Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

Previous Next

Security

June 2009

June 30, 2009

Botnets Behind Most Spam, Says MessageLabs

internentnews.com reports that, according to a report by Symantec's MessageLabs unit, botnets account for 83.2 percent of all spam . While the McColo shutdown severely affected the Srizbi botnet,... More >

Solid Oak Believes China Behind Cyber Attack

InformationWeek reports that Solid Oak Software has asked the FBI to investigate a cyber attack on the company that seems to have come from China. A Microsoft representative investigated suspiciou... More >

Blind Hacker Sentenced to 11 Years

According to PCWorld , Matthew Weigman , a blind Boston-area teenager, has been sentenced to more than 11 years in prison for hacking into the telephone network and harassing the Verizon investigat... More >

June 29, 2009

Spam Targeting Fawcett, Jackson Deaths

The U.S. Computer Emergency Response Team is warning about s pam and malicious e-mail attacks exploiting the deaths of actress Farrah Fawcett and singer Michael Jackson, reports V3.co.uk . In fact... More >

Secunia: Average PC User Has Dozen Unpatched Apps

According to Secunia, the average PC user has a dozen insecure applications installed. InformationWeek reports that PC users install about 80 applications and 15 percent of those are not up to da... More >

June 26, 2009

IBM Researcher Comes up With Encryption Breakthrough

IBM researcher Craig Gentry claims to have come up with a way for computer systems to perform calculations on encrypted data without decrypting it , reports Forbes .   So-called "fully homomor... More >

Adobe Patches Critical Flaw in Shockwave

Adobe has released an update to address a critical flaw in the Shockwave Player , reports PCMag.com . There's not much detail about the vulnerability in the advisory , but it's clear that the flaw... More >

June 25, 2009

Northrop Grumman Data Found in Ghana

A team of journalists doing an investigation for the Public Broadcasting Service show Frontline uncovered a hard drive in a Ghana market that contained sensitive documents belonging to U.S. governm... More >

Cisco Adds DLP to Network Security Arsenal

Thanks to a partnership with EMC's RSA security division, Cisco plans to integrate data loss prevention technology into some of its IronPort e-mail security appliances by the fall, reports eWEEK .... More >

Audit Finds Minnesota Retirement System at Risk

Although no hackers have broken into its computer systems, an audit found that the Minnesota State Retirement System lacks adequate controls to protect its systems from external threats, according ... More >

Early Tests Bode Well for Microsoft Security Essentials

Microsoft's free anti-virus software, Microsoft Security Essentials, has performed well in early tests , according to PCWorld . AV-Test challenged the product with its "WildList" collection of 3,19... More >

June 24, 2009

Survey: IT Pros Fail to Secure Smartphones

According to a survey by Credant Technologies, more than a third of IT professionals say they do not use a password on their work or personal smartphones, reports PC Pro . ComputerWeekly notes th... More >

IBM Upgrades Tivoli Identity Manager

ZDNet reports that IBM has upgraded its Tivoli Identity Manager to allow companies to   “administer, secure, monitor and certify user identities and their access to applications, information ... More >

Clear Service Closure Has Customers Concerned About Data

The abrupt closure of Verified Identity Pass Inc.'s airport fast-lane program has many customers concerned, according to Computerwold . Clear service collected detailed personal information, inclu... More >

Google Patches Critical Flaw in Chrome

PCWorld reports that Google has patched a critical vulnerability in its Chrome browser .   Version 2.0.172.33 fixes a flaw that could allow a hacker carry out a buffer overflow attack, accordi... More >

Cornell Security Breach Leaves 45,000 at Risk

A stolen university-owned computer has put over 45,000 current and former staff and students of Cornell University at risk of identity theft, reports The Cornell Daily Sun . The computer contained... More >

TJX Reaches Settlement with 41 States

According to Reuters , TJX Cos. Inc. has reached a settlement with 41 states that will cost the retailer $9.75 million, including $2.5 million to set up a new Data Security Fund to be used by the ... More >

June 23, 2009

Finjan Scans Twitter Links for Free

Finjan is offering a free browser add-on that scans Twitter links and warns if they point to a page containing malware.   According to ITWorld , SecureTwitter is part of SecureBrowsing, a plu... More >

Most of Spam Coming from China, Research Shows

According to Gary Warner, director of research in computer forensics at the University of Alabama at Birmingham, most of spam seems to be coming from China .   InformationWeek reports Warner's... More >

Symantec: Attacks of Unpatched Windows Bug to Increase

Symantec warns that a still-unpatched vulnerability in Microsoft Windows XP and Server 2003 that has been added to at least one Web-based attack kit means attacks will increase soon, reports Compu... More >

Microsoft Capping Security Essentials Downloads

According to SC Magazine , Microsoft is capping downloads of Microsoft Security Essentials, its new anti-virus product, at 75,000 . Downloads are available on a new dedicated Security Essentials si... More >

June 22, 2009

Researcher Focuses on Security Threat of Parking Meters

Parking meters a security risk ? Yes, says security researcher Joe Grand, who will be delivering a session at the upcoming Black Hat security conference, reports internetnews.com . "Why parking mete... More >

Security Software Market Defies Down Economy

New research from Gartner shows that the global security software market grew by over 18 percent in 2008 to reach $11.3 billion in worldwide revenues despite the economic gloom, reports V3.co.uk .... More >

'Nine Ball' Attack Greatly Exaggerated, Says ScanSafe

According to ScanSafe, reports that the so-called "nine ball" attack compromised over 40,000 legitimate Web sites is greatly exaggerated. V3.co.uk reports that ScanSafe believes the number of req... More >

June 19, 2009

When It Comes to Security, Men Less Savvy

According to research from PC Tools, men are not as security savvy as women .   ITWorld reports that 47 percent of men use the same passwords, compared to just 26 percent of women. Sixty perce... More >

New Twitter Attack Via E-Mail Attachment

Symantec is warning about a new Twitter attack that poses as an invitation to join Twitter with the message: 'Your friend has invited you to Twitter.'   However, according to vnunet.com , the... More >

Microsoft Security Essentials Coming June 23

According to InformationWeek , Microsoft has confirmed that Microsoft Security Essentials (aka Morro) will be available on Tuesday, June 23 , at about 9 a.m. Pacific. The Register notes that init... More >

June 18, 2009

Juniper, Kaspersky Team Up to Secure Network

Kaspersky Lab is teaming up with Juniper Networks to put malicious software protection in Juniper's SRX Series Services Gateways and J Series Services Routers, reports vnunet.com .   Petr Merk... More >

Heartland CEO Calls Breach 'Devastating'

Heartland Payment Systems CEO Robert Carr calls the data breach that rocked the payment processor "devastating." Since the incident, the company has been working overtime to repair the damage. &nbs... More >

iPhone 3.0 Patches 45 Flaws

According to The Inquirer , the iPhone 3.0 operating system contains 45 software patches .   Telegraph.co.uk reports that some of the issues addressed in the update include vulnerabilities i... More >

June 17, 2009

Morro's Real Name Will Be Microsoft Security Essentials

Details about Microsoft's OneCare replacement, codenamed Morro, have been leaked. According to ZDNet blogger Mary Jo Foley, the final alleged name of the product will be Microsoft Security Essenti... More >

Nine Ball Attack Hits Thousands of Web Sites

According to WebSense, a mass-compromise attack called Nine Ball has hit more than 40,000 Web sites. ITWorld reports that the attack injects malware into pages in order to redirect victims to a s... More >

Google Urged to Make Gmail More Secure

According to vnunet.com , a group of 38 computer scientists, law professors and security experts sent an open letter to Google CEO Eric Schmitt u rging Google to make Gmail more secure by making H... More >

Security Firm Discovers 'eBay for Stolen Data'

Security firm Finjan has discovered a fully functional marketplace for the building and selling of botnets , according to vnunet.com . Criminals can get everything from malware and data to the netw... More >

Hacker Hijacks Cligs URL Shortening Service

Cligs, a URL-shortening service, was hacked over the weekend, sending millions of Twitter users to Kevin Saban's blog, reports Computerworld .   As there doesn't appear to be any profit motive... More >

June 16, 2009

Beware of Calls for Iranian Proxy Servers

With cell-phone text messaging and social networking sites being blocked by the government, many Iranians upset over the results of recent elections are turning to proxy servers , reports FOXNews .... More >

Former Google Employees Launch Web Anti-Malware Service

According to InformationWeek , a couple of former Google employees have gotten together to create a Web security startup called Dasient .   Neil Daswani, Shariq Rizvi and Ameet Ranadive from M... More >

Twitter to Face Month of Bugs

Come July, Twitter users better hold on to their hats. According to InformationWeek , Israeli security researcher Aviv Raff plans to launch a " Month of Twitter Bugs " in an effort to raise awarenes... More >

Activists Shut Down Key Iranian Web Sites

Angry over the results of the recent Iranian elections, activists have launched a cyber protest that has knocked sites belonging to Iranian news agencies, President Mahmoud Ahmadinejad and Iran's s... More >

Apple Finally Patches Java Flaw

According to InformationWeek , Apple has finally fixed a Java flaw that could allow an attacker to to execute malicious code on affected Macs. The patch summary states that: "Java for Mac OS X 1... More >

June 15, 2009

Users Still Getting Duped by Phishing Sites, Report Shows

internentnews.com reports that according to a report from VeriSign, a whopping 88 percent of Web users in the U.S. can't identify phishing sites . However, blogger Sean Michael Kerner notes that th... More >

Lawmaker Concerned over Power Grid Vulnerability

According to a Reuters article on InformationWeek, fears over the vulnerability of the power grid keep Rep. Jim Langevin up at night. Langevin says a cyberattack could wipe out a whole section of... More >

Facebook Spammer Could Face Jail Time

Alleged Facebook Spammer Sanford Wallace could be looking at jail time for violating a restraining order , reports Computerworld . District Judge Jeremy Fogel has referred Wallace to the U.S. Attor... More >

June 12, 2009

McAfee Sees Growth in Botnets

Following the shutdown of McColo , cyber criminals have been working hard to rebuild.   vnunet.com reports that according to McAfee's Avert Labs, the first quarter of 2009 saw 12 million new ... More >

Firefox 3.0.11 Fixes Nine Security Bugs

According to internetnews.com , Mozilla's Firefox 3.0.11 release addresses nine different security vulnerabilities, including four that are rated as critical.   One critical fix deals with a ... More >

June 11, 2009

Video Spam Becoming More Widespread

VideoSurf CTO Eitan Sharon estimates that nearly 20 percent of online videos can be considered spam.   According to a GigaOm article in The New York Times, video spam would include videos th... More >

IT Staff Admit to Getting Around Security Controls

Controls designed to protect sensitive information aren't quite cutting it. A study by data security firm Cyber-Ark shows that 74 percent of IT staff said it was possible "get around" such protection... More >

Employees Ingnoring Security Policies, Survey Shows

PCWorld reports that a survey by Ponemon Institute shows that employees are ignoring security policies and doing things that could put a company at risk.   According to the survey, 69 percent... More >

New Malware Targets Apple Users

Sophos is warning of two new pieces of malware aimed at Apple users .   vnunet.com reports that Sophos believes a worm known as Tored-Fam is being used to build a Mac botnet known as Raedbot. ... More >

Microsoft Prepping Free Anti-Virus Software

First announced last year , Microsoft is now preparing to launch a public beta version of its new free security software product, codenamed Morro , reports Reuters .   According to the company... More >

June 10, 2009

Adobe Patches 13 Flaws in Reader, Acrobat

In its first round of regular security updates, Adobe has patched 13 critical vulnerabilities in its Reader and Acrobat software, according to IT Pro .   Adobe Reader 9.1.1 and Acrobat 9.1.1 ... More >

Former Hacker Tapped as Security Advisor

Much to his surprise, well-known hacker Jeff Moss , aka "Dark Tangent," has been named to the Department of Homeland Security's Advisory Council, reports Fox News . Moss is perhaps best known as th... More >

Takedown of 3FN Drops Spam 15 Percent

The court-ordered takedown of 3FN, an ISP operated by Belize-based Pricewert, dropped spam levels by 15 percent , according to security firm Marshal8e6. Two big-name botnets, Pushdo and Mega-D, were... More >

T-Mobile Says Info Genuine, But Servers Not Hacked

T-Mobile isn't denying that the the data posted on the security forum Full Disclosure is genuine, but it claims that the information comes from a stolen document , not a full-scale breach of its ser... More >

New Safari Patches Number of Holes

Apple's Safari 4.0 release also included 51 vulnerability fixes for issues in both the Mac and Windows versions.   According to Heise Online , the new version addresses vulnerabilities in t... More >

Open Source Project Opens up New Attack, Warns Symantec

Symantec is warning of a new attack aimed at users of wireless keyboards .   According to vnunet.com , "The warning follows the release of Keykeriki, an open-source 'sniffer' project that allo... More >

Huge Patch Batch from Microsoft

Microsoft's June Patch Tuesday addressed a whopping 31 vulnerabilities packaged into 10 bulletins, reports The Register .   As we reported last week , the patches correct bugs in Windows, Of... More >

June 9, 2009

T-Mobile Says Breach is Legit

T-Mobile now says the claim that its systems have been breached is legitimate , though it's not clear whether the hackers have access to everything as they claim, reports CSO .   The story q... More >

June 8, 2009

T-Mobile Investigating Possible Breach

Over the weekend, T-Mobile began investigating a reported breach of its network by unnamed hackers. A posting on a security site called Full Disclosure claimed that the company's customer data, logs,... More >

June 5, 2009

Virginia Commonwealth University Informs Students of Stolen Data

More than 17,000 former and current students of Virginia Commonwealth University were informed that their personal information may have been breached after a computer was stolen from a university lib... More >

Patch Tuesday to Fix Six Critical Vulnerabilities; Adobe to Begin Releases

On June 9, Microsoft's Patch Tuesday will bring six patches for critical vulnerabilities in Windows, Internet Explorer, Word, Excel and Office. Microsoft will also release an update to the Microsoft ... More >

June 4, 2009

.ORG Gets Secured

The .org domain is now protected against DNS hijacking, thanks to being signed with DNSSEC (DNS Security Extensions), reports internetnews.com .   The effort involved millions of dollars, say... More >

Cyber Security Role Staying with Homeland Security

Even with the upcoming appointment of a cyber security coordinator, Rand Beers, the nominee for undersecretary of the Department of Homeland Security for the National Protection and Programs Direct... More >

Trustwave Warns of Malware on ATMs

Security vendor Trustwave is warning that cybercriminals have refined a malicious software program that can c apture sensitive card details on ATMs running Microsoft's Windows XP, reports NetworkW... More >

Trojan Uses Video Link to Dupe Twitter Users

Another day, another Twitter attack, it seems.   This time users are being infected by a rogue anti-virus download that is spreading in the form of posts from hijacked user accounts, according... More >

Pelosi Calls for Probe into Nuclear Info Leak

House Speaker Nancy Pelosi is asking the U.S. Government Accountability Office to look into how a list of nuclear sites was accidentally posted on the Internet, reports TG Daily .   Yesterday ... More >

June 3, 2009

Colleges Earn C+ for Network Security, Survey Shows

According to a survey by the Association for Information Communications Technology Professionals in Higher Education, most colleges score the security of their networks an average of 3.7 out of 5. ... More >

Security Breach Exposes Sensitive Nuclear Site Info

An inadvertent security breach resulted in sensitive details about hundreds of civilian nuclear sites across the country being posted online.   The Washington Post reports that a draft declar... More >

Phishing Attempt Asks for Server Info, Warns Trend Micro

Trend Micro is warning of a new kind of phishing attack targeted at Microsoft Outlook users in which the user is asked to disclose their e-mail server and account information.   According to ... More >

Batteries.com, Aviva Report Security Breaches

Computerworld reports that both Batteries.com and Aviva USA , one of the largest insurance companies in the world, have suffered data breaches.   Batteries.com reports that 865 residents of Ne... More >

June 2, 2009

Sophos Combines Encryption, Antimalware in Windows Desktop Suite

Utilizing its acquisition late last year of Utimaco, Sophos has unveiled the Endpoint Security and Data Protection suite , a software suite for Windows desktops that combines full-disk encryption wi... More >

Thousands of Web Sites Hacked, Warns Websense

Websense is warning that up to 40,000 Web sites have been hacked to redirect users to another Web site that attempts to infect PCs with malicious software.   According to NetworkWorld , the s... More >

VPN Breach Highlights Security Challenges

internetnews.com reports that a former employee of Energy Future Holdings was able to log on to the corporate VPN and cause $26,000 in damages from lost business. The company has declined to comme... More >

Security Group Suggests 'Report Abuse' Button for Web Sites

The Information Security Awareness Forum is calling for a "report abuse" button on Web sites aimed at consumers as a way to alert companies to security problems, reports vnunet.com . At the very l... More >

Apple Patches 10 Bugs in QuickTime

Apple has patched 10 critical vulnerabilities in QuickTime that allow "arbitrary code execution," reports Computerworld .   All 10 bugs patched by QuickTime 7.6.2 involve some sort of file fo... More >

June 1, 2009

Cyberspace Policy Review Calls for Identity Management

The recently released report by the Obama administration that details the findings of a 60-day review of national cyber security policy and practice offers many recommendations for securing the nat... More >

LifeLock Cannot Set Fraud Alerts, Rules Court

Experian, one of the three main credit-reporting agencies, is suing ID-theft prevention service LifeLock, alleging that LifeLock's automatic renewal of customers' fraud alerts costs Experian millions... More >

Experts Warn of Hacking Threat Via Text Message

Security experts are warning mobile phones users of an attack in which would-be hackers access confidential information via a simple text message that appears to come from the service provider, acc... More >

Lessons from Royal Air Force Security Breach

More than 500 Royal Air Force staff are at risk of blackmail following the theft of three computer hard drives, according to Telegraph.co.uk . The devices contained highly sensitive information on ... More >

U.S. Networks 'Not Secure,' Says Cyber Security Review

Dovetailing with the president's announcement of the creation of a cyber security czar was the release of a report that covers the findings of a 60-day review of national cyber security policy and ... More >