</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BN8twNFkK8HaefoY3TgXv5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Jan 2011 10:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BN8twNFkK8HaefoY3TgXv5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[2011]]></media:description>                                                            <media:text><![CDATA[2011]]></media:text>
                                <media:title type="plain"><![CDATA[2011]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BN8twNFkK8HaefoY3TgXv5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In 2010 many of the security predictions made in the previous year came true, from increasing attacks on social networks to more mobile malware.</p><p>Clear trends emerge each year and 2011 looks likely to be no exception to the rule.</p><p>Whilst it is extremely challenging to predict the exact nature of future threats, it is certainly viable to map out possible occurrences.</p><p>With this in mind, we look at what some of the industry's more prescient security experts expect to see next year.</p><p>War, what is it good for?</p><p>So much talk this year focused on <a href="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet" target="_blank" data-original-url="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet">Stuxnet</a>. Whilst Microsoft has patched up all the holes Stuxnet was exploiting and the incredibly sophisticated piece of kit has been outed, what it made clear was that nation states are getting serious about cyber warfare.</p><p>Now Stuxnet has made its mark, it would not be a huge surprise if a country's critical infrastructure was impacted in a major way in 2011. Indeed, Websense said similar exploits will be carried out once or twice in 2011.</p><p>Whilst copycats will not be hugely prevalent next year, they could certainly be trickier to detect.</p><p>"Compared to the number of more traditional cyber criminal attacks that will occur, those with Stuxnet's level of sophistication will be few and far between," said Alexander Gostev, chief security expert at Kaspersky Lab.</p><p>"However, when they do, they will be potentially far harder to detect and as they are unlikely to affect the average user, the majority of victims are unlikely to ever know they have been targeted."</p><p>Nevertheless, nations will be busy shoring up their security across departments next year and preparing their armies to make strikes against hostile nations.</p><p>Hacktivism</p><p>Tech portmanteaus are often irritating beasts but there is something rather cool about hacktivism' it just seems to fit.</p><p>Anyone involved in the Anonymous hacktivist group was no doubt clinking champagne glasses when New Year's Eve rolled around after a 2010 in which they <a href="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge" target="_blank" data-original-url="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge">made headline news</a> for their pro-WikiLeaks DDoS attacks.</p><p>Anonymous hackers were also <a href="https://www.itpro.com/629011/hackers-launch-ddos-attacks-in-pirate-bay-rage" target="_blank" data-original-url="https://www.itpro.com/629011/hackers-launch-ddos-attacks-in-pirate-bay-rage">involved in attacks on anti-piracy sites</a>, so expect their work to continue in any left-wing agenda that goes under their radar. No doubt as the WikiLeaks saga runs on, other firms who pull the plug from Julian Assange's operation will be on the wrong end of a DDoS strike.</p><p>"Despite hasty attempts in many countries to pass legislation to counter this type of activity, effectively by criminalising it, we believe that in 2011 there will be yet more cyber protests, organised by this group or others that will begin to emerge," Panda said.</p><p>Many predicted social networks would become virtual playgrounds for hackers in 2010 and they were right. Disconcertingly, 2011 looks likely to get even worse, according to a wide range of security experts.</p><p>Joona Airamo, chief information security officer at Stonesoft, warned one attack could affect millions of users.</p><p>"Hackers will use malware that copies a user's address book and sends out malicious emails/files to all their friends," he said.</p><p>"Just like the old email scams, the malicious file will look like it has been sent from the initial target so recipients will trust the source."</p><p>Given the introduction of <a href="https://www.itpro.com/628633/facebook-messages-need-to-know" target="_blank" data-original-url="https://www.itpro.com/628633/facebook-messages-need-to-know">Facebook Messages</a>, an attack like the one Airamo outlined could become even more widespread. With some hope, Zuckerberg and Co will be on their security game to protect users.</p><p>Social engineering will continue to be big in 2011 in general, with Trend Micro claiming cyber criminals will launch malware campaigns by bombarding unwitting users with emails that "drop downloaders" containing malware.</p><p>Rising zero-days</p><p>In 2010, zero-day threats were disturbingly common, affecting various pieces of much-used technology, including <a href="https://www.itpro.com/626245/adobe-plugs-critical-security-holes" target="_blank" data-original-url="https://www.itpro.com/626245/adobe-plugs-critical-security-holes">Adobe Reader</a>, <a href="https://www.itpro.com/628894/zero-day-windows-flaw-goes-public" target="_blank" data-original-url="https://www.itpro.com/628894/zero-day-windows-flaw-goes-public">Windows</a> and <a href="https://www.itpro.com/628336/new-zero-day-flaw-hits-microsofts-internet-explorer" target="_blank" data-original-url="https://www.itpro.com/628336/new-zero-day-flaw-hits-microsofts-internet-explorer">Internet Explorer</a>.</p><p>This year, expect to see plenty more such sudden dangers and vendors scrambling to issue fixes.</p><p>"Zero-day vulnerabilities are widely considered something of a common occurrence. Sadly, that trend is set to continue in 2011, with zero-day threats becoming even more prevalent," said Kaspersky's Gostev.</p><p>"The rise in malicious exploits that seize on programming errors won't just be down to new vulnerabilities they will also occur because of the speed at which cyber criminals react to such loopholes."</p><p>Whilst Windows will remain the chief target for hackers, in terms of operating systems, cyber criminals will look to spread their net further as Microsoft's market share is eaten away by the likes of Apple's different offerings.</p><p>Already this year there has been a significant rise in malware targeting Apple users and a specialist version of the <a href="https://www.itpro.com/628150/koobface-turns-eyes-towards-macs" target="_blank" data-original-url="https://www.itpro.com/628150/koobface-turns-eyes-towards-macs">notorious Koobface worm was spotted</a>.</p><p>"As the Apple OS becomes more commonly used, there will be a nasty worm or virus which is going to target it specifically," said Stonesoft's Airamo.</p><p>Of course, Windows will remain the central target for hackers given the dominance it has over competitors, but there will be a change in tactics amongst cyber criminals, explained David Harley, senior research fellow at ESET.</p><p>"While there won't be a big shift towards specific targeting of other operating systems, as more people start using them, there will be increased interest in finding weaknesses." Harley said.</p><p>Mobile and consumerisation</p><p>As workers get increasingly mobile and as they use the same device for personal and business use, the more threats IT administrators are likely to face.</p><p>The fact is, with manufacturers like Apple, Google and Microsoft trying to cater to both businesses and consumers, and with the move to the cloud, people are entering the workspace expecting to be able to use a range of devices for work and pleasure.</p><p>"With the blurring of the lines between business and personal use, the increased sophistication of the devices and the consolidation of mobile platforms, it is inevitable that attackers will key in on mobile devices in 2011 and mobile devices will become a leading source of confidential data loss," Symantec said in a <a href="http://www.symantec.com/connect/blogs/survey-results-here-are-your-predictions-internet-security-2011" target="_blank">blog</a> post.</p><p>In a Symantec survey, over half of respondents said they will install security software on their mobile device in the future, so at least some are realising the threat facing smartphones and tablets.</p><p>Hopefully, 2011 will also be the year when everyone begins to understand the importance of securing their companies' and their own data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top 10 security threats of 2010 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629617/top-10-security-threats-of-2010</link>
                                                                            <description>
                            <![CDATA[ We list our top 10 threats of 2010 and their impact on the security industry as a whole. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sUCky69C8pFaHmb2eK6HVb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hLSZKG4LsFKfKPGktES2Rn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Dec 2010 08:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hLSZKG4LsFKfKPGktES2Rn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top 10]]></media:description>                                                            <media:text><![CDATA[Top 10]]></media:text>
                                <media:title type="plain"><![CDATA[Top 10]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hLSZKG4LsFKfKPGktES2Rn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The number of threats now on the web is incalculable given the rate at which they are amassing.</p><p>Nevertheless, there are those that make more of an impact than others and 2010 has been a year full of big moments.</p><p>We take a look back at some of the most significant threats, taking into consideration both their prevalence and industry impact.</p><p>10. Adobe exploits</p><p>Adobe had an up and down year, but it had plenty to contend with in the security space. The number of exploits affecting its software was disconcerting, even more worrying when looking at the <a href="https://www.itpro.com/627946/adobe-zero-day-flaw-code-published" target="_blank" data-original-url="https://www.itpro.com/627946/adobe-zero-day-flaw-code-published">zero-day threats</a> affecting the likes of Reader and Flash.</p><p>It is the prevalence of the software that makes it most concerning, yet Adobe is clearly taking steps to shore up its defences, in particular with some <a href="https://www.itpro.com/628765/adobe-boosts-security-with-reader-x" target="_blank" data-original-url="https://www.itpro.com/628765/adobe-boosts-security-with-reader-x">sandboxing technology</a>.</p><p>9. Mobile malware</p><p>As expected, smartphones increasingly became a target for data-hungry crooks. Android was under plenty of scrutiny, with malware targeting the Google OS found to have <a href="https://www.itpro.com/629452/malware-targeting-google-android-quadruples-in-2010" target="_blank" data-original-url="https://www.itpro.com/629452/malware-targeting-google-android-quadruples-in-2010">quadrupled in 2010</a>.</p><p>One of the most widely reported smartphone stories of the year focused on the <a href="https://www.itpro.com/625972/apple-fixes-jailbreakme-flaws" target="_blank" data-original-url="https://www.itpro.com/625972/apple-fixes-jailbreakme-flaws">JailbreakMe</a> app, which exploited security holes to allow non-approved apps to run on the phone. Whilst the app proved popular, the fact was the flaws could have allowed hackers to compromise iPhones.</p><p>Apple duly closed the vulnerabilities that JailbreakMe had used, but expect to see similar apps to appear in the coming months.</p><p>8. Mariposa</p><p>The <a href="https://www.itpro.com/625579/fbi-captures-mariposa-mastermind" target="_blank" data-original-url="https://www.itpro.com/625579/fbi-captures-mariposa-mastermind">Mariposa</a> botnet was a mega-botnet with control over nearly 13 million computers. Various arrests were made, with the mastermind taken into custody in Slovenia after a global effort from law enforcement.</p><p>The successful identification and arrests surrounding Mariposa raised a major theme of 2011: it may have been one of the best years yet for cyber crime takedowns, but the scale of the threats was startling nonetheless.</p><p>Mariposa was a sign of good things to come in terms of takedowns in the botnet sphere. Whilst such malicious networks had undoubtedly been causing havoc before 2010, but this year law enforcement really upped its game.</p><p><a href="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down" target="_blank" data-original-url="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down">Bredolab</a> was certainly one of the largest botnets ever seen, having over 30 million systems in its grasp.</p><p>In a high point for police and the IT security industry at large, Dutch police disconnected 143 servers which were helping run the botnet. Subsequently, Armenian police arrested a man believed to be the mastermind behind the operation.</p><p>6. Mac threats</p><p>2010 was surely the year when security professionals tried their hardest to dispel the myth that Macs are impenetrable machines. This was highlighted by a number of specialist Mac security offerings launched this year, including those from <a href="https://www.itpro.com/625384/mcafee-breaks-into-mac-security-sphere" target="_blank" data-original-url="https://www.itpro.com/625384/mcafee-breaks-into-mac-security-sphere">McAfee</a> and Panda Security.</p><p>The latter released a report indicating Mac OS vulnerabilities had <a href="https://www.itpro.com/627904/mac-os-vulnerabilities-skyrocket" target="_blank" data-original-url="https://www.itpro.com/627904/mac-os-vulnerabilities-skyrocket">increased more than five-fold</a> in less than a year. Elsewhere, a Mac version of the infamous Koobface worm was <a href="https://www.itpro.com/628150/koobface-turns-eyes-towards-macs" target="_blank" data-original-url="https://www.itpro.com/628150/koobface-turns-eyes-towards-macs">discovered</a> for the first time.</p><p>The evidence indicated Mac users are indeed safer than PC users, but what is clear is that hackers will go where the users are. As the number of Apple acolytes escalates, so will the number of threats facing their systems. The same goes for other operating systems and machines as well.</p><p>5. Facebook scams</p><p>As expected, social networks were a big target for cyber criminals in 2010. Facebook, being the most popular such service, was always going to be a hotbed for scammers trying out their luck.</p><p>One of the more concerning threats emerged at the start of the year, when hackers <a href="https://www.itpro.com/621652/latest-facebook-scam-could-affect-millions" target="_blank" data-original-url="https://www.itpro.com/621652/latest-facebook-scam-could-affect-millions">posed as Facebook officials</a> to obtain user login details.</p><p>Many scams were based around celebrities one of them focusing on a picture of a supposedly aroused Justin Bieber. Others looked to entice the slightly more disturbed minds on Facebook, offering particularly macabre content.</p><p>It's depressing, but expect to see this kind of threat sticking around as hackers have discovered they can make money from surveys that users are directed to as they hunt for seedy content.</p><p>4. Unprotected Wi-Fi exploits</p><p>Despite data security concerns growing in prominence amongst non-IT people, the fact is many clearly still used unprotected Wi-Fi networks throughout 2010.</p><p>This was brought to light by one hacker, who created the <a href="https://www.itpro.com/628438/firesheep-killer-blacksheep-launched" target="_blank" data-original-url="https://www.itpro.com/628438/firesheep-killer-blacksheep-launched">Firesheep tool</a>. This sniffed out login credentials for social networking sites from users on unprotected Wi-Fi hotspots. Worryingly, the tool was downloaded over 100,000 times in the first 24 hours following its launch and even spawned a copycat add-on in the form of something charmingly called 'idiocy.'</p><p>There was also the little matter of <a href="https://www.itpro.com/628351/timeline-google-street-view-scandal" target="_blank" data-original-url="https://www.itpro.com/628351/timeline-google-street-view-scandal">Google taking data</a> over unprotected Wi-Fi networks during its Street View project, but that was accidental according to the search firm. Nevertheless, the point is, everyone should stick to using secured networks and nothing else.</p><p>3. Zeus</p><p>Zeus, in its various guises, remained a major threat in 2010. Banks were the target and in August it emerged <a href="https://www.itpro.com/625891/zeus-3-attack-steals-675000-from-uk-bank" target="_blank" data-original-url="https://www.itpro.com/625891/zeus-3-attack-steals-675000-from-uk-bank">an unnamed UK financial institution had been hit</a>, with 3,000 customer accounts compromised and 675,000 stolen between 5 July and 6 August.</p><p>Startlingly, earlier in the year, an RSA study indicated almost nine in 10 Fortune 500 companies in the US had</p><p><a href="https://www.itpro.com/622411/most-of-fortune-500-hit-by-zeus-trojan" target="_blank" data-original-url="https://www.itpro.com/622411/most-of-fortune-500-hit-by-zeus-trojan">potentially been affected by the Zeus Trojan</a>.</p><p>In better news for the good guys, the Police Central e-Crime Unit officers <a href="https://www.itpro.com/627286/19-arrested-in-zeus-bank-fraud-bust" target="_blank" data-original-url="https://www.itpro.com/627286/19-arrested-in-zeus-bank-fraud-bust">arrested 19 people</a> suspected of being involved in a multi-million pound bank account theft that used Zeus.</p><p>2. DDoS</p><p>Distributed Denial of Service (DDoS) attacks have been around for years. Everyone knows the deal in layman's terms - you make so many requests for a website that it fails to function.</p><p>What led us to include DDoS strikes in the top 10 list was its use in the <a href="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us" target="_blank" data-original-url="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us">WikiLeaks saga</a>. As a result of the myriad attacks on both WikiLeaks itself and against organisations refusing to support Julian Assange and Co, the wider public became aware of what DDoS actually was.</p><p>Rarely does a threat become common knowledge outside of the tech industry and for this reason alone, this old threat was a big deal in 2010.</p><p>1. Stuxnet</p><p><a href="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet" target="_blank" data-original-url="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet">Stuxnet</a> was actually let loose in 2009, but it wasn't detected until 2010. When it was finally found, it caused some serious ripples in the security industry.</p><p>The fact it took advantage of four different exploits - something unprecedented according to most experts in the field - was just half the story.</p><p>Once people had dug under the surface, it became clear Stuxnet was almost certainly the work of a nation state. After researchers discovered it was going after controls at industrial plants and a number of officials in Iran hinted their nuclear operations had been hit, it was clear this was a game changer.</p><p>Whilst it was not the most prevalent threat of 2010, what it did was change the security landscape forever, perhaps more than any other piece of malicious kit that has come before.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security: Year in review 2010 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629644/security-year-in-review-2010</link>
                                                                            <description>
                            <![CDATA[ It's been a huge year for the security industry. We look back at some of the biggest moments of 2010. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3C54kU1woUSp7SLdvdXXzS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ts3gnLsuH79x762jxKYpPE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Dec 2010 08:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Wifi and Hotspots]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ts3gnLsuH79x762jxKYpPE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[2010]]></media:description>                                                            <media:text><![CDATA[2010]]></media:text>
                                <media:title type="plain"><![CDATA[2010]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ts3gnLsuH79x762jxKYpPE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It has been a monumental year for cyber security, perhaps the most significant 12 months ever.</p><p>The entire sector has grown in prominence both within the IT industry and outside. There have been some truly watershed moments, from serious political moves to giant acquisitions.</p><p>There is little doubt about it 2010 will be ingrained in the memory of many security professionals for some time to come. We take a look back at the biggest moments.</p><p>Getting political Cyber warfare emerged as a massive issue this year. Before 2010, governments had barely touched on the issues at hand, at least not openly. But a <a href="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us" target="_blank" data-original-url="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us">hack on Google</a> thought to emanate from China became well-publicised at the beginning of the year and things started to heat up.</p><p>And then the most sophisticated piece of malware ever seen was detected. After it was spotted by a relatively unknown company from Belarus named VirusBlokAda, <a href="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet" target="_blank" data-original-url="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet">Stuxnet</a> emerged as no ordinary threat. Not only did the creators manage to empower it to exploit four zero-day vulnerabilities, Stuxnet could manipulate programmable logic controllers (PLCs).</p><p>Basically, it had the potential to mess around with industrial controls. Interestingly, many of the infections were found to be in Iran, which led some to speculate that the malware had been created by a nation state. Indeed, this now looks likely, as Iranian officials even admitted the country's <a href="https://www.itpro.com/627223/stuxnet-hits-iran-nuclear-plant" target="_blank" data-original-url="https://www.itpro.com/627223/stuxnet-hits-iran-nuclear-plant">critical infrastructure had been targeted</a> by Stuxnet.</p><p>It is yet to be determined if Stuxnet managed to cause any real-world damage, although a German expert recently told the <a href="http://www.jpost.com/IranianThreat/News/Article.aspx?id=199475" target="_blank">Jerusalem Post</a> the malware had put Iran's nuclear programme back by two years.</p><p>The ripples Stuxnet made seemed to lead to a shift in the mindsets of politicians across the globe. In the UK, the Government announced additional funding for fighting cyber crime and ranked it alongside terrorism, chemical attacks and natural disasters as one of the <a href="https://www.itpro.com/627793/cyber-crime-one-of-the-biggest-threats-to-uk-security" target="_blank" data-original-url="https://www.itpro.com/627793/cyber-crime-one-of-the-biggest-threats-to-uk-security">biggest threats to the nation</a>.</p><p>Meanwhile, <a href="https://www.itpro.com/627646/gchq-uk-critical-services-cyber-threat-is-real" target="_blank" data-original-url="https://www.itpro.com/627646/gchq-uk-critical-services-cyber-threat-is-real">GCHQ director Iain Lobban warned</a> that the country's critical infrastructure was at threat from a cyber attack.</p><p>Cyber threats and political motivations had been intertwined for years, but only in 2010 did this become so startlingly clear.</p><p>If governments needed another reason to take online crime seriously, the WikiLeaks saga gave it to them. It opened up various questions around cyber security, first of all from the actual leaks themselves.</p><p>The ease with which the whistleblower was able to get his hands on classified documents astonished many and unsurprisingly led the US Government to review its security procedures.</p><p>One of the leaks appeared to confirm what many had suspected about the <a href="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us" target="_blank" data-original-url="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us">hack on Google</a> namely that it was ordered by the Chinese Politburo.</p><p>Then, of course, there were the various distributed denial of service (DDoS) attacks against not just <a href="https://www.itpro.com/628963/wikileaks-hit-by-denial-of-service-attack" target="_blank" data-original-url="https://www.itpro.com/628963/wikileaks-hit-by-denial-of-service-attack">WikiLeaks</a>, but also those who decided to back out of anything to do with Julian Assange's organisation.</p><p><a href="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge" target="_blank" data-original-url="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge">MasterCard</a> and PayPal were two targeted by the Anonymous hacker group, which grew to become the most famous bunch of cyber activists of the year, perhaps ever.</p><p>According to the UK's national security adviser Sir Peter Ricketts, Government websites should now be prepared for attacks from such hacktivists.' Now Assange has been granted bail, it remains to be seen whether Anonymous and other hackers will go after public bodies, but the threat does not look likely to be going away anytime soon.</p><p>Google Wi-Fi and the ICO</p><p>The kerfuffle that surrounded <a href="https://www.itpro.com/628762/google-street-view-data-dump-imminent" target="_blank" data-original-url="https://www.itpro.com/628762/google-street-view-data-dump-imminent">Google's data collection</a> over Wi-Fi networks during its Street View rounds rumbled on for a significant period of 2010.</p><p>There was plenty of confusion over what kind of admonishment the search giant was due after privacy bodies and even MPs poured scorn over Google's actions, which it claimed were accidental.</p><p>Google managed to avoid any fine in the UK, largely because our privacy watchdog, the Information Commissioner's Office (ICO), was powerless to hand out any monetary punishment. The ICO was handed <a href="https://www.itpro.com/622105/companies-face-fines-of-500000-for-losing-data" target="_blank" data-original-url="https://www.itpro.com/622105/companies-face-fines-of-500000-for-losing-data">new powers</a> to fine firms up to 500,000 on 6 April, but they were not retroactive. As Google had collected most of the data before that date, it could not be fined.</p><p>The ICO came under heavy fire throughout the process and attention turned to the fact the body had not used its new powers, despite having them for around half a year.</p><p>Finally, towards the end of November, <a href="https://www.itpro.com/628864/ico-deals-out-160000-in-data-breach-fines" target="_blank" data-original-url="https://www.itpro.com/628864/ico-deals-out-160000-in-data-breach-fines">160,000 in fines were dealt out</a> for two separate data breaches. A 100,000 penalty was handed to Hertfordshire County Council, whilst employment services company A4e was hit with a 60,000 fine.</p><p>Many lauded information commissioner Christopher Graham for finally showing the ICO had some teeth. But given no further fines have been meted out, it remains to be seen what lengths the watchdog will go to in the future to protect our privacy.</p><p>It certainly wasn't all bad news in the cyber crime space this year. Indeed, F-Secure's Mikko Hypponen said it was the best year yet for takedowns and arrests.</p><p>First off, arrests were made surrounding investigations into two giant botnets <a href="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down" target="_blank" data-original-url="https://www.itpro.com/628048/massive-bredolab-botnet-shut-down">Bredolab</a> and <a href="https://www.itpro.com/623914/fear-and-loathing-in-the-mariposa-aftermath" target="_blank" data-original-url="https://www.itpro.com/623914/fear-and-loathing-in-the-mariposa-aftermath">Mariposa</a>, both of which had infected close to 50 million computers combined. The latter appears to have been taken out of contention altogether now, whilst the end of Bredolab appears to be nigh.</p><p>In the UK, there were a few big moments for law enforcement. Some <a href="https://www.itpro.com/624622/london-teens-arrested-in-relation-to-78m-cyber-crime" target="_blank" data-original-url="https://www.itpro.com/624622/london-teens-arrested-in-relation-to-78m-cyber-crime">teenagers were arrested</a> in relation to an operation worth a whopping 7.8 million, whilst <a href="https://www.itpro.com/627286/19-arrested-in-zeus-bank-fraud-bust" target="_blank" data-original-url="https://www.itpro.com/627286/19-arrested-in-zeus-bank-fraud-bust">19 were taken in</a> on suspicion of using a Zeus Trojan to steal millions from UK banks. Another <a href="https://www.itpro.com/625795/phishers-compromise-10000-bank-accounts" target="_blank" data-original-url="https://www.itpro.com/625795/phishers-compromise-10000-bank-accounts">six arrests</a> were made in August under suspicion of helping compromise 10,000 bank accounts.</p><p>A big deal</p><p>The biggest point of 2010 from within the industry was <a href="https://www.itpro.com/625795/phishers-compromise-10000-bank-accounts" target="_blank" data-original-url="https://www.itpro.com/625795/phishers-compromise-10000-bank-accounts">Intel's acquisition of McAfee</a>. It cost a monolithic $7.68 billion and was proof the security market was now a really big deal.</p><p>Will the same McAfee product lines be maintained? Will Intel start to focus heavily on security by design? Well, we won't actually see anything material from the deal until <a href="https://www.itpro.com/626911/debut-mcafee-and-intel-product-due-in-2011" target="_blank" data-original-url="https://www.itpro.com/626911/debut-mcafee-and-intel-product-due-in-2011">next year</a> and Intel has kept fairly quiet on what is coming. So, we will just have to wait and see whether the huge investment was worth it.</p><p>There was another big acquisition later in the year when <a href="https://www.itpro.com/626857/hp-agrees-15-billion-arcsight-acquisition" target="_blank" data-original-url="https://www.itpro.com/626857/hp-agrees-15-billion-arcsight-acquisition">HP splashed $1.5 billion on Arcsight</a>. The pair promised to provide the kind of security solution to fit today's "modern enterprise." Again, we will just have to see what products do actually come out of the buy, but again there have been suggestions of bringing security into products rather than just working on boundary protection.</p><p>Expect some more big deals in 2011 and, of course, some equally massive security stories. Indeed, given the rate at which security has grown in stature this year, expect much more in the coming 12 months.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Human rights bodies under seige from DDoS strikes ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629662/human-rights-bodies-under-seige-from-ddos-strikes</link>
                                                                            <description>
                            <![CDATA[ Human rights organisations have had to deal with increasing numbers of attacks in the past year, research suggests. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qVtm377SvvgLUeBBcB3r42</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FYpAAkZsSZQr9N8hwiY9TH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Dec 2010 11:21:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FYpAAkZsSZQr9N8hwiY9TH-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker]]></media:description>                                                            <media:text><![CDATA[Hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FYpAAkZsSZQr9N8hwiY9TH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>This year has seen a big number of distributed denial of service (DDoS) attacks launched against human rights organisations, a report has suggested.</p><p>Almost two-thirds of respondents to a survey of human rights groups and independent media bodies said they had been hit by a DDoS attack in the past year.</p><p>The research, carried out by the Berkman Centre for Internet and Society, based at Harvard University, found there had been 140 attacks against over 280 different sites over a 12-month period from September 2009 to August 2010.</p><p>The poll showed 55 per cent of those hit by a DDoS attack had their site shut down by their ISPs in response and, in some cases, organisations' sites were not up and running again until weeks after a strike.</p><p>DDoS attacks have become common knowledge this year after the Anonymous hacking group used the method to protest against various sites.</p><p>The hacktivists' took umbrage with both anti-piracy bodies and organisations which pulled the plug on WikiLeaks, such as <a href="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge" target="_blank" data-original-url="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge">MasterCard</a> and PayPal.</p><p>Earlier this year, Panda Security researcher Sean-Paul Correll described DDoS as "the future of cyber protests" and many have predicted such attacks will ramp up next year.</p><p>WikiLeaks itself was hit by some hefty DDoS strikes, one <a href="https://www.itpro.com/629029/wikileaks-hit-by-10gbps-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/629029/wikileaks-hit-by-10gbps-ddos-attack">measuring in at a massive 10Gbps</a>.</p><p>Human rights sites have had to cope with two kinds of DDoS attacks, the first being application DDoS strikes, where massive numbers of requests are made on local server resources, the Harvard researchers explained.</p><p>These can usually be mitigated by a decent system administrator but network DDoS attacks, which exhaust network bandwidth, normally need the help of a hosting provider, as well as significant investment.</p><p>This means to protect human rights sites from DDoS strikes, their sites should be moved within the remit of ISPs' websites, which have the capability to defend against strikes.</p><p>"The rise of DDoS as a technique for silencing human rights and independent media sites is the symptom of a larger problem: the shortage of technical talent in administering these websites and the increasing isolation of the websites from the core of the network," the report concluded.</p><p>"We cannot consider DDoS alone, rather, we need to approach IT security for human rights and independent media sites as a whole."</p><p>Mikko Hypponen, chief research officer at F-Secure, said extended attacks against human rights groups have been around for years.</p><p>"Some of them are DDoS attacks, but the more serious ones are not about shutting down their websites but about infiltrating their services and accessing their data," Hypponen told <em>IT PRO</em>.</p><p>"Various NGOs have been a prime target for targeted attacks for quite some time."</p><p>Ram Herkanaidu, security researcher at Kaspersky Lab, said DDoS attacks used to be carried out in a random, graffiti-like way, but many now have financial backing from groups with an agenda.</p><p>"The majority of DDoS attacks nowadays are financially backed - that is, either used as an extortion scheme, or they get purchased by different parties to shut down adversaries and/or competitors," Herkanaidu told <em>IT PRO</em>.</p><p>"Some sites, such as online gaming sites, are more prone to extortion than others because any downtime will mean a great loss of revenue."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Who hit Spamhaus with DDoS strike? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629635/who-hit-spamhaus-with-ddos-strike</link>
                                                                            <description>
                            <![CDATA[ The anti-spam organisation may have been hit with a DDoS by wikileaks.info organisers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jzfGhMAXNbkutsxEGH9cd1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Q7VfZRGEGHKCRsRr5uccd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Dec 2010 12:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Q7VfZRGEGHKCRsRr5uccd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security]]></media:description>                                                            <media:text><![CDATA[Security]]></media:text>
                                <media:title type="plain"><![CDATA[Security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Q7VfZRGEGHKCRsRr5uccd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Spamhaus was hit with a distributed denial of service (DDoS) attack after it released info about a WikiLeaks mirror site, but there is some confusion over who was behind the strike.</p><p>Last week, the anti-spam organisation put out a warning wikileaks.org was redirecting web traffic to third-party mirror site wikileaks.info a space Spamhaus said was a known hive of activity for Russian cyber criminals.</p><p>Spamhaus's main concern was the security of the website's Webalta's 92.241.160.0/19 IP address space it did not have any anti-WikiLeaks agenda.</p><p>"We do have an interest in preventing spam and related types of internet abuse however and hope that the WikiLeaks staff will quickly address the hosting issue to remove the possibility of cyber criminals using WikiLeaks traffic for illicit purposes," the organisation said.</p><p>On 18 December, Spamhaus was hit by a large DDoS attack and eyes turned towards the Anonymous hacking group, which has been known to <a href="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge" target="_blank" data-original-url="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge">target organisations</a> who pulled support for WikiLeaks.</p><p>However, security professionals have indicated those running the WikiLeaks mirror site appeared to have been responsible.</p><p>"It was found to be PCs that had been hijacked by malware and were being used against their will to attack the Spamhaus services," explained Chester Wisniewski, senior security adviser at Sophos, in a <a href="http://nakedsecurity.sophos.com/2010/12/21/did-anonymous-attack-the-spamhaus-project/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+nakedsecurity+%28Naked+Security+-+Sophos%29" target="_blank">blog</a>.</p><p>"Those who commanded the attack are likely those that are hosting both wikileaks.info and the command-and-control servers used to instruct large quantities of zombied PCs to do their bidding."</p><p>Wisniewski advised those wanting to see the confidential cables to head to the official WikiLeaks site, which can be found at http://wikileaks.ch.</p><p>Last week, wikileaks.info rebuffed the claim it was hosting malicious activity.</p><p>"We find it very disturbing that Spamhaus labels a site as dangerous without even checking if there is any malware on it," the site's organisers said.</p><p>"We monitor the wikileaks.info site and we can guarantee that there is no malware on it."</p><p>In an update yesterday, wikileaks.info said it was unsure if a Spamhaus suggestion the mirror site's hosting provider Heihachi was behind the DDoS attack was true.</p><p>"Bottomline: we are a group that supports WikiLeaks with no connection to cyber criminals," the organisers added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WikiLeaks app pulled from Apple store ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629626/wikileaks-app-pulled-from-apple-store</link>
                                                                            <description>
                            <![CDATA[ Just days after its launch, a WikiLeaks app is no longer on Apple's App Store. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gdecANeCChvu99bXbAKhqr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kWzhZhHT6gDpycJ3rz6Mkf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Dec 2010 11:01:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Android]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Google]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kWzhZhHT6gDpycJ3rz6Mkf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wikileaks]]></media:description>                                                            <media:text><![CDATA[Wikileaks]]></media:text>
                                <media:title type="plain"><![CDATA[Wikileaks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kWzhZhHT6gDpycJ3rz6Mkf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A WikiLeaks app for iPhone has been pulled less than a week after it was made available for iOS users.</p><p>The app, which was placed on the App Store on 17 December, provided users with access to leaked cables and charged $1.99 (1.28) for access.</p><p>Of course, the communications have been accessible for free across the web and the app itself appears not to have been particularly popular with some.</p><p>A number of negative reviews were seen in a <a href="http://webcache.googleusercontent.com/search?q=cache:pOoeRIc-9g0J:itunes.apple.com/us/app/wikileaks-app/id409548258%3Fmt%3D8+wikileaks+app&cd=3&hl=en&ct=clnk&gl=us" target="_blank">Google cached version of the app info</a>, with one saying they would "rather go on wikileaks.com."</p><p>"This app is just a wrapper for the mobile web site," another poster called Murdock1450 said.</p><p>"There is no access to the actual released documents. Twitter feed doesn't count as up to date information."</p><p>There are a range of Android WikiLeaks apps where users can view leaked cables, a number of which are free.</p><p>At the time of publication, Apple had not responded to a request for comment.</p><p>The Cupertino company may have risked the wrath of pro-WikiLeaks web denizens such as the Anonymous hacking group, if Apple did take down the app.</p><p>Anonymous have launched various attacks on companies that have pulled support from Julian Assange's site, <a href="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge" target="_blank" data-original-url="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge">including MasterCard</a>.</p><p>Last week, the Bank of America said it would no longer process payments for WikiLeaks.</p><p>Assange has reportedly claimed to have information related to Bank of America activity and threatened to release some damaging documents on senior members of staff at the financial institution.</p><p>The WikiLeaks founder remains at a mansion in Norfolk, where he has to stay under his bail conditions.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Week in Review: Cloud carnage and Twitter time ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629572/week-in-review-cloud-carnage-and-twitter-time</link>
                                                                            <description>
                            <![CDATA[ This week saw the launch of our Cloud Power channel, whilst Twitter was under the spotlight. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6j3PNTtKDek4br4vi1Ezm3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TqWmTqTfGhDNgTJELTTvJ3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Dec 2010 15:47:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[SaaS]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TqWmTqTfGhDNgTJELTTvJ3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Week in review]]></media:description>                                                            <media:text><![CDATA[Week in review]]></media:text>
                                <media:title type="plain"><![CDATA[Week in review]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TqWmTqTfGhDNgTJELTTvJ3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>This week <em>IT PRO</em>, in association with Microsoft, launched <a href="https://www.itpro.com/629479/it-pro-launches-cloud-power-channel" target="_blank" data-original-url="https://www.itpro.com/629479/it-pro-launches-cloud-power-channel">launched Cloud Power</a> a brand new resource for all your cloud needs.</p><p>The site has been launched at a time when it is impossible to deny the rise of cloud computing.</p><p>But it is still a topic for hot discussion, as highlighted by Gartner's claim that the cloud has been <a href="https://www.itpro.com/629395/gartner-says-cloud-is-over-hyped" target="_blank" data-original-url="https://www.itpro.com/629395/gartner-says-cloud-is-over-hyped">somewhat over-hyped</a>, whilst Google's use of the cloud for Chrome OS user data was criticised due to <a href="https://www.itpro.com/629506/open-source-champion-labels-chrome-os-careless" target="_blank" data-original-url="https://www.itpro.com/629506/open-source-champion-labels-chrome-os-careless">security concerns</a>.</p><p>In less contentious news, Gartner said the software-as-a-service sector <a href="https://www.itpro.com/629455/enterprise-saas-revenues-top-9-billion" target="_blank" data-original-url="https://www.itpro.com/629455/enterprise-saas-revenues-top-9-billion">would be worth $9.2 billion</a> (5.8 billion) by the end of the year.</p><p>Twitter time</p><p>Twitter was under the spotlight once again this week. In good news for the micro-blogging service, it raised $200 million of financing, which meant the company is now valued at $3.7 billion.</p><p>Elsewhere, there were calls for a review into <a href="https://www.itpro.com/629542/total-twitter-court-ban-not-feasible" target="_blank" data-original-url="https://www.itpro.com/629542/total-twitter-court-ban-not-feasible">whether tweeting should be allowed from court</a> an issue that came about due to use of Twitter during WikiLeaks founder Julian Assange's bail hearing.</p><p>Meanwhile, the Office of Fair Trading ruled it needs to be made clear <a href="https://www.itpro.com/629458/office-of-fair-trading-calls-for-sponsored-tweets-to-be-disclosed" target="_blank" data-original-url="https://www.itpro.com/629458/office-of-fair-trading-calls-for-sponsored-tweets-to-be-disclosed">when tweets or blogs are sponsored</a>, so as not to mislead consumers.</p><p>The biggest social network in the world had a double dose of good news, as Facebook was named the best place to work in the US and Mark Zuckerberg was named Time's Person of the Year.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Total Twitter court ban not ‘feasible’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629542/total-twitter-court-ban-not-feasible</link>
                                                                            <description>
                            <![CDATA[ A lawyer says a total ban on Twitter in court is not feasible. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4Z6VH6jJdwinbqpKJVwNxq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dKd8ovA64JtUac9bh8GTRE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Dec 2010 15:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dKd8ovA64JtUac9bh8GTRE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Court]]></media:description>                                                            <media:text><![CDATA[Court]]></media:text>
                                <media:title type="plain"><![CDATA[Court]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dKd8ovA64JtUac9bh8GTRE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An outright ban on using Twitter in court would not be "feasible or reasonable," a lawyer has said.</p><p>Stewart Room, partner in Field Fisher Waterhouse's Privacy and Information Law Group, told <em>IT PRO</em> that the issue needs serious consideration but it is vital journalists be able to report on court proceedings.</p><p>"Twitter is a tool for journalism as well as for social networking," Room said. "So if tweeting by journalists in court is banned, what is the difference if they step outside the courtroom to post their messages?"</p><p>Room also questioned whether restrictions on the use of Twitter should be evidence-based or not.</p><p>Proceedings surrounding <a href="https://www.itpro.com/629203/wikileaks-founder-arrested-in-uk" target="_blank" data-original-url="https://www.itpro.com/629203/wikileaks-founder-arrested-in-uk">WikiLeaks founder Julian Assange's</a> appeal for bail, which has now been granted, were kept fully secret today after Twitter usage was banned inside the courtroom. Journalists had been permitted to tweet from court before Thursday.</p><p>The Lord Chief Justice, meanwhile, has called for a debate on tweeting from the courtroom, according to reports.</p><p>Whilst journalists should be allowed to tweet from court, albeit within a set of rules, other parties involved in cases may need different rules, Room said.</p><p>"Banning the use of Twitter in court by the parties to the proceedings, by witnesses and jury members is much easier to reconcile with public policy," he said.</p><p>"Mature thought is required to create workable and justifiable rules for everyone else. But, of course, some evidence will always need to be kept strictly confidential, but journalists know the rules and the courtroom is usually cleared of lay persons when such materials are being discussed."</p><p>Twitter was at the centre of another court battle earlier this year, when a user was handed a 1,000 fine and a criminal conviction for threatening to blow up an airport on the micro-blogging service.</p><p>Chambers then lost an appeal, much to the vexation of supporters who voiced their dismay on Twitter at the court's decision.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Q&A: Mikko Hyppönen, chief research officer, F-Secure ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629407/qa-mikko-hyppnen-chief-research-officer-f-secure</link>
                                                                            <description>
                            <![CDATA[ We ask one of the leading experts on cyber crime for an assessment of the recent spate of cyber attacks and the growing threats to companies trading online. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i2qTqGyVBajDtaWGV7hxvt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cfnDkM8JABW2fDcuoYpon7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Dec 2010 16:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Stephen Pritchard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cfnDkM8JABW2fDcuoYpon7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mikko Hypponen, F-Secure]]></media:description>                                                            <media:text><![CDATA[Mikko Hypponen, F-Secure]]></media:text>
                                <media:title type="plain"><![CDATA[Mikko Hypponen, F-Secure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cfnDkM8JABW2fDcuoYpon7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Since WikiLeaks released US government cables, the internet has been rocked by cyber attacks both against the whistleblowing site, and then against companies, including Amazon and PayPal, that had severed business relationships with it.</p><p>With the threat levels facing all businesses on the rise, <em>IT PRO</em> spoke to one of the foremost experts on cyber crime, chief research officer at <a href="http://www.f-secure.com" target="_blank">F-Secure</a>, Mikko Hyppnen, about the risks and some of the countermeasures companies can take.</p><p>You've been watching the chain of events following WikiLeaks' release of the US cables very closely. How seriously do you think these incidents both those aimed at WikiLeaks and those aimed at its former business partners have been in raising the level of threat across the internet community?</p><p>We've seen such an amount of different attacks against different targets. Then again most of the attacks we've seen have been simple denial of service, traffic overload attacks, which means that they might be able to slow down or shut down an attack, but are unable to break in. So we haven't seen any data being stolen, for example.</p><p>What you're saying is the attacks are not very sophisticated?</p><p>No, in fact most of the attackers who are part of the so-called Anonymous group are not really computer experts at all but want to participate in the attack because they believe in the cause. So they download the tool and let others use their computers to mount the attack.</p><p>What's frightening is how many people have done that and how quickly this has gathered momentum. There seem to be a lot of people willing to do something against the law to attack commercial organisations</p><p>It is clearly illegal, and it is also pretty costly. These attackers have succeeded in shutting down the online payment credit card verification systems of both Visa and Mastercard and disrupt part of the PayPal service, and this will immediately start causing losses to credit card companies. I'm quite sure most of the people participating in these attacks don't really realise that these are serious crimes.</p><p>Most companies operating online haven't prepared themselves for an attack like this. Companies that have taken precautions are the ones that have been attacked previously. This is no wonder; getting protection against denial of service attacks is expensive and complicated.</p><p>But companies like Amazon have such massive infrastructure. It is much more than just an online store. They have become so large with their internal computing infrastructure that they have started renting it out and is now one of the largest cloud infrastructures, so they have very large server infrastructure and very large bandwidth.</p><p>They can defend themselves, but for a lot of companies who are involved in e-commerce or depend on the internet for tools such as collaboration and communications, what should they be doing in light of these attacks?</p><p>A good idea is to set up a plan covering what to do, if you are attacked. Of course if you can afford it, it is always a good idea to host your website with a company that specialises in protecting against denial of service attacks, or if you are hosting your own site you can invest in specialist gear [to protect your site].</p><p>However, in most cases, it is enough to have a plan for what to do if you are attacked. You might migrate to a different server, change your domain names, change hosting IP addresses or change to a hosting provider that might be able to handle the attacks. Another easy to do trick is to have a spare domain name in case you are attacked, and then you can give out the "spare" domain name to people who need to access your site. Planning is the key, if you have some guidelines to follow if an attack happens, you will be much better off.</p><p>Once this type of attack has been demonstrated to be so effective as many people in the information security field think it has been doesn't that open up the floodgates for all manner of people who want to disrupt commerce to follow suit?</p><p>It is a real risk, and denial of service attacks are nothing new. We saw the first very large scale one in 2000. Since then we've seen large-scale attacks over and over again, and the motives range from "hacktivism" which is what we are seeing right now to criminal attacks on online stores where the hackers ask for a ransom.</p><p>I am sure that the politicians and regulators will be asking for legislation to solve the problem. That is easy to say, but it won't solve the problem; the problem is that the internet is international. We don't have global laws and never will have global laws so any legislation we pass in individual countries, or even EU-wide, doesn't mean anything at all as these people are all over the world and their targets are all over the world.</p><p>These crimes are faceless and the damage done by one single attacker isn't very large, in monetary terms, so the interest of traditional police forces to investigate attacks internationally doesn't seem very high. Local legislation in individual countries isn't really helping us.</p><p>It is international crime, and international crime was a problem even before the internet.</p><ul><li>For more on the threats posed by cyber attacks to business and how to counter them, listen to Stephen Pritchard's podcast interview with Mikko Hyppnen.</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Are businesses underestimating targeted cyber threats? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629476/are-businesses-underestimating-targeted-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ Detica research shows many businesses believe they are well prepared for targeted attacks, yet they may be naive in their assessment. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bzrXhveXEixLdq36YvPM5v</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kR23EFB4KgnAX9KMDbNsF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Dec 2010 13:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kR23EFB4KgnAX9KMDbNsF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker]]></media:description>                                                            <media:text><![CDATA[Hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kR23EFB4KgnAX9KMDbNsF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Almost all British businesses believe they are adequately protected against targeted attacks on their systems, a survey has indicated.</p><p>The Ipsos MORI survey, commissioned by Detica, discovered 94 per cent of British firms felt they had good enough protection, yet traditional defences still proved popular.</p><p>Almost two-fifths said they used a firewall to protect against targeted cyber attacks, while 22 per cent trusted in their anti-virus systems. However, such protections may not be good enough, the Detica report suggested.</p><p>Furthermore, just 14 per cent said they were at high risk of a targeted attack and only one respondent said they were at a very high risk.</p><p>Board members appeared somewhat unbothered about targeted attacks as well. Just 24 per cent of respondents said their board had requested information about such targeted attacks in the last 12 months.</p><p>Henry Harrison, technical director for Detica, told <em>IT PRO</em> a major problem for companies and their understanding of targeted cyber threats derived from a lack of suitable data on the subject.</p><p>In particular, Harrison pointed to recent stories surrounding the distributed denial of service (DDoS) attacks in support of <a href="https://www.itpro.com/629383/are-businesses-at-risk-of-wikileaks-attacks" target="_blank" data-original-url="https://www.itpro.com/629383/are-businesses-at-risk-of-wikileaks-attacks">WikiLeaks</a>.</p><p>"[DDoS attacks] are the cyber version of a carpet bomb," Harrison said.</p><p>"The news which has come out in the last couple of weeks has been both helpful and unhelpful... the language of attack' can be unhelpful."</p><p>Despite these concerns over media stories surrounding cyber security awareness, "we are starting to see some real coverage of these issues," he added.</p><p>However, businesses should be more worried about covert infiltration by cyber criminals in their attempts to steal data or intellectual property, Harrison explained.</p><p>Private companies are more at risk than public organisations, he claimed, especially considering many private companies help run the UK's critical infrastructure.</p><p>It emerged yesterday that the Anonymous group running DDoS campaigns in support of WikiLeaks decided to send faxes of leaked documents to various firms, including Amazon and Mastercard.</p><p>The new 'Leakflood' campaign, in which the hackers will also send out messages from Anonymous, is due to come to an end at 16:00 GMT today.</p><p>Luis Corrons, technical director of PandaLabs, said in a <a href="http://pandalabs.pandasecurity.com/tis-the-season-of-ddos-wikileaks-editio" target="_blank">company blog</a> it was the first "FaxDDoS" he had ever seen.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Businesses warned against cutting security spending ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629461/businesses-warned-against-cutting-security-spending</link>
                                                                            <description>
                            <![CDATA[ Companies have already driven down their security budgets and further cuts could risk 'impacting core controls', warns security chief. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7EFSvDvb2wgyBUC8RENyLT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7VJk2mCRdCxLKzYP3NXEVT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Dec 2010 12:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Stephen Pritchard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7VJk2mCRdCxLKzYP3NXEVT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neil Campbell, GM of security at Dimension Data]]></media:description>                                                            <media:text><![CDATA[Neil Campbell, GM of security at Dimension Data]]></media:text>
                                <media:title type="plain"><![CDATA[Neil Campbell, GM of security at Dimension Data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7VJk2mCRdCxLKzYP3NXEVT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Companies view IT security spending as a "grudge purchase", with most businesses already having trimmed budgets as far as they can.</p><p>Further cuts risk "impacting core technology controls", a leading security adviser has warned. But businesses are also still more likely to take a reactive approach to information security, rather than to adopt a proactive strategy, which could be cheaper, and more effective.</p><p>The warning - from Neil Campbell, global general manager at <a href="http://www.dimensiondata.com/Pages/Home.aspx" target="_blank">Dimension Data</a>, the IT services company - comes at a time when businesses are being forced to review their data security policies in light of the <a href="https://www.itpro.com/629383/are-businesses-at-risk-of-wikileaks-attacks" target="_blank" data-original-url="https://www.itpro.com/629383/are-businesses-at-risk-of-wikileaks-attacks">WikiLeaks diplomatic cable leaks</a> and the subsequent cyber attacks on businesses.</p><p>Organisations still view IT security, as well as tools such as data leak protection, as insurance policies they have to take out. Only rarely do businesses see security as a revenue generator. However, more companies are building security into new business processes, Campbell told <em>IT PRO</em> in an interview.</p><p>"Customers are on a journey from being reactive to proactive when it comes to security," he said. "When you are reactive you wait for a security incident to occur. Then when it does, you end up spending too much on technology thinking the technology will fix it.</p><p>"If you are proactive, you have a much better understanding of what your risks are, so when an incident does occur you either have the right controls in place, or are willing to accept the consequences [of an incident]."</p><p>"Companies are already minimising their security spend wherever possible," he said. "The bulk of a security budget is [for] operating that infrastructure and it is hard to make cuts without impacting core technology controls."</p><p>Businesses are also more likely to incorporate security spending into specific projects, with their own distinct financial goals, and business units are becoming more aware of how IT security can help the business to develop new products or services. Online banking is one area where companies have been able to use the internet to drive out significant costs, through slimming down branch networks.</p><p>"The perfect situation is where new security features represent incremental changes for the IT department," he said. "I would be worried if IT invested first in new features and then let the business know about them IT should be asking the business where it is going, and how can it meet their needs as an IT supplier. Security investments should be made on that basis."</p><p>But Campbell also highlighted the WikiLeaks diplomatic cables as an example of where organisations had failed to keep up with security threats. Standard data leak prevention technology could have stopped an incident that, according to Campbell, was "preventable".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WikiLeaks alternative OpenLeaks spawned by former workers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629425/wikileaks-alternative-openleaks-spawned-by-former-workers</link>
                                                                            <description>
                            <![CDATA[ OpenLeaks will provide the technology to allow organisations to publish confidential documents. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jJEr7SSKC7spTDKJsYv59W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QZs3ppaEbhEUgQiphTUptY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Dec 2010 15:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QZs3ppaEbhEUgQiphTUptY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenLeaks]]></media:description>                                                            <media:text><![CDATA[OpenLeaks]]></media:text>
                                <media:title type="plain"><![CDATA[OpenLeaks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QZs3ppaEbhEUgQiphTUptY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Wikileaks defectors have set up their own alternative whistle-blowing service, which will offer the technology to download files rather than publish any material.</p><p>Daniel Domscheit-Berg, who was one of the top players at WikiLeaks, has set up the OpenLeaks site in a bid to be more "open," allowing the source to decide how long organisations can use documents.</p><p>Domscheit-Berg told the BBC he felt WikiLeaks had started to go in the "wrong direction."</p><p>"There's too much concentration of power in one organisation; too much responsibility; too many bottlenecks; too many resource constraints."</p><p>At the current time there is nothing on <a href="http://www.openleaks.org" target="_blank">OpenLeaks</a> except a logo and a Coming soon' notification.</p><p>Jim Killock, executive director of the Open Rights Group, said the emergence of OpenLeaks has offered proof the issue goes beyond just Julian Assange's site.</p><p>"This shows that the idea of online whistleblowing sites will not live or die with Wikileaks," Killock told <em>IT PRO</em>.</p><p>"Which is all the more reason for governments to apply due process and respect the law, rather than trying to remove sites like Wikileaks through private phone calls."</p><p>WikiLeaks has seemingly spawned other similar services, including Brussels Leaks.</p><p>"We thought for a while it'd be a good idea to set up a website to allow people to anonymously upload files or send tip-offs on issues which we could use to either publish ourselves or send on to relevant people," the Brussels Leaks founders said on their <a href="http://brusselsleaks.com" target="_blank">website</a> last week.</p><p>"Wikileaks something we have no connection with other than ideals - showed the power of this."</p><p>Currently, Julian Assange remains in custody after a <a href="https://www.itpro.com/629203/wikileaks-founder-arrested-in-uk" target="_blank" data-original-url="https://www.itpro.com/629203/wikileaks-founder-arrested-in-uk">European arrest warrant was issued</a> by Sweden. Assange faces allegations of sexual crimes, which he has denies.</p><p>The 39-year-old Australian had been staying the UK in an attempt to keep out of the public eye whilst his website published leaked cables from US embassies.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Are businesses at risk of WikiLeaks attacks? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629383/are-businesses-at-risk-of-wikileaks-attacks</link>
                                                                            <description>
                            <![CDATA[ Denial of service attacks against WikiLeaks, as well as companies that refuse to do business with it, have raised the stakes for cyber-crime. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bjTTnvDpDQzh2GPXQnA8uQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8MKyt7do2RKuj3GqM5onfY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Dec 2010 15:43:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Firewalls]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Stephen Pritchard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8MKyt7do2RKuj3GqM5onfY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security warning]]></media:description>                                                            <media:text><![CDATA[Security warning]]></media:text>
                                <media:title type="plain"><![CDATA[Security warning]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8MKyt7do2RKuj3GqM5onfY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ANALYSIS:The blurred -out image of the young hacker on the <a href="http://www.bbc.co.uk/news/technology-11968605" target="_blank">BBC News</a> might not strike fear into business leaders. But perhaps it should.</p><p>The hacker, who identified himself as "Coldblood", claimed to be a member of the Anonymous group behind distributed denial of service (DDoS) attacks on Mastercard, Visa, Amazon.com and PayPal. The companies were targeted, Coldblood told the BBC, because they had "bowed to Government pressure" to withdraw services from WikiLeaks. WikiLeaks itself was hit by several DDoS attacks after it released US diplomatic cables to the press.</p><p>Fears are growing that the type of attacks aimed both at WikiLeaks, and its former business partners, are creating an environment that is increasingly dangerous for any organisation doing business online.</p><p>Although security experts point out that mounting the type of attacks that took place against Visa and Mastercard is illegal in the UK, under the provisions of the 2006 Police and Justice Act, prosecuting individuals behind cyber attacks is fraught with difficulty. It remains all too easy for hackers to base themselves, or their botnets, in countries where the law is more lax.</p><p>Security professionals worry too that, now groups such as Anonymous have demonstrated both the ease and the power of cyber attacks, others will follow their lead. Governments are already concerned about military-style cyber attacks on countries, such as those that affected Baltic states and Georgia; both NATO and the UK government, in its recent <a href="https://www.itpro.com/627700/government-funding-boost-to-fight-cyber-crime" target="_blank" data-original-url="https://www.itpro.com/627700/government-funding-boost-to-fight-cyber-crime">defence and security review</a> have made cybercrime and cyber warfare defence a higher priority.</p><p>"At the highest level, it is not a question of focusing on WikiLeaks. This comes down to what people are doing, not their motivation," says Professor John Walker, a member of the Security Advisory Group at ISACA and CTO of Secure-Bastion. "We need to think about the next reason for using it [DDoS attacks]. It is a threat that faces every organisation that faces the Internet."</p><p>Businesses are also concerned that they might, through no fault of their own, become caught up in cyber attacks driven by political economic or other motives beyond their control. Online businesses in particular will have thousands of customers, and little way of knowing if a customer might be caught up in the type of controversy that has affected WikiLeaks in the future.</p><p>Break down the Government walls</p><p>Government agencies and bodies such as NATO can, of course, afford to take steps to detect and prevent cyber attacks, and they can also call on their intelligence services to try to predict where the next attacks might come from.</p><p>Commercial businesses, though, are forced to rely on their security vendors, IT consultants and own in-house IT teams to bolster defences. After the recession, Professor Walker cautions, some companies may well find their defences are lacking. "Security has been impacted. Businesses now need to see how secure they are," he said.</p><p>The first and urgent steps to protect a business against cyber attacks need not be expensive, however. At ISACA, Professor Walker advises carrying out an urgent security review. Mid-sized businesses and enterprises should have the resources to do this themselves.</p><p>If they do not, a few thousand pounds spent on external testing is a far better than running the risk of the significant downtime and reputational damage that follows a successful attack, he suggests. When businesses do carry out such audits, often the result is that they find they can switch resources to where they are more effective; new spending is not always necessary.</p><p>But businesses that trade online, or depend heavily on the public internet for their collaboration and communications tools, might need to delve deeper into their technology platforms to ensure they are resilient. Firms need to make sure operating systems, web servers, databases and firewalls are up to date and fully patched, and that they are watching logs for suspicious activity. IT staff should also ensure they receive up to date security information from the vendors, as these are a valuable early warning system. "DDoS attacks against websites can be difficult to fend off, as we saw with MasterCard and others over the past couple of days," explains Dave Beesley, MD of consultancy Network Defence. "However, there are strategies that companies can take to defend themselves against cyber threats generally. "The first is to make sure that their web platforms, operating systems and applications are running the latest up-to-date patches, as attackers often seek to exploit known vulnerabilities. And web gateways and firewalls need auditing to ensure their rule-sets are capable of dealing with attacks."</p><p>IT professionals should act quickly to check their security, and to reassure their companies' boards that all that can be done, is being done. No-one can say how the WikiLeaks saga will end, but the unfortunate truth is that cyber attacks are here to stay.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Week in Review: Xmas acquisitions, tablet talk and WikiLeaks week 2 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629380/week-in-review-xmas-acquisitions-tablet-talk-and-wikileaks-week-2</link>
                                                                            <description>
                            <![CDATA[ This week, Google is just one tech giant to make acquisitions, whilst there has been plenty of tablet talk in the lead up to Christmas. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">w4mcEHpMKfHgd7ZTygCd3F</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctQthwT3zALjipUe2Gj5mm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Dec 2010 14:48:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[PaaS]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctQthwT3zALjipUe2Gj5mm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Week in review]]></media:description>                                                            <media:text><![CDATA[Week in review]]></media:text>
                                <media:title type="plain"><![CDATA[Week in review]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctQthwT3zALjipUe2Gj5mm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tis the season to acquire</p><p>It seems some of the world's tech giants have decided to treat themselves this Christmas with a number of acquisitions.</p><p>First off, Google did a <a href="https://www.itpro.com/629176/google-goes-on-christmas-acquisition-spree" target="_blank" data-original-url="https://www.itpro.com/629176/google-goes-on-christmas-acquisition-spree">double buy</a>, picking up Phonetics Arm and Widevine.</p><p>However, the search giant had an up and down week, after revealing Chrome OS laptops would not arrive before the end of the year.</p><p>Later in the week, Dell revealed it was in talks to <a href="https://www.itpro.com/629320/dell-in-talks-to-acquire-compellent" target="_blank" data-original-url="https://www.itpro.com/629320/dell-in-talks-to-acquire-compellent">acquire storage software company Compellent</a>.</p><p>And then there was <a href="https://www.itpro.com/629263/salesforcecom-to-splash-212-million-on-heroku" target="_blank" data-original-url="https://www.itpro.com/629263/salesforcecom-to-splash-212-million-on-heroku">Salesforce.com's purchase</a> of Ruby platform-as-a-service provider Heroku for a whopping $212 million.</p><p>The announcement was made at <a href="https://www.itpro.com/629227/roundup-dreamforce-2010" target="_blank" data-original-url="https://www.itpro.com/629227/roundup-dreamforce-2010">Dreamforce 2010</a>, where <em>IT PRO</em> has been reporting from.</p><p>Tablet talk</p><p>Plenty of excitement surrounds the next iteration of the iPad as reports suggested it could be ready by February. As for new features, it appears a camera will be added.</p><p>RIM said it would be offering <a href="https://www.itpro.com/629257/free-playbook-for-rim-developers" target="_blank" data-original-url="https://www.itpro.com/629257/free-playbook-for-rim-developers">free tablets to developers</a> who submit successful apps before the PlayBook's US release date.</p><p>Earlier in the week, the manufacturer said the software to feature on the PlayBook will soon find its way onto BlackBerry devices as well.</p><p>Intel, meanwhile, said it hopes its chips will feature in tablets next year.</p><p>When will WikiLeaks weeks end?</p><p>Of course, it was pretty difficult to stay away from any WikiLeaks news this week.</p><p>DataCell, a company which facilitates payments to WikiLeaks, said it would be <a href="https://www.itpro.com/629278/datacell-launches-legal-action-against-visa-and-mastercard" target="_blank" data-original-url="https://www.itpro.com/629278/datacell-launches-legal-action-against-visa-and-mastercard">taking legal action</a> against Visa and MasterCard. DataCell claimed it had lost revenue as Visa and MasterCard suspended processing of donations to the whistle-blowing website.</p><p>WikiLeaks supporters have gone after companies such as MasterCard who have pulled services to Julian Assange's site, launching a number of <a href="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge" target="_blank" data-original-url="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge">DDoS attacks</a>.</p><p>See IT PRO's <a href="https://www.itpro.com/629383/are-businesses-at-risk-of-wikileaks-attacks" target="_blank" data-original-url="https://www.itpro.com/629383/are-businesses-at-risk-of-wikileaks-attacks">analysis of the WikiLeaks threat</a> to see whether your business could be affected by DDoS attacks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Twitter defends WikiLeaks trending absence ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629311/twitter-defends-wikileaks-trending-absence</link>
                                                                            <description>
                            <![CDATA[ The microblogging site claims it is ‘absolutely not’ blocking WikiLeaks from its trending topics. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3RFBzaWwfmiNFWL2QwV4jC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DJhKe7WDxyzCNTnZWd4VLA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Dec 2010 12:28:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jennifer Scott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DJhKe7WDxyzCNTnZWd4VLA-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Twitter]]></media:description>                                                            <media:text><![CDATA[Twitter]]></media:text>
                                <media:title type="plain"><![CDATA[Twitter]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DJhKe7WDxyzCNTnZWd4VLA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Accusations that <a href="http://www.twitter.com" target="_blank">Twitter</a> has been blocking <a href="http://www.wikileaks.ch" target="_blank">WikiLeaks</a> from becoming a trending topic on its website have been denied by the company.</p><p>In a <a href="http://blog.twitter.com/2010/12/to-trend-or-not-to-trend.html" target="_blank">blogpost</a> issued last night, the head of communications for the microblogging site, Carolyn Penner, claimed it was merely the algorithm used to define trending topics that had led to #WikiLeaks being excluded rather than anything intentional.</p><p>"This week, people are wondering about WikiLeaks, with some asking if Twitter has blocked #wikileaks, #cablegate or other related topics from appearing in the list of top Trends," she wrote.</p><p>"The answer: Absolutely not. In fact, some of these terms, including #wikileaks and #cablegate, have previously trended either worldwide or in specific locations."</p><p>Penner offered a simplistic explanation of the algorthim which claimed it identified the newest breaking news in real-time rather than just what is tweeted about the most.</p><p>"Put another way, Twitter favours novelty over popularity," she added.</p><p>The blog is being seen by some as an attempt to subdue WikiLeaks supporters and hacktivist' groups such as Anonymous, who have <a href="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge" target="_blank" data-original-url="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge">already targeted sites including MasterCard.com</a> for blocking donation payments to the whistle-blowing website.</p><p>Penner concluded: "Sometimes a topic doesn't break into the Trends list because its popularity isn't as widespread as people believe. And, sometimes, popular terms don't make the Trends list because the velocity of conversation isn't increasing quickly enough, relative to the baseline level of conversation happening on an average day; this is what happened with #wikileaks this week."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DataCell launches legal action against Visa and MasterCard ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629278/datacell-launches-legal-action-against-visa-and-mastercard</link>
                                                                            <description>
                            <![CDATA[ The credit card giants have no longer just got distributed denial of service attacks from WikiLeaks supporters to contend with. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oP3BCEjGGD1MAYBBWQgGzi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zUSUYhjXGoowbj6WNSAXGR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Dec 2010 09:48:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jennifer Scott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zUSUYhjXGoowbj6WNSAXGR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Legal action]]></media:description>                                                            <media:text><![CDATA[Legal action]]></media:text>
                                <media:title type="plain"><![CDATA[Legal action]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zUSUYhjXGoowbj6WNSAXGR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The company which facilitates payments to <a href="http://www.wikileaks.ch" target="_blank">WikiLeaks</a> is taking on the big guns of the credit card industry in an attempt to open up payment processes once more.</p><p><a href="http://www.datacell.com/index.php" target="_blank">DataCell</a> has announced it will be taking "immediate legal actions" against <a href="https://www.itpro.com/626371/visa-lays-down-the-law-of-pci-compliance" target="_blank" data-original-url="https://www.itpro.com/626371/visa-lays-down-the-law-of-pci-compliance">Visa</a> and <a href="https://www.itpro.com/625168/top-us-banks-targeted-by-mastercard-and-visa-scam" target="_blank" data-original-url="https://www.itpro.com/625168/top-us-banks-targeted-by-mastercard-and-visa-scam">MasterCard</a>, who have both this week suspended processing donations to the whistle-blowing website.</p><p>The company claimed it was loosing revenue due to the payment suspension, as well as WikiLeaks losing donations.</p><p>"DataCell is only doing work for Wikileaks in helping them processing credit card payments," said Andreas Fink, chief executive (CEO) of DataCell. "We are helping an honourable organisation to get its funding it needs to sustain the load on their servers and deliver the messages the public wants to read."</p><p>He claimed the blocking of payments by Visa and MasterCard could severely damage the two companies' reputations and make them lose customers.</p><p>"This might be very well the end of the credit card business worldwide," he added.</p><p>The legal action is just the latest issue faced by the companies who have become targets of WikiLeaks supporters.</p><p>A hacker group calling themselves Anonymous' targeted MasterCard's website yesterday with a distributed denial of service (DDoS) attacks and <a href="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge" target="_blank" data-original-url="https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Itpro%2FNews+%28IT+PRO+-+News%29">successfully took the site down</a>. Reports suggest Visa's website could be the next target.</p><p>WikiLeaks is responsible for leaking the contents of confidential US Embassy cable communications to a number of newspapers around the world, including <a href="http://www.guardian.co.uk" target="_blank">The Guardian</a> in the UK.</p><p>Founder of the website, Julian Assange, was this week <a href="https://www.itpro.com/629203/wikileaks-founder-arrested-in-uk" target="_blank" data-original-url="https://www.itpro.com/629203/wikileaks-founder-arrested-in-uk?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+ITPro%2FToday+%28IT+PRO+-+Today%29">arrested in London</a> after he was accused of committing sexual assault in Sweden back in August. The Australian has been refused bail and is waiting to fight against an extradition order to send him back to Sweden.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MasterCard site taken down in WikiLeaks revenge ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629251/mastercard-site-taken-down-in-wikileaks-revenge</link>
                                                                            <description>
                            <![CDATA[ The ‘Anonymous’ hackers claim to have taken down another website with a DDOS attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6CnGHQpuSCSMdsCxMiTn5H</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HUKt88THeGmtwpsRHRtMaP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Dec 2010 14:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jennifer Scott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HUKt88THeGmtwpsRHRtMaP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[MasterCard]]></media:description>                                                            <media:text><![CDATA[MasterCard]]></media:text>
                                <media:title type="plain"><![CDATA[MasterCard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HUKt88THeGmtwpsRHRtMaP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The website of credit card heavyweights <a href="http://www.mastercard.com" target="_blank">MasterCard</a> has been taken down in what appears to be a revenge attack for the company's stance on <a href="http://wikileaks.ch" target="_blank">WikiLeaks</a>.</p><p>Earlier this week, MasterCard confirmed it would not be processing donations made by its cards to WikiLeaks the site responsible for leaking a number of confidential US Embassy cable communications to the public.</p><p>It now seems to have become the latest target of the WikiLeaks-supporting hacker group Anonymous,' who claimed to have launched a distributed denial of service (DDOS) attack on the company's website.</p><p>A post on <a href="http://twitter.com/anon_operation" target="_blank">Twitter</a> from the group, which goes under the username @Anon_Operation, said: "WE ARE GLAD TO TELL YOU THAT http://www.mastercard.com/ is DOWN AND IT'S CONFIRMED! #ddos #wikileaks Operation:Payback(is a bitch!) #PAYBACK."</p><p>We contacted MasterCard for comment but it had not responded to our request at the time of publication.</p><p>If the attack has been launched by Anonymous, MasterCard will join the ever increasing list of WikiLeaks enemies' being targeted.</p><p>PostFinance, the Swiss bank which blocked payments to WikiLeaks, has already fallen victim to Anonymous and the group has claimed it will target PayPal after the service also suspended transfers to the site.</p><p>Julian Assange, the founder of WikiLeaks, was yesterday <a href="https://www.itpro.com/629203/wikileaks-founder-arrested-in-uk" target="_blank" data-original-url="https://www.itpro.com/629203/wikileaks-founder-arrested-in-uk?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+ITPro%2FToday+%28IT+PRO+-+Today%29">arrested in London</a>, accused of sexual assault, which allegedly took place in Sweden back in August. He is now fighting against extradition back to the country.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WikiLeaks founder arrested in UK ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629203/wikileaks-founder-arrested-in-uk</link>
                                                                            <description>
                            <![CDATA[ Julian Assange is arrested by the Metropolitan Police on accusations of sexual assault. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">98bmNbEvsfSkraXHz4TiBU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/w7bGopVRZ4QsbafERpWQe4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Dec 2010 12:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jennifer Scott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/w7bGopVRZ4QsbafERpWQe4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Julian Assange]]></media:description>                                                            <media:text><![CDATA[Julian Assange]]></media:text>
                                <media:title type="plain"><![CDATA[Julian Assange]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/w7bGopVRZ4QsbafERpWQe4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The founder of controversial website WikiLeaks, Julian Assange, has been arrested by the Metropolitan Police in London today, accused of sexual assault.</p><p>The 39-year-old, originally from Australia, has been staying the UK in an attempt to keep out of the public eye whilst his website published leaked cables from US embassies, revealing confidential, and often embarrassing, Government communications.</p><p>However, a European arrest warrant was granted to bring in Assange, who stands accused of one count of rape, one count of unlawful coercion and two counts of sexual molestation, which are alleged to have occurred back in August this year in Sweden.</p><p>He is due to appear at Westminster Magistrates' Court later today.</p><p>However, Kristinn Hrafnsson, a spokesperson WikiLeaks, told <a href="http://uk.reuters.com" target="_blank">Reuters</a>: "Wikileaks is operational. We are continuing on the same track as laid out before."</p><p>"Any development with regards to Julian Assange will not change the plans we have with regards to the releases today and in the coming days."</p><p>Take a look at our <a href="https://www.itpro.com/629149/week-in-review-the-week-of-the-wikileaks" target="_blank" data-original-url="https://www.itpro.com/629149/week-in-review-the-week-of-the-wikileaks">Week in Review</a> to find out how the week of the WikiLeaks played out.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Week in Review: The week of the Wikileaks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629149/week-in-review-the-week-of-the-wikileaks</link>
                                                                            <description>
                            <![CDATA[ This week, tech news was dominated by the story of Wikileaks and the consequences of the cables... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6h3zpbu9xwxyf6k5Gz7a18</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/i2yXhLwPcANAwbJTqECytX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Dec 2010 17:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jennifer Scott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/i2yXhLwPcANAwbJTqECytX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Week in Review]]></media:description>                                                            <media:text><![CDATA[Week in Review]]></media:text>
                                <media:title type="plain"><![CDATA[Week in Review]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/i2yXhLwPcANAwbJTqECytX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Wikileaks week</p><p>The world of politics was thrown into disarray on Monday when whistle blowing website Wikileaks unleashed 250,000 US embassy cable communications, revealing secrets many Governments would have preferred to have kept quiet.</p><p>However, the tech world felt some of the consequences with selections of the information leaked affected big companies and Government tech issues.</p><p>First to come to the forefront was the revelation <a href="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us" target="_blank" data-original-url="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us">China's Politburo had ordered a hack attack on Google</a> earlier this year. It was widely believed to have been the case but this was the first written confirmation from a Chinese contact admitting it to the American Embassy in Beijing.</p><p>Later in the week, a new cable got Gordon Brown back in the headlines after his departure from Downing Street. The communication showed the former Prime Minister had <a href="https://www.itpro.com/629008/wikileaks-brown-requested-uk-sentence-for-mckinnon" target="_blank" data-original-url="https://www.itpro.com/629008/wikileaks-brown-requested-uk-sentence-for-mckinnon">made a personal request for computer hacker Gary McKinnon</a> to spend any of his jail time for hacking into NASA and the Pentagon's computer systems in the UK.</p><p>But not everyone seemed to enjoy being in the spotlight and the site has fallen victim to a number of Distributed Denial of Service attacks (DDoS).</p><p>The first attack was <a href="https://www.itpro.com/628963/wikileaks-hit-by-denial-of-service-attack" target="_blank" data-original-url="https://www.itpro.com/628963/wikileaks-hit-by-denial-of-service-attack">launched on Sunday</a> as it began to leak documents and responsibility was claimed by a hacker calling themselves th3j35t3r.'</p><p>A further DDoS attack <a href="https://www.itpro.com/629029/wikileaks-hit-by-10gbps-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/629029/wikileaks-hit-by-10gbps-ddos-attack">was launched on Tuesday</a> "exceeding 10 Gigabits a second," which would have been double the speed of the previous one.</p><p>Now the back and forth seems to be surrounding where founder and editor-in-chief Julian Assange was keeping the files. Initially Assange moved the files from his Swedish service provider to Amazon's EC2 cloud offering. However, in a matter of days, his <a href="https://www.itpro.com/629101/wikileaks-files-ejected-by-amazon" target="_blank" data-original-url="https://www.itpro.com/629101/wikileaks-files-ejected-by-amazon">files were ejected from the Amazon data centres</a> and were suspected to have moved back to the original provider.</p><p>The week concluded with <a href="https://www.itpro.com/629122/wikileaks-goes-swiss-as-domain-provider-pulls-plug" target="_blank" data-original-url="https://www.itpro.com/629122/wikileaks-goes-swiss-as-domain-provider-pulls-plug">EveryDNS.net removing its support for Wikileaks</a> and forcing Assange to change the domain name to a Swiss-based address.</p><p>Where the story goes from here is anybody's guess but we will be keeping you up to date with all the tech related leaks as it happens.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wikileaks goes Swiss as domain provider pulls plug ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629122/wikileaks-goes-swiss-as-domain-provider-pulls-plug</link>
                                                                            <description>
                            <![CDATA[ Wikileaks moves its site to Switzerland as EveryDNS.net withdraws its support. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5cJgaw1K7CkJtCL5KbZ3Jd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RsGGPQZNP8LJTiw8Gfh6dG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Dec 2010 11:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Google]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RsGGPQZNP8LJTiw8Gfh6dG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wikileaks]]></media:description>                                                            <media:text><![CDATA[Wikileaks]]></media:text>
                                <media:title type="plain"><![CDATA[Wikileaks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RsGGPQZNP8LJTiw8Gfh6dG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Wikileaks has moved its site to a Switzerland-based address after its domain name provider pulled the plug.</p><p>EveryDNS.net announced it had stopped providing domain name system services to wikileaks.org yesterday, claiming repeated distributed denial of service (DDoS) attacks threatened the provider's stability.</p><p>Wikileaks said it was on the wrong end of a 10Gbps <a href="https://www.itpro.com/629029/wikileaks-hit-by-10gbps-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/629029/wikileaks-hit-by-10gbps-ddos-attack">DDoS strike</a> earlier this week, following an initial attack on the day it began releasing its controversial government communications.</p><p>"A 24 hour termination notification email was sent to the email address associated with the wikileaks.org account," a statement from EveryDNS.net read.</p><p>"In addition to this email, notices were sent to Wikileaks via Twitter and the chat function available through the wikileaks.org website. Any downtime of the wikileaks.org website has resulted from its failure to use another hosted DNS service provider."</p><p>Wikileaks revealed over Twitter today it had moved to http://wikileaks.ch, which is currently up and running.</p><p>Earlier this week, Wikileaks was forced to <a href="https://www.itpro.com/629101/wikileaks-files-ejected-by-amazon" target="_blank" data-original-url="https://www.itpro.com/629101/wikileaks-files-ejected-by-amazon">remove its files</a> from Amazon servers.</p><p>Wikileaks founder and editor-in-chief Julian Assange is believed to have moved the files back to another service provider in Sweden.</p><p>The site has inspired both derision and praise after leaking various cable communications, one of which <a href="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us" target="_blank" data-original-url="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us">implicated China</a> in a hack on Google.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wikileaks files ejected by Amazon ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629101/wikileaks-files-ejected-by-amazon</link>
                                                                            <description>
                            <![CDATA[ Days after moving its files to Amazon cloud servers, Wikileaks has been forced to think again. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4iGTmX1ThgTrgcUDuAQLtd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kZG6dmgDr9KLbM68APGQgW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Dec 2010 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Eric Doyle ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kZG6dmgDr9KLbM68APGQgW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wikileaks]]></media:description>                                                            <media:text><![CDATA[Wikileaks]]></media:text>
                                <media:title type="plain"><![CDATA[Wikileaks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kZG6dmgDr9KLbM68APGQgW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Whether it was fear of the global governmental disapproval or of the havoc that distributed denial of service (DDoS) attacks can cause, <a href="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us" target="_blank" data-original-url="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us">Wikileaks</a> has reportedly been forced to remove its files from <a href="https://www.itpro.com/618799/amazon-opens-ec2-up-to-auction-style-payments" target="_blank" data-original-url="https://www.itpro.com/618799/amazon-opens-ec2-up-to-auction-style-payments">Amazon's Elastic Compute Cloud</a> (EC2) service.</p><p>Wikileaks founder and editor-in-chief Julian Assange is believed to have had the files, which he said were not the 250,000 controversial US diplomatic messages, moved back to his former service provider in Sweden.</p><p>An acerbic Twitter message from the whistle-blowing company read: "WikiLeaks servers at Amazon ousted. Free speech the land of the free - fine our $ are now spent to employ people in Europe."</p><p>Amazon has not made its role, if any, in the move public but the Tweet seemed to make it clear it was not Wikileaks that wanted the change, just days after it had opened the EC2 account. There was also pressure being applied by US senator Joe Lieberman, chairman of the Senate's Homeland Security and Governmental Affairs Committee, to have the files ejected.</p><p>UK free speech organisation Index on Censorship, which represents Assange in Britain, has also made public correspondence between Wikileaks and a US Embassy official in London.</p><p>Addressing the US Ambassador, Assange wrote: "Subject to the general objective of ensuring maximum disclosure of information in the public interest, WikiLeaks would be grateful for the United States Government to privately nominate any specific instances (record numbers or names) where it considers the publication of information would put individual persons at significant risk of harm that has not already been addressed."</p><p>This was in response to the US assertion the leaked messages would put lives at risk. Assange claimed his embarrassing posts might put livelihoods at risk rather than lives.</p><p>On behalf of the Embassy, Harold Hongju Koh, a legal adviser in the US Department of State, replied: "We will not engage in a negotiation regarding the further release or dissemination of illegally obtained US Government classified materials."</p><p>Assange responded: "You have chosen to respond in a manner which leads me to conclude that the supposed risks are entirely fanciful and you are instead concerned to suppress evidence of human rights abuse and other criminal behaviour."</p><p>With more revelations about its activities promised, the US Government has vowed to continue its attempts to silence Wikileaks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wikileaks hit by 10Gbps DDoS attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629029/wikileaks-hit-by-10gbps-ddos-attack</link>
                                                                            <description>
                            <![CDATA[ Wikileaks says it was hit by a second DDoS attack today, following one on Sunday. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t7iULL4JhjDHAraCBFoj9L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8YfQRQqjt8owMhgqwWgY7i-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Nov 2010 15:38:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8YfQRQqjt8owMhgqwWgY7i-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker]]></media:description>                                                            <media:text><![CDATA[Hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8YfQRQqjt8owMhgqwWgY7i-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Wikileaks said it was under another distributed denial of service (DDoS) attack today.</p><p>The controversial site, which began releasing classified communications between government officials and diplomats two days ago, said it was under siege again following an <a href="https://www.itpro.com/628963/wikileaks-hit-by-denial-of-service-attack" target="_blank" data-original-url="https://www.itpro.com/628963/wikileaks-hit-by-denial-of-service-attack">attack on Sunday</a>.</p><p>"We are currently under another DDoS attack," the site's <a href="http://twitter.com/wikileaks" target="_blank">official Twitter feed</a> read.</p><p>"DDoS attack now exceeding 10 Gigabits a second."</p><p>If the 10Gbps figure - relating to the speed at which traffic goes through a site - was correct, this would be over double the power of Sunday's attacks, which registered at 2-4 Gbps, according to network security specialist Arbor Networks.</p><p>The security firm's chief scientist Craig Labovitz said the initial DDoS effort "was modest in the relative scheme of recent attacks against large web sites."</p><p>"While the DDoS attack generated an outpouring of blog posts, news articles and tweets, it appears to have had little impact on the Wikileaks 'Cablegate' disbursement of documents," Labovitz said in a <a href="http://asert.arbornetworks.com/2010/11/wikileaks-cablegate-attack" target="_blank">blog</a>.</p><p>A hacker known as Jester claimed to have been responsible for the initial attack, but there has not been any confirmation on the perpetrator of today's efforts.</p><p>At the time of writing, Wikileaks' sites were up and running.</p><p>Today, the site leaked communications indicating ex-Prime Minister Gordon Brown called on the US to allow hacker Gary Mckinnon <a href="https://www.itpro.com/629008/wikileaks-brown-requested-uk-sentence-for-mckinnon" target="_blank" data-original-url="https://www.itpro.com/629008/wikileaks-brown-requested-uk-sentence-for-mckinnon">serve any potential sentence in the UK</a>.</p><p>Yesterday, another leak emerged implicating China in a <a href="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us" target="_blank" data-original-url="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us">hack on Google</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wikileaks: Brown requested UK sentence for McKinnon ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/629008/wikileaks-brown-requested-uk-sentence-for-mckinnon</link>
                                                                            <description>
                            <![CDATA[ Gordon Brown made a personal plea for the hacker to serve his sentence on UK shores, claims latest Wikileaks cable. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kaogMGqMHfkN1hNS4dRqJo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AX9ZjLs8e86CZHd4x2crp7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Nov 2010 11:36:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jennifer Scott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AX9ZjLs8e86CZHd4x2crp7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gary McKinnon]]></media:description>                                                            <media:text><![CDATA[Gary McKinnon]]></media:text>
                                <media:title type="plain"><![CDATA[Gary McKinnon]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AX9ZjLs8e86CZHd4x2crp7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ex-Prime Minister Gordon Brown personally asked the US Government to allow Gary McKinnon to serve his sentence in the UK, according to <a href="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us" target="_blank" data-original-url="https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us">Wikileaks</a>.</p><p>The latest cable to be revealed by <a href="http://www.guardian.co.uk/world/2010/nov/30/wikileaks-cables-gary-mckinnon-gordon-brown" target="_blank">The Guardian</a> this week showed the former Labour leader had asked Louis Susman, the US ambassador for the UK, to allow the computer hacker to serve the time for his crime on British shores rather than being extradited.</p><p>"PM Brown, in a one-on-one meeting with the ambassador, proposed a deal that McKinnon plead guilty, make a statement of contrition, but serve any sentence of incarceration in the UK," <a href="http://www.guardian.co.uk/world/us-embassy-cables-documents/228597" target="_blank">wrote Susman in a cable to secretary of state Hilary Clinton in August 2009</a>.</p><p>"Brown cited deep public concern that McKinnon, with his medical condition, would commit suicide or suffer injury if imprisoned in a US facility."</p><p>When Clinton then visited the UK in October last year, Susman again warned the McKinnon issue was likely to arise.</p><p>"McKinnon has gained enormous popular sympathy in his appeal against extradition; the UK's final decision is pending." he wrote. "The case has also caused public criticism of the US-UK extradition treaty."</p><p>The plea appeared to fall on deaf ears, however, as no progress was made.</p><p>The current Prime Minister, David Cameron, also brought up the McKinnon case in December, when he was the leader of the opposition.</p><p>"Cameron said he had raised the extradition with the ambassador in an earlier conversation because the case was a matter of concern for many in the British public," Susman said.</p><p>"British people generally feel McKinnon is guilty 'but they are sympathetic'," Cameron said.</p><p>A home affairs committee hearing to look at the validity of the extradition demands is due to start today, headed by Keith Vaz, with McKinnon's mother Janis Sharp set to give evidence.</p><p>McKinnon, who has been diagnosed with Asperger's syndrome, was <a href="https://www.itpro.com/609504/timeline-gary-mckinnon-on-the-brink-of-extradition" target="_blank" data-original-url="https://www.itpro.com/609504/timeline-gary-mckinnon-on-the-brink-of-extradition">found guilty of hacking into NASA and Pentagon computer systems in 2001 and 2002</a>. However, he claimed he was not attempting to breach national security but instead find proof of the existence of aliens.</p><p>He has been appealing against his extradition since February 2007.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wikileaks, China and Google: What the hack tells us ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/628987/wikileaks-china-and-google-what-the-hack-tells-us</link>
                                                                            <description>
                            <![CDATA[ Wikileaks has released a cable communication indicating China was responsible for hacking Google, but what does it tell us about security in general? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dECgpzJczS5uDHE21VD6i3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WwW46nRjy3xFkr2MxAwP8W-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Nov 2010 17:02:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WwW46nRjy3xFkr2MxAwP8W-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[China]]></media:description>                                                            <media:text><![CDATA[China]]></media:text>
                                <media:title type="plain"><![CDATA[China]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WwW46nRjy3xFkr2MxAwP8W-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ANALYSIS The Chinese Politburo was behind the Google hack, according to a Wikileaks document released as part of the site's wide-ranging leaks of US Embassy cable communications.</p><p>A document, picked up by the <a href="http://www.nytimes.com/2010/11/29/world/29cables.html?_r=1" target="_blank">New York Times</a>, has claimed to cover communications from a Chinese contact telling the American Embassy in Beijing that the Politburo had ordered a hack attack on Google.</p><p>Google had previously claimed sources from within China were responsible for hacks on the search giant and other US companies.</p><p>So what have we learned, if anything, from this?</p><p>First off, has Wikileaks actually released anything that surprising? Given there were already suspicions over China's involvement it may not come as a surprise to many there is now a little more evidence to argue the nation's involvement in hacking Google.</p><p>What is more concerning is the reported wider-ranging plans and an operation by the Chinese Government to breach systems including those of Western allies and US businesses. This becomes even more alarming when the communications leak indicates the hacking work had been going on since 2002.</p><p>So it seems to have taken a while for people to take cyber warfare seriously. Although this year things have sparked into life with various public figures <a href="https://www.itpro.com/627793/cyber-crime-one-of-the-biggest-threats-to-uk-security" target="_blank" data-original-url="https://www.itpro.com/627793/cyber-crime-one-of-the-biggest-threats-to-uk-security">warning about the threat</a>, does this leak not hint the security community was a little late in spreading the word about wars over the web?</p><p>Get a grip on security</p><p>Regardless of tardiness in that respect, the China Google case tells us governments need to get a hold of security as soon as possible.</p><p>"If the news that Chinese authorities were responsible for the Google hacks is true it highlights the growing importance that the Government must take cyber security more seriously," Ash Patel, country manager for UK and Ireland at Stonesoft, told <em>IT PRO</em>.</p><p>"Most of a country's critical systems are controlled by computers and as cyber criminals become better resourced it is easier for them to cripple a country by taking control of these, whether it be politically motivated or not."</p><p>Whilst the UK Government may have invested what appeared to be a significant chunk of money into fighting cyber crime with an additional 650 million, this "really isn't enough," according to Patel.</p><p>Indeed, it pales in comparison to the 20 billion that was discussed to renew the UK's Trident Nuclear deterrent programme, Patel added.</p><p>But while we are likely to see more attacks, we should be wary of hyperbole, according to David Harley, senior research fellow at ESET.</p><p>"I'd certainly expect to see more reports of politically-motivated attacks (on the evidence we now have, you could certainly put Stuxnet into that bracket), because so many people have become aware of the possibility," Harley told <em>IT PRO</em>.</p><p>"However, I'd also expect that an indeterminate proportion of that will be speculation rather than hard fact, and I'm always conscious that a certain amount of such speculation is based on misunderstanding or even sensation-seeking rather than hard fact. And that will apply globally, not just in relation to the Far East."</p><p>So do journalists need to get some perspective as well?</p><p>Perhaps this example is a case in point: a recent report on Stuxnet from Sky News hinted the virus was in the hands of "bad guys." Paul Ducklin, head of technology in the Asia Pacific region for Sophos, took umbrage with the piece, suggesting the security industry needs to focus on realities rather than "speculation."</p><p>"The problem with inaccurate, inflammatory and irresponsible stories about Stuxnet - good though they may be for page impressions and video views - is that they make cyber criminality sound like a second-rate problem when it is positioned against a news backdrop alleging cyber war," Ducklin said in a <a href="http://nakedsecurity.sophos.com/2010/11/25/stuxnet-scared-of-shadows/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+nakedsecurity+%28Naked+Security+-+Sophos%29" target="_blank">blog</a>.</p><p>"Let's stop being frightened of shadows and actually concentrate on getting rid of the cyberenemy already in our midst."</p><p>What of Wikileaks?</p><p>So what of Wikileaks? It has already sparked debate over whether what it is doing is moral or not. Is it OK to place people's lives in danger for the sake of truth?</p><p>Whatever stance you take, it is undoubtedly disarming how easy it appeared to have been for the whistleblower to get their hands on what were thought to be highly confidential documents.</p><p>Given the political furore around the release, one would have expected the embassy cable communications to have been kept securely locked away. This doesn't appear to have been the case.</p><p>According to <a href="http://www.guardian.co.uk/world/2010/nov/28/how-us-embassy-cables-leaked%20Shorten%20Links%20Here" target="_blank">the Guardian</a>, a published chatlog of a conversation between soldier Bradley Manning, believed to be the whistleblower, and a fellow hacker showed how the process was stunningly straightforward.</p><p>"I would come in with music on a CD-RW labelled with something like 'Lady Gaga' erase the music then write a compressed split file. No one suspected a thing ... <em>listened and lip-synched to Lady Gaga's Telephone while exfiltrating possibly the largest data spillage in American history," Manning reportedly said.</em></p><p>Amichai Shulman, chief technical officer with data security specialist Imperva, said the case highlighted the need for organisations to monitor employee behavior with respect to files generally.</p><p>"This embarrassing fiasco - which is certain to drag on for some time - shows that the internal threat is not necessarily about unauthorised access to data, but rather the abuse of legitimate access," Shulman added.</p><p>"Organisations need to wake up to the complexities of internal threats, rather than simply relying on conventional IT security systems."</p><p>Now, if the US Government has dealt with data in too nonchalant a fashion, you have to wonder about how they are handling the personal data UK citizens and others place on American administration websites every day.</p><p>We are living in a global economic world where our data is flying across the world each second and this valuable information needs protection wherever it is.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wikileaks hit by 'denial of service attack' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/628963/wikileaks-hit-by-denial-of-service-attack</link>
                                                                            <description>
                            <![CDATA[ On the day it began leaking US embassy cable communications, Wikileaks says it was hit by hackers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oXQqgKGMSeFE7S3W9GZaED</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wx73Up2E5LVkHtoN5smb7h-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Nov 2010 10:57:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wx73Up2E5LVkHtoN5smb7h-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wikileaks]]></media:description>                                                            <media:text><![CDATA[Wikileaks]]></media:text>
                                <media:title type="plain"><![CDATA[Wikileaks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wx73Up2E5LVkHtoN5smb7h-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Wikileaks claimed to have been hit by a "mass distributed denial of service attack" yesterday.</p><p>The revelation came over the organisation's Twitter page on the day <a href="http://cablegate.wikileaks.org/index.html" target="_blank">Wikileaks</a> started to release a range of US Embassy cable communications.</p><p>The released data includes cables from 1966 up to the end of February 2010, covering confidential communications between 274 embassies in countries across the world and the US.</p><p>Wikileaks' website is now up and running as it continues to leak documents.</p><p>A hacker going by the name of th3j35t3r' claimed <a href="http://twitter.com/th3j35t3r" target="_blank">over Twitter</a> to have been responsible for taking down the website.</p><p>Administrations across the world have raised concerns about the fallout of the leaks, with the US condemning the actions of Wikileaks, claiming the lives of diplomats have been placed at risk.</p><p>Julian Assange, Wikileaks founder, countered by claiming US authorities were worried about being held to account.</p><p>China hack</p><p>Although the documents have not been fully released yet, as they will be trickled out over the coming months, some information has emerged.</p><p>One document, picked up by the <a href="http://www.nytimes.com/2010/11/29/world/29cables.html?_r=1" target="_blank">New York Times</a>, claimed to cover communications from a Chinese contact telling the American Embassy in Beijing that China's Politburo had ordered a hack attack on Google.</p><p>The cable also reportedly suggested the Google hack formed part of a wider operation by the Chinese Government to breach systems including those of Western allies and US businesses.</p><p>According to the communications, the hacking work had been going on since 2002.</p><p>Google had threatened to <a href="https://www.itpro.com/619399/google-to-quit-china" target="_blank" data-original-url="https://www.itpro.com/619399/google-to-quit-china">leave China altogether</a> earlier this year following claims the search giant had been hit by hack emanating from the emerging economic superpower. Google also cited issues with censorship controls in the country as a reason for potentially pulling out.</p><p>David Harley, senior research fellow at ESET, still had reservations about the provenance and motivations behind the attack.</p><p>"While Wikileaks has turned up some interesting comment from government officials, it would be naive to assume that these people have the best understanding of what's really happening," Harley told <em>IT PRO</em>.</p><p>"We do know that there's been quite a lot of samurai (hackers-for-hire) activity out of China for quite a few years, targeting both military and commercial enterprises, and some of that is claimed (in some cases, by the perpetrators) to have been state or military-sponsored, so given the difficulties between Google and China in the past year, we're clearly not looking at the flatly impossible."</p><p>Business message?</p><p>Nick Lowe, head of Western Europe sales for Check Point, said the fact that many workers had authorised access to the US Government network SIPRNET, from which the information was leaked, showed controls may not have been adequate.</p><p>"The fact that hundreds of thousands of authorised users had access to SIPRNET, and could download material to removable storage devices like memory sticks or DVDs, means there's huge potential for a breach - especially when the data written to the removable storage isn't encrypted," he added.</p><p>"Having policies alone on data security issues simply isn't enough. These have to be backed up by technology that applies security automatically, so that users cannot tamper with or work around it. Otherwise leaks are simply inevitable."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>