How Not to Acknowledge a Data Breach
"Overall, I’m willing to chalk this entire episode up to a complete lack of training in how to deal with the news media, but if I were a customer of Wipro I’d be more than a little concerned about the tone-deaf nature of the company’s response thus far.

As one follower on Twitter remarked, “openness and transparency speaks of integrity and a willingness to learn from mistakes. Doing the exact opposite smacks of something else entirely.”
17 hours ago by jonerp
Breach Clarity | Data Breach Analysis
Interesting (beta) tool to answer the question "how bad is it that I was in X breach and what should I do about it?"
25 days ago by dsalo
A Deep Dive on the Recent Widespread DNS Hijacking Attacks
"The U.S. government — along with a number of leading security companies — recently warned about a series of highly complex and widespread attacks that allowed suspected Iranian hackers to siphon huge volumes of email passwords and other sensitive data from multiple governments and private companies. But to date, the specifics of exactly how that attack went down and who was hit have remained shrouded in secrecy.

This post seeks to document the extent of those attacks, and traces the origins of this overwhelmingly successful cyber espionage campaign back to a cascading series of breaches at key Internet infrastructure providers."
8 weeks ago by jonerp

