Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

May 29, 2009

President Makes Cyber Czar Role Official

It's official. CNN reports that today President Barack Obama announced that he is creating the post of cyber security coordinator to oversee "a new comprehensive approach to securing America's di... More >

Pentagon to Create New Cyber Command

With President Barack Obama set to announce White House plans for protecting U.S. critical infrastructure from cyberattacks, comes news that the Pentagon has plans to create a new military command ... More >

Study: BlackBerry More Secure Than iPhone

DailyTech reports that according to a study by Lopez Research, Research in Motion's BlackBerry beats out Apple's iPhone in terms of security.   The study rated the phones on a scale of 0 to 4... More >

Thousands of Australians Victims of Identity Theft

The personal details of thousands of Australians has been available on a free blogging site for over a month, reports Australian IT . The information includes Visa, Mastercard and American Express... More >

McAfee's 'Most Dangerous Search Terms'

McAfee has come out with its list of " The Web's Most Dangerous Search Terms ," and if you're looking for screen savers, music lyrics or free digital music, beware.   According to internetnews.... More >

Microsoft Warns of DirectX Vulnerability

Microsoft is warning users that hackers are exploiting an unpatched critical vulnerability in DirectX, reports Computerworld . Malicious QuickTime files are being used to hijack computers.   ... More >

May 28, 2009

Aetna Notifies 65,000 of Security Breach

The Social Security numbers of 65,000 current and former employees of Aetna have been compromised in a job application Web site data breach, reports ITWorld . The site, which is maintained by an e... More >

Feds Create Three New Cyber Challenge Competitions

The country is looking for a few good ... high school hackers?   According to Forbes , the military-funded Cyber Challenge is offering three new contests aimed at high school and college stud... More >

Free Security Benchmark for iPhone

The industry's only consensus security benchmark for the iPhone is now available thanks to the Center for Internet Security.   The goal of the benchmark, according to Computerworld , is to he... More >

Sophos: Beware of Western Union Spam

Sophos is warning about a new crop of spam that claims to be from Western Union.   According to vnunet.com , the message tells users they can collect a money transfer amount by printing out a... More >

RIM Patches PDF Flaw

Research in Motion has patched a flaw in its BlackBerry Enterprise Server's BlackBerry Attachment Service, reports Computerworld .   The flaw in the service, which processes message attachment... More >

May 27, 2009

Wormlike Phishing Attack Targets Twitter Users

Twitter users have been targeted by a kind of phishing attack with worm-like characteristics , reports Computerworld .   The offending site is called TwitterCut, which would send users a messa... More >

Vasco Lets Remote Workers Authenticate with Cell Phone

In an effort to provide safer access to remote workers, Vasco has come up with two-factor authentication that uses an employee's mobile phone as the authentication device.   According to vnun... More >

Spam Jumps 90 Percent, Says Symantec

A report by Symantec shows that corporate networks are being flooded with unsolicited e-mail.   According to The Register , spam made up 90.4 percent of messages on corporate networks in May,... More >

PandaLabs Holds Competition to Boost Testing of New Security Suite

The first public beta of PandaLabs' upcoming Global Protection 2010 security suite is now live , reports vnunet.com . The suite includes anti-malware protection, firewall software and tools to prot... More >

May 26, 2009

Most Web Sites Vulnerable, Says WhiteHat

According to a recent report from WhiteHat Security, most Web sites have a vulnerability .   The report shows that 82 percent of Web sites have had a high, critical or urgent issue over their l... More >

A Little Help for Creating Strong Passwords

Like may of us, New York Times blogger Riva Richmond has frequently broken every rule of good password security, such as using her name or the same password for multiple accounts.   But now, o... More >

Updated SMB Security Suite from Trend Micro

Trend Micro has updated its small business security suite, reports vnunet.com . Worry-Free Business Security version 6.0 now features URL filtering and new Smart Scan capabilities, as well as USB d... More >

SharePoint Bug Shuts Down App

A flaw in SharePoint will shut down the application after six months, warns Microsoft.   According to vnunet.com , the problem occurs when users install service pack two (SP2) for Office ShareP... More >

May 22, 2009

Neeris Behind U.S. Marshals' Network Problems?

Malware knocked the Windows-based computer systems at the U.S. Marshals Service offline, reports Computerworld . It is not clear if the malware caused the network outage or if the agency took syst... More >

DNS Attack Cripples China's Internet Access

A DNS attack in China crippled Internet access in part of the country, reports Computerworld .   The DDoS attack targeted only DNSPod's DNS servers. Access to the registrar's IP address was bl... More >

Typo-Squatting Site Designed to Look Like Twitter

vnunet.com reports that Trend Micro security researcher Rik Ferguson has discovered a typo-squatting site that is designed to look like Twitter . Trying to look authentic, the URL uses only two 't'... More >

Another Phishing Attack on Facebook

Another day another Facebook phishing scam, it seems.   This time, Facebook users received an e-mail message with the subject line “Hello,” then were directed to a fake Facebook page that aske... More >

May 21, 2009

DoD Requests info for 'E-Mail Security Gateway'

The U.S. Department of Defense has released a Request for Information for an "e-mail security gateway" that will protect all DoD e-mail systems attached to its Non-classified IP Router Network, rep... More >

Conficker 'Still a Significant Botnet'

With news about Conficker petering out, it's easy to think the worm does not pose a risk, but that's not the case.   According to researchers at Symantec, Conficker is infecting about 50,000 ne... More >

National Archives Offers Reward for Return of Hard Drive

The U.S. National Archives and Records Administration is offering a $50,000 reward for the safe return of a missing external hard drive, reports ChannelWeb .   As we reported yesterday , a c... More >

Adobe to Start Its Own Quarterly Patch Tuesday

Adobe has announced that it plans to release quarterly security updates that will coincide with Microsoft's Patch Tuesday, according to CNet News .   Starting this summer, the updates will be... More >

May 20, 2009

Mac OS X Still Vulnerable to 6-Month-Old Security Flaw

Apple has yet to fix a security vulnerability that was discovered six months ago.   ZDNet reports that Mac OS X is vulnerable to a "highly critical" security flaw in Java that allows an attac... More >

Rudder Blames E-Mail Glitch for Bank Account Exposure

Financial monitoring company Rudder blames an e-mail glitch for accidentally exposing the bank account information of hundreds of its customers, according to PCMag.com .   Rudder CFO Nikunj S... More >

Microsoft Adds to Security Development Lifecycle

Microsoft is adding to its Security Development Lifecycle in an effort to allow developers to integrate the SDL more tightly into the development process, reports vnunet.com .   The company is... More >

PCI Council Creates Cloud Security Task Force, Announces Board of Advisors

The Payment Card Industry Council has established a task force to look into potential cloud security risks , reports NetworkWorld .   Specifically, "the Council is evaluating various options t... More >

National Archives Hard Drive Missing

A computer hard drive containing a large amount of personal information from Bill Clinton’s presidency has gone missing from the National Archives , reports The New York Times .   The apparent... More >

May 19, 2009

Three Cyber Security Groups Form 'Chain of Trust'

The Anti-Spyware Coalition, the National Cyber Security Alliance and StopBadware.org has joined forces to form the Chain of Trust Initiative . According to Computerworld , the goal of the initiativ... More >

Spammers Pushing Acai Supplements

internetnews.com reports that spammers are using the Cutwail botnet, one of a new wave of botnets, to push an Acai dietary supplement , Acai Power Slim. While pushing dietary supplements is nothing... More >

Kaspersky Warns of Malware on Virgin Systems

Kaspersky Labs is warning users that they should scan new Windows XP netnooks for malware before connecting them to the Internet, reports Computerworld .   Kaspersky developers discovered the... More >

Microsoft Confirms IIS Bug, Downplays Severity

Computerworld reports that although Microsoft confirmed that its Internet Information Services Web-server software contains a flaw that could allow attackers to steal data, it downplayed the sever... More >

No Need for Standalone Anti-Spyware

Beware of standalone anti-spyware products, warns Gartner.   According to vnunet.com , Gartner analyst Neil MacDonald says some companies are trying to charge customers extra for anti-spyware ... More >

Facebook Joins OpenID Ranks

According to a TechCrunch article in The Washington Post, Facebook has joined the growing ranks of OpenID supporters .   This means that Gmail users can pop over to their Facebook account, or... More >

May 18, 2009

'The New York Times' Twitter Account Hacked

According to Mashable , the Twitter account of The Moment , a popular fashion blog belonging to The New York Times, has been hacked.   The incident caused more than half a million users to get... More >

U.S. Schools Need to Improve Cyber Security

According to CDW Government's School Safety Index, 55 percent of U.S. school districts has suffered security breaches, reports InformationWeek . What's more, 75 percent of surveyed schools admitte... More >

Ex-Employee Tries to Steal $9 Million

According to internetnews.com , Abdirahman Ismail Abdi tried to transfer $9 million to accounts in Qatar after he was fired by the California Water Service Company. While Abdi had access to critic... More >

Scammers Take Advantage of Kindle Publishing for Blogs Flaw

InformationWeek reports that scammers are cashing in on a vulnerability in Amazon Kindle Publishing for Blogs .   Apparently, Amazon failed to include any technical mechanism to determine whet... More >

Google: Chrome was Vulnerable to Same Safari Bug

Google has revealed that its Chrome browser was vulnerable to the same bug that a German college student going by the name of "Nils" used to bring down Apple's Safari in the Pwn2Own contest, report... More >

May 15, 2009

DoD Official Faces Espionage Charges

The Department of Defense has charged James Wilbur Fondren Jr. with conspiring to provide classified information to an agent with ties to China, reports InformationWeek . Fondren was a civilian em... More >

Juniper Integrates Security into Junos

Juniper Networks has embedded a number of security appliances into its Junos network operating system, due to be released May 15.   According to vnunet.com , Junos 9.5 adds unified threat man... More >

McAfee Buys Solidcore

McAfee has agreed to purchase privately owned Solidcore Systems Inc. for about $33 million, plus another $14 million if certain performance targets are met, according to an Associated Press articl... More >

Facebook Hit by Phishing Attack ... Again

Facebook has been hit by another phishing attack , reports Reuters . The attack is similar to one that occurred a couple of weeks ago in which phishers sent phoney e-mail messages that appear to ... More >

'Gumblar' Setting Records Through Backdoor Infection

According to vnunet.com , the malware attack officially known as "Gumblar" is compromising Web sites and injecting malicious JavaScript code at a record-setting pace.   The attack can launch ... More >

San Antonio Selected for Air Force Cyber Command

Lackland Air Force Base in San Antonio, Texas has been chosen as the headquarters for a new cyber command , according to the San Antonio Express .   The headquarters will focus on protecting A... More >

May 14, 2009

OLPC's Krstic to Help Apple with Security?

Is Apple getting some security help from OLPC's security guru, Ivan Krstic? ZDNet blogger Christopher Dawson thinks so. He reports that Apple has hired him "presumably to work on security within t... More >

May 13, 2009

D-Link Secures Home, Small Office Routers

In an effort to protect home and small office routers from automated attacks, D-Link has added CAPTCHA protections , reports vnunet.com . The user will be required to enter a small amount of text d... More >

Visa Card Acts as Authentication Device

Deloitte is testing of a new type of corporate credit card that doubles as a two-factor authentication device for remote network access.   According to vnunet.com , 500 Deloitte employees are t... More >

Adobe Fixes Reader, Acrobat Bugs

As promised , Adobe has patched several security flaws in its Adobe Reader and Acrobat products, reports The H .   The updates fix a bug in versions 9.1.1, 8.1.5 and 7.1.2 of Adobe Reader and... More >

14 Vulnerabilities in PowerPoint Patch Tuesday Update

Microsoft's single security update for May's Patch Tuesday fixes 14 distinct vulnerabilities in Microsoft Office PowerPoint, reports InformationWeek . One vulnerability is rated as "critical," w... More >

Almost 70 Security Fixes in Mac OS X 10.5.7

Apple's Mac OS X update includes nearly 70 security fixes .   According to Computerworld , more than a third of the Mac OS X 10.5.7 security patches are considered critical and carry the "arbi... More >

May 12, 2009

Court OKs TD Ameritrade Data Theft Settlement

People who used TD Ameritrade's services before Sept. 14, 2007 will be able to benefit from the settlement of a class-action lawsuit filed over client data theft , reports Newsvine.com . The breach... More >

How to Protect Your Privacy on Google

In an IDG article in The New York Times, author Robert L. Mitchell says Goggle offers many ways for users to protect their privacy -- you just have to find them. Here are a few.   Use the Go... More >

Google Insists Moroccan Web Site Not Hacked

According to InformationWeek , Google is insisting that its Moroccan Web site was not hacked . However, a screen shot by Habib Haddad, founder of the Google-powered Arabic search engine Yamli, su... More >

Employee Stole Johns Hopkins Patient Data

More than 10,000 patients of Johns Hopkins Hospital could be at risk of identity theft after a former employee allegedly stole patient data, reports Computerworld .   So far, law enforcement ... More >

May 11, 2009

Microsoft to Test Windows 7 RC's Update Abilities

In an effort to test Windows 7 RC’s update mechanism, Microsoft will send users up to 10 fake fixes on Tuesday, May 12, reports TechSpot . The software giant is trying to determine its ability to ... More >

China Makes Spam Bulletproof

According to Computerworld , $700 is all a spammer needs to access a server in China to send all the spam they like. The practice is called bulletproof hosting and also can be used to register dom... More >

What Does a Trojan Look Like?

Do you know the color of spyware? Or the shape of a Trojan? InformationWeek reports that on a commission from MessageLabs, artists Alex Dragulescu and Julian Hodgson are showing that online threats ... More >

Heartland Eats over $12 Million in Fines, Legal Fees

According to vnunet.com , it turns out that the Heartland data breach cost the payment processor more than $12 million in fines and legal costs . Company CEO Robert Carr says more than half that ... More >

Microsoft Finds, Fixes Windows 7 Bug

Microsoft has discovered the first bug in the Windows 7 Release Candidate , reports vnunet.com .   A fix has been issued through Windows update for the flaw that could cause application failur... More >

UC Berkeley Databases Breached

According to InformationWeek , Hackers accessed health services data at University of California, Berkeley , and stole the personal information of more than 160,000 students, alumni and parents. Th... More >

May 8, 2009

Survey: Women More Affected by Identity Theft

According to a survey by Affinion Security Center, women are more affected by identity theft than men .   CNET News reports that 17 percent of women said they lost $1,000 or more from ID theft... More >

Phishers Start Spamming Facebook Users

Spammers who went phishing on Facebook last week have now started to send messages to the accounts that they cracked.   Computerworld reports that while some of the spam is your typical pharm... More >

Single Security Patch for May Patch Tuesday

There is only one security update slated for Microsoft's next Patch Tuesday release.   According to Computerworld , the fix will address a "critical" vulnerability in PowerPoint that develope... More >

Virginia Will Not Pay Hacker's Ransom

Virginia says it will not pay a $10 million ransom that was requested by a hacker who compromised the Virginia Health database, reports DailyTech . Instead, Sandra Ryals, director of the Department... More >

Google Reissues Chrome Update

Shortly after releasing an update to patch two vulnerabilities in Chrome, Google released a replacement update to prevent a batch of crashes that turned up as well, according to CNET News . &nbs... More >

May 7, 2009

Report: Air Traffic Control at Risk of Cyberattack

A U.S. Department of Transportation audit found that air traffic control systems are at high risk of cyberattack due to the use of insecure Web applications by aviation authorities around the country... More >

Researchers Release VBootkit 2.0 Code

Even though they promised not to, researchers Vipin Kumar and Nitin Kumar have released proof-of-concept code that can be used to control a computer running Microsoft's Windows 7. InfoWorld reports... More >

PandaLabs Warns of Bogus Search Engines

ComputerWeekly reports that PandaLabs says cybercriminals are creating specialized search engines to push users directly to pages designed to distribute malware, like fake anti-virus programs. &nb... More >

Google Fixes Two Bugs in Chrome

Google has released an update for its Chrome browser to address two vulnerabilities , one of which is rated as critical.   The Register reports that the critical flaw deals with a failure to p... More >

North Korea Forms Military Hacking Unit

According to vnunet.com , North Korea has built a new military unit comprised of 100 hackers to handle cyber warfare with the U.S. and South Korea. The until will not only by charged with infiltra... More >

May 6, 2009

Federal Agencies Vulnerable to Cyberattacks

According to Nextgov , a panel of government oversight officials and industry security professionals told the House Oversight and Government Reform Subcommittee on Government Management, Organizatio... More >

Swedish National Indicted for Hacking Cisco, NASA

According to DailyTech , 21-year-old Swedish national Philip Gabriel Pettersson has been accused by the U.S. government of stealing programming information from NASA and Cisco in 2004.   Spec... More >

Windows 7 Still Contains Well-Known Flaw

After all the talk of the enhanced security features of Windows 7 , the operating system still contains a flaw in the Windows Explorer feature that could allow virus writers to disguise executable... More >

Free Security Software Gets 'Best Buy' Rating

Three free security programs have received Consumer Report's "best buy" label.   Computerworld reports that while security suites from Eset, McAfee and Symantec all earned scores in the 70's ... More >

Chrome, Firefox Users on Top of Patches, Study Shows

Apple Safari and Opera browser users are more likely to be using unpatched versions than Google Chrome or Mozilla Firefox users, according to a recent study by Google Switzerland and the Swiss Federa... More >

May 5, 2009

DoD to Expand Cyber Security Outreach Program

According to internetnews.com , the Department of Defense plans to grow its cyber security outreach program .   The Defense Industrial Base (DIB) Cyber Security Task Force is looking to add ma... More >

Pirated Copies of Windows 7 RC Contain Trojan

InfoWorld reports that pirated copies of the Windows 7 Release Candidate appearing on file-sharing sites contain a Trojan. It's unclear what the exact name of the Trojan is. One commenter on a Min... More >

Parabon Preps Companies for DDoS Attacks

Parabon Computation hopes to help companies better prepare for distributed denial of service (DDoS) attacks by offering an online service that simulates a full-fledged DDoS attack on their networks. ... More >

Virginia Department of Health Professions Receives Extortion Demand

According to InformationWeek , the Virginia Department of Health Professions has received an extortion demand for $10 million to return more than 8 million patient records and 35 million prescript... More >

McAfee: Botnet Ranks Growing

According to McAfee's quarterly threat report, the number of computers connected to botnets jumped to more than 12 million over the first quarter of 2009.   vnunet.com reports that the U.S. a... More >

Researchers Hijack Torpig Botnet

Researchers from the University of California were able to access and gain control over a botnet known as Torpig or Sinowal, allowing them insight into how it steals personal information.   Acco... More >

May 4, 2009

Tests Show McAfee Vulnerable to Cross-Site Scripting

ReadWriteWeb blogger Lidija Davis says tests this weekend reveal that McAfee's site is vulnerable to cross-site scripting . The issue seems to be due to poor output filtering.   In addition, i... More >

Adobe to Release Reader, Acrobat Patch Next Week

Adobe says it will have patches for the latest flaws in Acrobat and Reader by May 12 , according to InfoWorld .   Last week, Adobe said that a newly discovered critical vulnerability in Adobe... More >

32,000 Warned About LexisNexis Security Breach

LexisNexis has admitted that for more than three years, criminals used its information retrieval service to commit credit card fraud.   According to The Associated Press , LexisNexis has begun ... More >

May 1, 2009

New Standard for Card Data Encryption on the Way

According to Computerworld , the Accredited Standards Committee X9 is looking to create a new specification for encrypting cardholder data while it is in transit between systems during the transac... More >

Internet Threats Rise in April Thanks to Phishing

According to managed security vendor Network Box, Web-based threats jumped by two-thirds in April.   vnunet.com reports that phishing attacks were the main contributor to the 63 percent rise i... More >

Twitter Admin Account Breached

The Register reports that screenshots posted on French blog Korben indicate that Twitter's administrative account has been breached . The account belongs to Jason Goldman , a product manager at ... More >

Facebook Gets Security Help from MarkMonitor

According to eWEEK , Facebook is supplementing its own in-house security efforts with MarkMonitor’s AntiFraud Solutions .   MarkMonitor’s chief marketing officer Frederick Felman says,   ... More >

Maryland Hoping to Become Cyber Security Hub

Looking to position Maryland as a hub for cyber security, Governor Martin O’Malley has unveiled the Maryland Security Technology Initiative .   The Baltimore Business Journal reports that the ... More >