Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

Previous Next

Security

March 2009

March 31, 2009

Spam Volume at Pre-McColo Levels, Says Postini

According to Postini, spam volumes have increased to the levels prior to the shut down of hosting company McColo Corp.   CNET News reports that the overall spam volume during the first quarter... More >

Survey Shows Insider Threat Weighs Heavily on Security Pros

Security professionals are most concerned about threats originating from the inside , according to a survey by InformationWeek Analytics/DarkReading.com.   Byte and Switch reports that 52 perc... More >

Red Hat Reveals Details on Fedora Intrusion

Last August, Red Hat admitted that hackers accessed infrastructure servers belonging to the company and the Fedora Project. Now after a six-month investigation, Red Hat is revealing exactly what ha... More >

Survey Shows IT Pros Fear Smartphones

A new survey by security certifications organization ISC2 shows that 90 percent of security professionals think that smartphones pose a significant risk to the enterprise, reports vnunet.com . &nb... More >

Online Fraud Increasing, Says Report

According to the Internet Crime Complaint Center, a nonprofit organization run by the FBI and the National White Collar Crime Center, 2008 was the biggest year ever for reported cybercrime incidents.... More >

US-CERT Creates Tool to Detect Conficker

As security researchers downplay the hype over a possible April Fools Day meltdown caused by the Conficker worm, the Department of Homeland Security is doing its part to help secure federal and s... More >

March 30, 2009

Cyber Crime Costing Trillions

According to vnunet.com , security firm Finjan agrees with AT&T's chief security officer Edward Amoroso's warning that the cost of cyber crime is running into trillions of dollars .   Finj... More >

California Man Accused of Organizing ID Theft Ring

The Las Vegas Sun reports that Jerry Van Le, a resident of Northern California, has been accused of stealing the Social Security numbers from about 25 children, immigrants and others who had not y... More >

Researchers Discover Hole in Conficker

Conficker may not be covering its tracks as tightly as once thought.   According to The Washington Post , Honeynet Project researchers have discovered a security hole in the computer code tha... More >

China Denies Cyber Espionage Claims

The Information Warfare Monitor claims to have uncovered a cyber spy network based in China that has infected computers in 103 countries, reports Digital Trends .   The IWM was originally loo... More >

Analyst Finds Three Flaws in Google Docs

Security analyst Ade Barkah says he's found three flaws in Google Docs that could expose private information.   According to Reuters , one flaw allows images to be accessed even if a document... More >

Media Adds to Hype over Conficker

While some security researchers are saying fears over an April 1 meltdown caused by the Conficker worm are greatly exaggerated , the media is doing its part to build up the hype.   "60 Minute... More >

Firefox Fixes Published Early

Mozilla Firefox 3.0.8 fixes more than just attack code that was released by security researcher Guido Landi. It also patches the flaw exploited by the German  hacker who used it to win the Pwn2Ow... More >

March 27, 2009

Apple Developing Biometric Reader for iPhone, Mac

According to AppleInsider , Apple has filed for a patent for a new technique that would hide a biometric reader inside an iPhone or a Mac.   For the iPhone, the solution would involve a hidden ... More >

OpenSSL Patches Three Security Holes

OpenSSL has patched three security holes that carry "moderate severity" ratings, reports ZDNet .   The flaws involve an ASN1 printing crash, an invalid ASN1 clearing check and an incorrect Err... More >

More Companies Turning to Managed Security

With 98 percent of businesses saying they have suffered a tangible loss due to security risks, many are turning to managed security services for help, according to a Symantec survey.   SearchSec... More >

New Attack Could Make Anti-Virus Software Useless

Researchers Alfredo Ortego and Anibal Sacco of Core Security Technologies are warning about a new form of attack that could render anti-virus software useless.   According to vnunet.com , the a... More >

March 26, 2009

Firefox Update Fixes Online Attack Code

Mozilla developers have worked out a fix for the attack code that was released by security researcher Guido Landi, reports InfoWorld . The code targets a critical, unpatched flaw in the Firefox bro... More >

Sun Updates Java Runtime Environment

Sun Microsystems has updated its Java Runtime Environment to fix several bugs, including multiple security issues.   According to vnunet.com , Version 1.6.0_13 (or JRE 6 Update 13) addresses ... More >

Plutonium Mix-up Reveals Security Flaws at Los Alamos

A recent confidential investigation into fears that a significant amount of plutonium was missing from Los Alamos National Laboratory in New Mexico has raised numerous security questions. It turns ou... More >

Security Fix Added to IE8

A few final tweaks has resolved some security issues in Microsoft's Internet Explorer 8 beta. ChannelWeb reports that Microsoft has fixed a flaw that would allow an attack on IE by using the .Net f... More >

Cisco Security Update Fixes Router Bugs

As part of its twice-yearly update of the Internetwork Operating System used to power its routers, Cisco has released eight security patches .   According to PCWorld , two of the bugs are in i... More >

March 25, 2009

Call Center Denies Involvement in Symantec Data Leakage

BBC reporters claim that, through their undercover investigation, they were able to buy credit card details from a man who worked at a call center contractor in India.   According to Softpedia ... More >

Survey Shows Enterprises Concerned About Employee Fraud

According to an annual security survey by KPMG, enterprises increasingly are concerned that employees will be more tempted to steal information or sell insider knowledge due to the poor economy. &n... More >

Worm Targets Linux Routers

The first of its kind, a new worm is targeting DSL routers running Mipsel , a form of the Debian Linux distribution designed for MIPS processors.   According to vnunet.com , the psyb0t worm ha... More >

March 24, 2009

Researchers Unite to Hunt Conficker C

Security researchers have banded together to hunt down a worm called Conficker C and prevent a massive April Fool's Day infection. According to CNN.com , the group is going by the name Conficker Ca... More >

10 Essential IE Security Settings

Although Internet Explorer slid in market share last year, it continues to be the dominant Web browser. However, it has had its fair share of security problems, such as an IE7 flaw that was being ... More >

HP Offers Free Scanner for Flash Vulnerabilities

With rumors surfacing earlier this month , it turns out to be true that HP is offering a development tool that finds vulnerabilities in Adobe's Flash for free .   InfoWorld reports that SWFS... More >

Three Flaws Found in HP OpenView

Users are being urged to patch their HP OpenView Network Node Manager software as soon as possible.   According to vnunet.com , researchers at Core Security have discovered three flaws that a... More >

Sun Warns of Vulnerability in Java System Identity Manager

Sun Microsystems is recommending that administrators update their Java System Identity Manager software after nine vulnerability issues were discovered. vnunet.com reports that the vulnerabilitie... More >

March 23, 2009

Ukrainian Crime Operation Pulls in $10K/Day

A 16-day infiltration of a cybercrime operation based in the Ukraine found that cybercriminals raked in $172,000 , or $10,800 per day, reports NetworkWorld .   Security vendor Finjan says the ... More >

Chrome, Smartphones Unbroken at Pwn2Own

According to The H , Google's Chrome browser and all of the smartphones managed to make it through the Pwn2Own contest unbroken.   Charlie Miller , who was the first winner of this year's con... More >

Smart Grid a Cyber Security Risk, Experts Say

Cybersecurity experts are cautioning against widespread deployment of smart grid technology, saying a massive blackout could occur if a hacker broke into the system.   CNN.com reports that expe... More >

March 20, 2009

Expert: Critical Infrastructure at Risk of Cyberattack

In a testimony before a U.S. Senate committee, Joseph Weiss, managing partner of control systems security consultancy Applied Control Solutions, said that he has found evidence of more than 125 indu... More >

Researchers Devise Viral Twitter Attack

Security researchers at Secure Science have posted a proof of concept that shows how a new Twitter attack could spread virally .   According to InfoWorld , the researchers claim to have found ... More >

Safari First to Go in Pwn2Own Contest

Security researcher Charlie Miller was the first winner on day one of the annual Pwn2Own competition at the CanSecWest security conference in Canada after hacking the Safari browser in under two... More >

March 18, 2009

Researchers to Report Intel Chip Rootkit Code

Security researchers Joanna Rutkowska and Loic Duflot are planning to release information on what NetworkWorld blogger Jamey Heary calls "the scariest, stealthiest, and most dangerous rootkit" he's... More >

Stimulus, Oscars Popular Spam, Says Symantec

According to Symantec's monthly State of Spam report , the popular topics for spammers in February were the Obama stimulus package, the Oscars and get-rich-quick schemes. However, the most popular s... More >

Military Contractors Looking for Cyber Security Work

The biggest U.S. military contractors are hoping to win billions of dollars in work to protect the federal government from cyber attacks.   The Wall Street Journal reports that defense contrac... More >

Privacy Group Wants FTC to Halt Google Services

The Electronic Privacy Information Center wants the Federal Trade Commission to stop Google from offering online services that collect data until the agency can verify the presence of adequate priv... More >

March 17, 2009

8,000 Comcast Customer IDs Exposed

For the last two months, a list of 8,000 user names and passwords of Comcast customers has been available on the Web. According to The New York Times , the discovery was made by Kevin Andreyo, an ... More >

Bogus E-mails Warn of Terrorist Attack

Several security firms are warning of bogus e-mails that report a terrorist attack .   According to vnunet.com , the spam messages have headlines like "why did it happen in your city?" and "at... More >

March 16, 2009

2008 Record Year for Cybersquatting

A United Nations agency says 2008 was a record year for cybersquatting.   According to a Reuters article on internetnews.com, the World Intellectual Property Organization handled 2,329 disput... More >

Could Egress Put an End to Data Breaches?

A new data exchange system from Egress Software Technologies could finally put an end to breaches after data is forwarded in error, stolen or lost.   Computer Business Review reports that the ... More >

March 13, 2009

Warning: Fake Video Spoofs Facebook Page

Websense is warning of a fake video malware attack that is being circulated as a Facebook page. According to vnunet.com , the attack spreads via e-mails disguised as personal messages on Facebook. ... More >

Microsoft Infrastructure Strategist Named Cybersecurity Leader

Former chief trustworthy infrastructure strategist Phil Reitinger has been appointed as deputy undersecretary of the National Protection and Programs Directorate by DHS Secretary Janet Napolitano. ... More >

Microsoft Update Ineffective

PandaLabs has issued a warning about Microsoft's MS09-008 update , which is supposed to fix vulnerabilities in the Windows DNS server and WINS server. According to Techtree.com , the lab has discov... More >

March 12, 2009

Gartner's Predictions for Identity and Access Management

Gartner has predicted a series of key changes that identity and access management will undergo over the next few years.   According to vnunet.com , Gartner's research predicts that hosted IAM... More >

ScanSafe Reports 'Staggering' Surge in Malware

New research from security-as-a-service provider ScanSafe offers some "staggering" numbers on malware.   According to the research, reports vnunet.com , malware surged by a huge 300 percent du... More >

HP to Announce Flash Security Tool?

internetnews.com blogger Sean Michael Kerner reports that HP may officially announce a Flash security tool on March 23.   According to Kerner, the tool is called SWFscan and is supposed to su... More >

Microsoft Adds Koobface to MSRT

In an effort to put the kibosh on the Koobface worm that has been spreading through social networking sites, Microsoft has added definitions for the worm to its Malicious Software Removal Tool, acc... More >

March 11, 2009

Patch Tuesday Fixes First Critical Bug in Windows 7

This month's Patch Tuesday contained a fix for the first critical vulnerability in Windows 7.   According to Computerworld , the public beta of Windows 7, as well as the previews, contain thre... More >

Buggy Symantec Update Causes Trouble

Mysteriously, Norton Internet Security and Norton Antivirus 2006 and 2007 users got error messages when they tried to download an update to the Product Information Framework Troubleshooter , reports... More >

Adobe Releases Patch for Acrobat, Reader

Just as it said it would , Adobe has released a patch for a critical vulnerability in its PDF viewing and editing software.   According to Computerworld , the update, which you can find here ,... More >

March 10, 2009

Juniper Offers Threat Management Solution

Juniper Networks' Threat Management Solutions provide real-time threat defense and network-wide visibility and control, reports SC Magazine .   The new SRX3000 Series Services Gateways, Unifi... More >

Panda: As Many as 10 Million PC Are Infected

Panda Security warns that as many as 10 million PCs are infected with programs designed to steal personal information. According to InfoWorld , just over 1 percent of 67 million systems that tried... More >

Firefox Has Most Bugs, Fastest Fixes

Just because a browser has more vulnerabilities doesn't make it less secure than another, but rather how quickly those vulnerabilities are addressed is the true test.   A report for Secunia on v... More >

McAfee: Spam Expected to Rise in March

According to McAfee's March 2009 Spam Report, companies are wasting over $180,000 a year in lost productivity because of spam, which is expected to grow by 20 percent in March.   On average, c... More >

March 9, 2009

Cyber Squatting on the Rise, Study Says

A new study by brand protection firm MarkMonitor shows that cyber squatting is on the rise .   vnunet.com reports that the number of incidents last year rose 18 percent to 1,722,133. According... More >

Google Admits Privacy Glitch

Google admits that is has shared a small number of online documents with users that were not authorized to see them.   The Wall Street Journal reports that that privacy glitch was caused by a ... More >

eBay Scammers Target Unpatched Vulnerability in Firefox, IE

According to The H Security , scammers are targeting eBay with a cross-site scripting attack to manipulate the descriptions of goods in order to change or overwrite any item numbers and the advert... More >

March 6, 2009

80,000 New York Officers at Risk After Breach

A security breach at the New York Police Department could put 80,000 police officers at risk of identity theft , according to vnunet.com .   Anthony Bonelli has been arrested for allegedly ill... More >

Three Security Patches in Next Patch Tuesday

Microsoft's next Patch Tuesday, March 10, will contain three security updates , reports CNET News .   One update is rated as "critical" and affects Windows 2000, XP, Vista and Server 2003 and... More >

March 5, 2009

'Botmaster' Sentenced to Four Years

According to the Daily Breeze , former computer security consultant John Schiefer has been sentenced to four years in federal prison for turning thousands of computers into zombies so he could ste... More >

Phony Job Ads up 345 Percent

It seems identity thieves are taking advantage of the abundance of layoffs. According to the UK Association for Payment Clearing Services and the Identity Theft Resource Center, phony job ads have j... More >

Google Dismisses Gmail Flaw

Internet Security Auditors researcher Vicente Aguilera Diaz has released proof of concept of a Cross-Site Request Forgery vulnerability in Google’s Gmail . He originally reported this to Google two ... More >

Scammers Target Stimulus Package

Scammers are already hard at work making use of the U.S.'s new stimulus package, warns the Federal Trade Commission.   Using spam and deceptive Web sites, fraudsters are luring users with the p... More >

McAfee: Increase in Malware Attacks Using Removable Drives

McAfee warns that it is seeing an increase in malware attacks using removable drives .   vnunet.com reports that many of the attacks make use of the autorun feature in Windows, which allows re... More >

Mozilla Patches Eight Bugs in Firefox

Mozilla has fixed eight security issues in the latest update to its Firefox Web browser.   According to Computerworld , Firefox 3.0.7 addresses six "critical" bugs in the browser's garbage col... More >

March 4, 2009

Koobface Reappears on Facebook

Trend Micro warns that a new variant of the Koobface worm , dubbed Worm_Koobface.az, is spreading across Facebook and other social networking sites.   Users are sent a video link "from a friend... More >

Opera Patches 'Extremely Severe' Flaw

Opera has released version 9.64, which fixes several security holes, including one the company rates as " extremely severe ."   According to PCWorld , the flaw would allow an attacker to take o... More >

March 3, 2009

Are Netbooks a Gateway for Hackers?

Netbooks could offer a high-speed gateway for hackers . They're inexpensive, which makes them attractive for consumers, but their lax security makes them easier prey for viruses and hackers, reports ... More >

IBM Says USB Stick to Secure Internet Banking

IBM claims it has come up with a USB stick that it says can ensure safe banking transactions even if a PC is loaded with malware.   According to InfoWorld , the prototype is called ZTIC (Zone ... More >

Google Puts Stop to Trends Malware Attacks

It looks like Google is going after malware writers that are manipulating Google Trends to get their pages to show up as top results in search queries. vnunet.com reports that the number of mali... More >

Cisco Gets on Cloud Security Train

Cisco is dipping into cloud security with a set of new managed, hosted and hybrid e-mail security services, reports eWEEK . Cisco IronPort E-mail Security services will launch in April and gives bu... More >

March 2, 2009

ID Theft off to Rapid Start

A new report from the Identity Theft Resource Center shows that identity theft is off to a rapid start this year. According to the report, U.S. businesses have already been hit by 83 security breach... More >

Spim Level Ticking Upward

Security researchers are finding spim levels again ticking upward . According to internetnews.com , spimmers are using the same tactics that spammers are using on social networking sites: sending ... More >

Time Warner Hit by DoS Attacks

Time Warner Cable says the reason for slow broadband performance that many have complained about is that the company's DNS servers were the target of a series of DoS attacks . According to BetaNews... More >

Kaiser Says Stolen Info Came From Union Office

Kaiser Permanente says it is not the source of the data breach that that affected 29,500 people .   According to MSNBC.com , Kaiser says the data was taken from United Healthcare Workers , a ... More >