Most Popular Stories
Events
- A&D Cybersecurity Forum
March 31 - April 1 — Washington, DC - Sensors Expo & Conference
June 7-9, 2010 — Rosemont, IL - Non-Traditional ISR
Mar 22-24, 2010 — Sheraton National Hotel Arlington, Arlington, VA - Non-Traditional ISR
Mar 22-24, 2010 — Sheraton National Hotel Arlington, Arlington, VA
Sponsored Links
HOT TOPICS >> Solid State Drives | IT Security | Open Source | ARM Processors | Google Chrome 4
INDUSTRY >> Healthcare | Government | Financial Services | Biotech | Compliance
Free Newsletter
Latest News
Popular Topics
Whitepapers
- eBook: 7 Undeniable Truths of IT Governance
- Horizontal ECM… Not Enough
- Why Software Projects Fail: A New Assessment of Risk
- Matching Transaction Codes to Applications
- Improving SAP Identity Center Workflow
- Consumption-Based Fundamental Asset Allocation Redefines Investing -- Relevant Investing in a Post-Collapse Era
Section of Kaspersky website compromised
In an ironic twist, a section of Moscow-based security vendor Kaspersky's new U.S. support site was compromised by someone using an SQL injection attack. What that means is a malicious SQL-based script was successfully inserted into the commands being fed into the database.
According to Roel Schouwenberg, a senior antivirus researcher for Kaspersky, the portion of the site that was breached has been developed by a third party. He said, "Obviously we are not happy about that and are in the process of making the review process stricter than it currently is."
No sensitive data or customer information were compromised this time round, though Schouwenberg did admit that a more sophisticated attacker could have potentially accessed some 2,500 email addresses of customers as well as about 25,000 product activation codes.
Interestingly, it was a Kaspersky employee in Romania who alerted workers in the U.S. after spotting a report of the breach on a Romanian Hackers Blog. To their credit, the company removed the affected section of the site, replacing it with an older--and presumably secure--version.
For more on this story:
- check out this article from CNET News
Related Articles:
Web security news from FierceCIO
Related Stories
- Symantec busy, busy, busy
- Smart Trojan targets Firefox extension for access
- Just one security bulletin for Patch Tuesday in May
- Trend Micro: Microsoft's whitelist suggestion helps hackers
- Hacking is top cause of data breaches
- Study: Old security flaws cause some breaches
- China fingered in cyber attacks on U.S. government
- Crippling SSL vulnerability discovered
- How small business can fight hackers
- Heartland settles with American Express
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2010 FierceMarkets. All rights reserved. |
![]() |






