 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Security Detail &#187; RSA Security</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/security-detail/tag/rsa-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/security-detail</link>
	<description>Tony Bradley's take on the latest vital IT security news.</description>
	<lastBuildDate>Mon, 29 Apr 2013 17:39:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>RSA Offers to Replace SecurID Tokens&#8230;Finally</title>
		<link>http://itknowledgeexchange.techtarget.com/security-detail/rsa-offers-to-replace-securid-tokensfinally/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-detail/rsa-offers-to-replace-securid-tokensfinally/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 17:11:38 +0000</pubDate>
		<dc:creator>Tony Bradley</dc:creator>
				<category><![CDATA[compromise]]></category>
		<category><![CDATA[Lockheed-Martin]]></category>
		<category><![CDATA[RSA Security]]></category>
		<category><![CDATA[SecurID]]></category>
		<category><![CDATA[tokens]]></category>
		<category><![CDATA[two-factor authentication]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-detail/rsa-offers-to-replace-securid-tokensfinally/</guid>
		<description><![CDATA[RSA Security probably hoped the issue of compromised SecurID tokens would just get swept under the rug and quietly disappear. No such luck. Following recent attacks against Lockheed-Martin and other defense contractors, which used counterfeit SecurID keys to attempt to gain unauthorized access to the network, RSA Security has had to admit the scope of the problem and [...]]]></description>
				<content:encoded><![CDATA[<p>RSA Security probably hoped the issue of compromised SecurID tokens would just get swept under the rug and quietly disappear. No such luck.</p>
<p style="text-align: left">Following recent <a href="http://www.pcworld.com/businesscenter/article/228927/lockheedmartin_attack_signals_new_era_of_cyber_espionage.html" target="_blank">attacks against Lockheed-Martin </a>and other defense contractors, which used counterfeit SecurID keys to <a href="http://itknowledgeexchange.techtarget.com/security-detail/a-tale-of-two-cyber-attacks/" target="_blank">attempt to gain unauthorized access </a>to the network, RSA Security has had to admit the scope of the problem and offer to <a href="http://www.pcworld.com/businesscenter/article/229553/after_hack_rsa_offers_to_replace_secureid_tokens.html" target="_blank">replace the compromised SecurID tokens</a>, and offer some additional perks as well to try and earn back some customer trust.</p>
<p>There are roughly 40 million SecurID tokens in circulation. Replacing them will not be cheap, but rebuilding customer confidence is much more important than the short term financial impact.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-detail/rsa-offers-to-replace-securid-tokensfinally/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The USA Is Under Cyber Seige</title>
		<link>http://itknowledgeexchange.techtarget.com/security-detail/the-usa-is-under-cyber-seige/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-detail/the-usa-is-under-cyber-seige/#comments</comments>
		<pubDate>Thu, 02 Jun 2011 02:46:23 +0000</pubDate>
		<dc:creator>Tony Bradley</dc:creator>
				<category><![CDATA[china]]></category>
		<category><![CDATA[Cold War]]></category>
		<category><![CDATA[Cyber War]]></category>
		<category><![CDATA[Gmail]]></category>
		<category><![CDATA[L-3 Communications]]></category>
		<category><![CDATA[Lockheed-Martin]]></category>
		<category><![CDATA[RSA Security]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-detail/the-usa-is-under-cyber-seige/</guid>
		<description><![CDATA[It seems that a new Cold War is brewing, but instead of nuclear stockpiles or a Cuban missile crisis we have zero-day exploits and the RSA Security data breach. Whatever you want to call it, the United States seems to be facing a bit of a cyber seige right now. Attackers&#8211;apparently using counterfeit SecurID tokens [...]]]></description>
				<content:encoded><![CDATA[<p>It seems that a new Cold War is brewing, but instead of nuclear stockpiles or a Cuban missile crisis we have zero-day exploits and the <a href="http://itknowledgeexchange.techtarget.com/security-detail/rsas-achilles-heel-wasadobe-flash/" target="_blank">RSA Security data breach</a>. Whatever you want to call it, the United States seems to be facing a bit of a cyber seige right now.</p>
<p>Attackers&#8211;apparently using counterfeit SecurID tokens thanks to information compromised in an earlier breach of RSA Security&#8211;have <a href="http://news.cnet.com/8301-27080_3-20068051-245.html" target="_blank">attacked the networks of defense contractors</a>, including Lockheed-Martin and L-3 Communications. Now, there are also reports that hackers have gained access to hundreds of Gmail accounts, including <a href="http://www.mercurynews.com/business/ci_18186502?nclick_check=1" target="_blank">personal email accounts of senior US officials</a>.</p>
<p>International espionage is nothing new. Nations&#8211;even allies&#8211;are constantly trying to access classified information and learn the secrets of rival nations. All that has changed is that the Internet has made it much easier and faster in many cases to get that information&#8211;anonymously, and remotely from around the world with much less risk of personal harm on the part of the &#8220;spy&#8221;.</p>
<p>We don&#8217;t know for sure who our Cold War enemy is, or if its a single nation or multiple nations. But, Google reports that the Gmail account hacks originated from China. I wonder how all of this fits in with the Pentagon doctrine that a cyber attack can be considered an <a href="http://online.wsj.com/article/SB10001424052702304563104576355623135782718.html" target="_blank">act of war worthy of an armed response</a>?</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-detail/the-usa-is-under-cyber-seige/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A Tale of Two Cyber Attacks</title>
		<link>http://itknowledgeexchange.techtarget.com/security-detail/a-tale-of-two-cyber-attacks/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-detail/a-tale-of-two-cyber-attacks/#comments</comments>
		<pubDate>Mon, 30 May 2011 04:36:54 +0000</pubDate>
		<dc:creator>Tony Bradley</dc:creator>
				<category><![CDATA[authentication tokens]]></category>
		<category><![CDATA[Lockheed-Martin]]></category>
		<category><![CDATA[RSA Security]]></category>
		<category><![CDATA[SecurID]]></category>
		<category><![CDATA[Sony]]></category>
		<category><![CDATA[Sony Playstation Network]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-detail/a-tale-of-two-cyber-attacks/</guid>
		<description><![CDATA[Lockheed-Martin was the target of a &#8216;significant and tenacious&#8217; cyber attack, and Sony has been plagued by attacks for a month now. However, the results of the two network attacks are completely different. The attack on Lockheed-Martin has been linked to the attack earlier this year on RSA Security. That attack compromised the encryption keys [...]]]></description>
				<content:encoded><![CDATA[<p>Lockheed-Martin was the target of a <a href="http://www.pcworld.com/businesscenter/article/228927/lockheedmartin_attack_signals_new_era_of_cyber_espionage.html" target="_blank">&#8216;significant and tenacious&#8217; cyber attack</a>, and Sony has been plagued by attacks for a month now. However, the results of the two network attacks are completely different.</p>
<p>The attack on Lockheed-Martin has been linked to the <a href="http://itknowledgeexchange.techtarget.com/security-detail/rsas-achilles-heel-wasadobe-flash/" target="_blank">attack earlier this year on RSA Security</a>. That attack compromised the encryption keys of <a href="http://itknowledgeexchange.techtarget.com/security-detail/rsa-vague-on-securid-hack-details/" target="_blank">RSA&#8217;s SecurID tokens</a>, and fake authentication tokens were apparently used in the attack on the defense contractor.</p>
<p>You would think that attackers armed with the keys to the vault would be able to clean house and walk out with all kinds of top secret plans for next generation military aircraft and weapons systems, but Lockheed-Martin says no. It claims the attack was detected, identified, and thwarted before any data was compromised, and that its network is locked down and secure.</p>
<p>Then you have Sony. We don&#8217;t know much about the <a href="http://itknowledgeexchange.techtarget.com/security-detail/what-sony-doesnt-know-might-hurt-you/" target="_blank">details of the Sony attacks</a>, but I have not seen any speculation related to RSA SecurID tokens. The attacks against Sony have yielded sensitive information on 100 million customers or so, and it seems like every other day there is a breach of some new Sony network that continues to lead to a data breach.</p>
<p>Following news of the Lockheed-Martin attack, the United States government apparently offered its assistance to handle the matter. It seems, though, that Lockheed-Martin has things under control, and that perhaps the United States should see if it can stop the hemorraging at Sony.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-detail/a-tale-of-two-cyber-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
