Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

Previous Next

Security

February 2009

February 27, 2009

New Facebook Scam Targets Terms & Conditions

A new Facebook scam is targeting the publicity surrounding the site's proposed new terms and conditions, reports vnunet.com . The message reads:   "[Friend's name] has just reported you to Fac... More >

Fiscal 2010 Budget Sets Aside More for Cybersecurity

The Obama administration's fiscal 2010 budget proposal sets aside $355 million for cybersecurity efforts .   According to internetnews.com , a big portion of the funding with go to the Departm... More >

Malware Writers Take Advantage of Google Trends

McAfee is warning that malware distributors are taking advantage of Google Trends to get top billing for their pages.   According to vnunet.com , malware writers are using the service to find... More >

Hacking Contest to Test Web Browsers, Mobile Devices

TippingPoint's DVLabs third annual Pwn2Own contest will focus on Web browsers and mobile devices, reports InformationWeek .   According to Computerworld , the first hackers to crack either a... More >

Google Wants You to Hack Its Native Client

In an effort to make its Native Client more secure, Google is holding a 10-week contest in which it will award cash prizes for the person or team who discovers the most high-impact bugs and reports t... More >

February 26, 2009

Report: Hacking Not Always for Financial Gain

According to a recent report from the Web Application Security Consortium, stealing money and data is not always the main motivation for hackers. Twenty-four percent of 57 Web site hacks from last ye... More >

Microsoft Patches Problems in IE8 for Windows 7 Beta

Microsoft has issued an update for Windows 7 Beta to plug numerous compatibility and reliability holes in Internet Explorer 8, according to ChannelWeb . The patches address a variety of stability ... More >

NSA to Get More Cybersecurity Duties?

According to a Reuters report in InfromationWeek, Director of National Intelligence Admiral Dennis Blair says the National Security Agency may take on a greater role in cybersecurity due to its t... More >

Conficker Gets an Upgrade

The Conficker worm has been upgraded to get around attempts to shut it down.   According to vnunet.com , the new variant, called Conficker B++ , uses a new set of backdoors to update itself in... More >

February 25, 2009

Adobe to Patch Five Flaws in Flash

Adobe is patching its Flash multimedia software to fix five flaws affecting Windows, OS X and Linux systems.   InfoWorld reports that the update addresses a critical flaw that could allow a h... More >

Gmail Users Hit with Black out, Then Phishing Scam

Google Gmail users were hit with a widespread phishing attack hours after a worldwide outage . According to The Register , the malicious message spread through the Google Talk instant messaging ch... More >

Gartner: Convenience Priority with Passwords

Consumers may be more away of security concerns, but they still rely on service providers for protection and persist in using unsafe password management practices, according to a survey from Gartner.... More >

Microsoft Pushes out AutoRun Update

Following a US-CERT security alert, Microsoft is pushing out an update that fixes a bug in the Windows AutoRun software .   According to InfoWorld , the bug is cause for concern, since the Co... More >

February 24, 2009

Researcher Makes Homemade Patch for Adobe Flaws

Lurene Grenier, a senior research engineer with the Sourcefire Vulnerability Research Team, has created her own patch for the flaw in Adobe Reader and Acrobat .   Adbobe has said it won't have ... More >

Facebook Hit By 'Error Check System' Attack

Security experts are concerned by the methods being used by a new rogue application spreading through Facebook .   vnunet.com reports that the 'Error Check System' seems to be harmless in its ... More >

Symantec Warns of Excel Bug

Symantec is warning that attackers are going after a zero-day vulnerability in Microsoft's Excel spreadsheet program .   According to InfoWorld , the vulnerability affects Excel 2007 and Excel... More >

Top 20 Ways to Improve Computer Security

A group of U.S. government security organizations that includes the NSA, US-Cert and the SANS Institute has compiled a list of the top 20 security actions that organizations should take to improve c... More >

Another Payment Processor Breached

Visa and MasterCard are notifying banks about the breach of another payment processor. This incident is not related to the massive Heartland Payment Systems incident reported last month.   Acc... More >

February 23, 2009

Microsoft Working on More Secure Web Browser

Microsoft developers are working on a new browser that they say could be far more secure than Google's Chrome, Mozilla's Firefox or Microsoft's own Internet Explorer, reports InfoWorld . The prototy... More >

Survey Shows Booted Workers Steal Company Info

A survey by Ponemon Institute shows that more than half of laid-off workers take data on their way out . NetworkWorld reports that 59 percent of respondents admitted that they stole company data, w... More >

Another Data Breach for University of Florida

The University of Florida is notifying at least 97,200 people that a hacker accessed its antiquated Grove system and possibly stole their names and Social Security numbers. internetnews.com reports... More >

February 20, 2009

Black Hat Demo Questions Security of SSL

The security of the Secure Sockets Layer protocols is being called into question again following a presentation at the Black Hat conference.   According to vnunet.com , a researcher calling h... More >

Two Acquisitions for Novell Boost Security

In an effort to reduce its customers' risk, Novell has made two new acquisitions , reports vnunet.com .   The company purchased compliance and privileged user management firm Fortefi . Accord... More >

Adobe Flaw Makes PDFs Risky

A flaw in Adobe Reader and Acrobat could compromise PCs if a user opens a malicious PDF file.   InfoWorld reports that the flaw  triggers a buffer overflow condition and gives attackers control... More >

February 19, 2009

Verizon Has Plan for Spam

According to Spamhaus.org , Verizon.net hosts the most spam-spewing zombies of any other major ISP in the U.S. A Composite Block List breakdown shows that of the 225,454 U.S. based Internet addres... More >

February 18, 2009

IE 7 Flaw Being Exploited in Wild

An exploit for the Internet Explorer 7 flaw that was patched in Microsoft's last Patch Tuesday release is now in the wild.   According to CNET News , the malicious code comes via a Word docu... More >

Spammers Crack Windows Live Hotmail CAPTCHA

The recently updated Windows Live Hotmail CAPTCHA System has been hacked , reports IT PRO .   Last year, Microsoft revamped the CAPTCHA authentication it uses in an effort to stop automated bo... More >

RSA: Phishing Attacks Soar

A report from RSA Security shows that global phishing attacks surged by 66 percent last year as compared to 2007, resulting in 135,426 separate incidents.   vnunet.com reports that the UK was... More >

February 17, 2009

Fortinet Intros Firewall for Web Apps

Aimed at midsize businesses, Fortinet has announced a Web application firewall, FortiWeb 1000B , that processes SSL and XML traffic separately from the Web server, according to NetworkWorld .  ... More >

Java Patching Made Easy

Need to find out if your Java environment is up to date? Now you can, thanks to this link from Sun that allows you to run a quick scan of your installation.   ZDNet blogger Ryan Naraine has t... More >

Cisco, Trend Micro Secure Routers

Cisco is making integrating Internet security inside the home easier thanks to a collaboration effort with Trend Micro. According to CNET News , Trend Micro's Home Network Defender will be incorpora... More >

Report Lists Top Security Threats in 2009

The Secure Enterprise 2.0 Forum has released its top eight security threats for 2009 , reports ReadWriteWeb . The report doesn't name specific technologies or companies that are risky, but rather "... More >

February 16, 2009

Defense Department's University on Technological Threats

In an effort to get a better grasp on technological threats, the Defense Department is making use of the National Defense University . The university is located at at Fort Lesley J. McNair, and its ... More >

First Arrests in Heartland Breach

The first arrests associated with the Heartland security breach have been made. Computerworld reports that Florida residents Tony Acreus, Jeremy Frazier and Timothy Johns were arrested for alleged... More >

Another Delay for Massachusetts' Data Security Regulations

According to Computerworld , Massachusetts has delayed the deadline for companies to comply with data security regulations ... again. The original deadline was Jan. 1. Then it was moved back to May ... More >

February 13, 2009

Phishers Targeting Apple's MobileMe

TG Daily reports that phishers are casting their nets in Apple's MobileMe in an effort to get credit card information.   Fake e-mails, purporting to be official communications from the Mobile... More >

Massive Security Update from Apple

PC Magazine reports that Apple has released patches that address over 50 distinct vulnerabilities .   Mac OS X v10.4.11 and Mac OS X v10.5.6 are addressed in the OS X Security Update 2009-001... More >

Flaw in Android 'Sensationalistic'?

Security researcher Charlie Miller says he's found a flaw in Android that is serious enough that he's recommending people stop using the browser until it's fixed.   According to CNET News , t... More >

Microsoft Offers Bounty for Conficker Authors

Microsoft is willing to pay $250,000 to know who's behind the Conficker computer virus that infected more than 15 million machines, reports Telegraph.co.uk .   The worm also is known as Downad... More >

February 12, 2009

Hijackers Take over Facebook Page

According to internetnews.com , spammers have taken control of Facebook site " 5,000,000 against the new version of Facebook ." Their ads promoted get-rich-quick schemes and a guide on how to seduce... More >

RIM Reissues BlackBerry Security Patch

In an issue related to Microsoft's recent patch for Internet Explorer , Research in Motion has reissued a security patch for software used on its BlackBerry smartphone.   According to vnunet.c... More >

Memo: 67 Computers Missing from Los Alamos

According to watchdog group Project on Government Oversight, the Energy Department sent a memo to Los Alamos officials concerning the 67 computers that have gone missing . Thirteen of those were los... More >

Now F-Secure Falls Victim to SQL Injection Attack

The same hacker site that claims to have hacked Kaspersky Labs and BitDefender now says it has breached the site of F-Secure .   According to CNET News , F-Secure has taken the affected se... More >

February 11, 2009

Forensic Firm Finds Sensitive Data on eBay Hard Drives

During a study by Kessler International, the computer forensics firm found that 40 percent of hard drives that it purchased in bulk on eBay contained personal, private and sensitive information . Th... More >

Hackers Push Malware Through Digg.com

According to Panda Labs, scammers are using the popular news aggregator Digg.com to get users to download malware .   Purporting to be news items about celebrities, the posts contain a link to ... More >

E-Mail, Web Security Services from Websense

Websense is rolling out new e-mail and Web security services . SC Magazine reports that Websense Hosted Email Security and Websense Hosted Web Security will protect businesses from emerging Web 2... More >

February 10, 2009

Virus Infects Houston Court System

Houston's municipal court system has been infected by a virus, according to an Associated Press story in The Houston Chronicle.   The court system actually had to close down Friday afternoon ... More >

Federal Government Misses DNS Deadline

The first deadline for the federal government to push out DNS security mechanisms on its .gov top-level domain has been rescheduled. NetworkWorld reports that officials now say it will happen by ... More >

Obama Calls for Cybersecurity Review

In an effort to determine how federal agencies use technology to protect secrets and data, President Obama has ordered a 60-day review of the nation's cybersecurity . The effort will examine all gov... More >

FAA Computer System Hacked

Hackers were able to break into the FAA's computer system last week and access the names, Social Security numbers and medical information of 45,000 employees and retirees, according to the Associat... More >

February 9, 2009

Kaspersky Gets Hacked

According to Security Watchdog , anti-malware firm Kaspersky Lab's U.S. portal has been hacked .   The hacker goes by the name Unu and has posted details of his SQL injection attack on the H... More >

TwitterHawk Initiative Tries to Curtail Spam

A new target marketing provider, TwitterHawk, has made changes to its services in order to save Twitter users from spam .   Marketers can use TwitterHawk to monitor Twitter posts for keywords a... More >

Economic Stimulus Plan Attracts Spammers

Even before the law has been passed, spammers are already going after economic stimulus plan , according to vnunet.com .   The SANS Institute reports that there is scam offering users a refund... More >

Security Breach Affects Nearly 30,000 Kaiser Employees

Nearly 30,000 Kaiser Permanente employees are being notified that their personal information may have been breached, reports CNET News . A "handful" of employees have already reported identity frau... More >

February 6, 2009

Handful of Registrars Responsible for Most Spam

According to research by KnujOn, 83 percent of all the spam and malware distributed over the past eight months is coming from only 10 registrars .   The top 10, reports Ars Technica , are: &nb... More >

Paranet Expands to Cover VoIP Security

According to a press release , Paranet Solutions has decided to add VoIP Security Services to its Security Solutions Suite. The addition of VoIP Security Services will address issues like illegal re... More >

ATM Thieves Bag $9 Million in RBS Breach

Late last year, ATM thieves bagged $9 million in cash in one day by exploiting a breach at payment processor RBS WorldPay, reports The Washington Post .   Hackers broke into RBS's databases an... More >

Sunbelt Upgrades Network Vulnerability Scanner

Sunbelt Software has upgraded its network vulnerability scanner, Sunbelt Network Security Inspector. According to the press release , the new scanner boasts a new scanning engine, a more intuitive u... More >

February 5, 2009

Four Security Flaws in Next Patch Tuesday

Computerworld reports that Microsoft's next Patch Tuesday, expected Feb. 10, will address four security flaws , two of them labeled as "critical."   According to the advisory , the updates af... More >

North Dakota Drivers Infected by Fake Parking Tickets

Hackers are always looking for new ways to get people to use malicious Web sites. BBC News reports that fake parking tickets seems to be the latest trick.   Cars in Grand Forks, N.D., were t... More >

Google Fixes Cross Browser Attack Vector in Chrome

Google has released an update to Chrome browser version 1.0.154.48 that fixes a cross-browser attack vector , reports internetnews.com .   The fix addresses a bug that allows command line argu... More >

Disgruntled SF Admin Files Claim Against City

Terry Childs, who made headlines last year when he was accused of locking top administrators out of San Francisco's new computer system , has filed a claim against the city of San Francisco stating ... More >

February 4, 2009

Cisco Warns of Wireless LAN Controller Flaws

According to ZDNet , Cisco has issued a warning about multiple security flaws in some of its Wireless LAN controllers .   If you have Cisco Wireless LAN Controllers (WLCs), Cisco Catalyst 6500... More >

Hacker Demos Drive-By RFID Heist

According to vnunet.com , British white hat hacker Chris Paget has demonstrated how easy it would be for someone to clone U.S. passport cards that use Radio Frequency ID chips .   Using a $250... More >

China Takes the Lead in Spam Market

According to McAfee, January saw in increase in the number of spam messages originating from China. CIOL reports that while the use of zombie networks is down, China now beats the U.S. as the top... More >

Firefox Update Fixes Critical JavaScript Issue

CNET News reports that Firefox version 3.0.6 fixes six bugs , including a critical JavaScript issue affecting the browser's layout engine. Mozilla's Thunderbird e-mail client and SeaMonkey Internet... More >

February 3, 2009

Ask.com Gets Symantec to Secure Traffic

Thanks to a two-year deal, Symantec will help Ask.com surfers identify malicious Web sites by providing safety level ratings via a new toolbar, reports the Associated Press . The ratings are integ... More >

IBM Report: Web Apps Making Businesses Vulnerable

According to IBM's latest X-Force Trend and Risk report, businesses are making it easier for hackers to sneak onto their legitimate sites , exposing customers to security threats, because they are ... More >

DoJ Phishing Own Employees

According to vnunet.com , the Departent of Justice is phishing its own employees to test security awareness.   The e-amils, sent from Jan. 25 to Jan. 27 , claim to be from the "Thrift Saving... More >

February 2, 2009

Big Security Hole in Windows 7, Says Researcher

A security researcher says there's a big problem in the latest beta version of Windows 7, reports vnunet.com .   Long Zheng has released a proof-of-concept for a problem involving the User Acc... More >

Data Breaches Cost More Than Ever, Study Finds

A study by the Ponemon Institute shows that companies are losing more than ever from data breaches because customers are turning their backs on them.   NetworkWorld reports that every data re... More >

Google Glitch Flags Every Site as Dangerous

According to InformationWeek , a misplace forward slash (/) that caused every search result to be flagged as dangerous confused many Google users.   In a blog post, Google VP Marissa Mayer sa... More >

Fannie Mae 'Hacker' Pleads Not Guilty

According to The Inquirer , former Fannie Mae computer programmer Rajendrasinh Makwana has pleaded not guilty to charges that he created a computer time bomb to wipe 4,000 Fannie Mae computer serv... More >

Security Software Solutions

Security software and strategies to protect valuable company information and insure compliance with global, federal, and state regulations.

Enterprise Manager

Tools, best practices and expert advice on managing your enterprise IT infrastructure, databases, and Web service components.

Data Warehousing for Business Intelligence

Comprehensive storage solutions for better data access and retrieval, leading to better-informed business decisions.

Virtualization

New business consolidation breakthroughs for better server optimization, resulting in more storage and computing capacity.