Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

Previous Next

Security

July 2009

July 31, 2009

Apple to Release Patch for iPhone Flaw

UK-based network operator O2 says Apple may issue a patch for the iPhone's SMS vulnerability as early as this weekend, reports InformationWeek . However, it's not clear if the patch will only be f... More >

Adobe Update Fixes 12 Vulnerabilities

Adobe has patched 12 vulnerabilities in its Flash player, reports Computerworld .   Adobe kept true to its word that it would patch all versions of Flash by July 30 . In addition to patching ... More >

Hacker McKinnon Loses Last Extradition Appeal

British hacker Gary McKinnon has lost his three battles to avoid extradition to the U.S., reports Reuters .   McKinnon is accused of hacking 97 U.S. military computer systems in 2001 and 20... More >

July 30, 2009

New Mac Attack Unveiled at Black Hat

Researcher Dino Dai Zovi has unveiled a new Mac attack that allows hackers to gain control of OS X machines and steal data from them that is supposed to be encrypted, reports DailyTech .   Ac... More >

PandaLabs: Rogue Anti-Virus Software to Explode in 2009

A report from Panda Labs has some surprising information about fake anti-virus software.   NetworkWorld reports that PandaLabs found more fake anti-virus software in the first half of 2009 th... More >

Clampi Trojan Stealing 'Tremendous' Amount of Financial Info

Botnet researcher Joe Stewart calls Clampi "the most professional thieving pieces of malware" he's ever seen. According to Stewart, the Clampi Trojan horse is stealing a "tremendous" amount of fina... More >

Security Experts Hacked on Eve of Black Hat

According to CNET News , the Web sites of several security experts and groups were hacked , and their passwords, e-mails, IM chats and other information were posted on the Internet. Among the victi... More >

Black Hat Researchers Unveil Serious SSL Flaws

Security researchers at the Black Hat conference unveiled some serious flaws in software that uses the SSL encryption protocol, reports PCWorld .   One researcher calling himself Moxie Marlin... More >

July 29, 2009

McAfee Exposes Conference Attendee Info

According to NetworkWorld , McAfee has accidentally sent the contact details of 1408 conference attendees in a thank you message attachment. The spreadsheet attachment contains the names, numbers,... More >

Symantec: Spam Learning New Languages

According to the MessageLabs Intelligence Report on spam from Symantec, spam is growing across the globe thanks to automated translation services and templates. internetnews.com reports that loca... More >

Cybercriminals Use Google to Target Malware

According to the August threat forecast from MX Logic, spammers and scammers are increasingly using Google to identify topics to determine new social engineering tactics, reports InformationWeek .... More >

Researchers to Detail SMS, MMS Spoofing at Black Hat

Researchers Zane Lackey and Luis Miras plan to show how they were able to spoof SMS and MMS messages and falsify the signaling data that underlies these messages at this week's Black Hat conference... More >

Verizon Offers ActiveX Control Testing

Following Microsoft's emergency security update to its Active Template Libraries, Verizon Business is offering a free scanning service to help software developers determine if any controls and comp... More >

Typo Responsible for Internet Explorer Exploits

Computerworld reports that Microsoft has confirmed that an errant "&" character is responsible for the bug that has let hackers exploit Internet Explorer since early July. Michael Howard, a pr... More >

Twitter Warning of TwitViewer Phishing Scam

Twitter is warning users of a possible phishing scam.   According to ITWorld , users are apparently giving their login credentials and passwords to TwitViewer , a Twitter service that promises... More >

July 28, 2009

Researcher to Discuss Smart Meter Security Risks

The Black Hat conference is reviving the debate over the security of the smart grid .   According to internetnews.com , IOactive security researcher Mike Davis is set to deliver a talk about w... More >

IT Execs Worry Shrinking Budgets to Impact Security

According to a survey from the RSA conference, 57 percent of IT managers expect their top cyber security challenge in the next year to be "budgetary constraints."   InformationWeek reports tha... More >

July 27, 2009

Microsoft to Present Security Tools, Info at Black Hat

According to InformationWeek , Microsoft plans to provide an update on security initiatives it launched last summer, as well as release new security tools and information , at this year's Black Hat... More >

Researchers: Security Certificate Warnings Don't Work

According to researchers at Carnegie Mellon University, between 55 percent and 100 percent of Web surfers ignore certificate security warnings , depending on which browser they are using. For exampl... More >

Data Loss Prevention Assessments from Nebulas

A new service designed to give organizations greater insight into their risk of data leakage has been launched by Nebulas Solutions Group.   V3.co.uk reports that the Data Loss Prevention Asse... More >

Microsoft to Release Two Out-of-Band Security Bulletins

According to V3.co.uk , Microsoft plans to release two emergency patches to address flaws in Internet Explorer and Visual Studio that could allow remote code execution.   The security adviso... More >

Network Solutions Suffers Data Breach

Web hosting firm Network Solutions is warning approximately 573,928 cardholders that their transaction data may have been compromised, reports V3.co.uk .   In a statement, the firm admits tha... More >

July 24, 2009

iPhone Encryption 'Entirely Useless,' Says Researcher

Researcher Jonathan Zdziarski calls the iPhone's encryption "entirely useless." Zdziarski recently demonstrated for Wired how he could copy and decrypt secured information from an iPhone.   ... More >

DNS Still Vulnerable After a Year

It's been a year since researcher Dan Kaminsky uncovered the DNS flaw. However, according to The New York Times , the DNS is just as vulnerable as ever to cache-poisoning attacks.   The pro... More >

Microsoft Boosts Security in Office 2010

Microsoft has had a heck of a time keeping Office secure as exemplified by a recent patch for Publisher 2007 . But the company hopes to change that with Office 2010.   Computerworld reports th... More >

July 23, 2009

New Tool Makes It Easy to Hack Oracle Database

With the help of a controversial open source software project known as Metasploit, security experts have created a new tool for breaking into Oracle's database .   Reuters reports that the eas... More >

2009 Set to Break Malware Records, Says McAfee

According to McAfee, 2009 may break all records for new malware samples. V3.co.uk reports that the security firm has seen more than 1.2 million new malware samples pop up over the first six months... More >

Adobe Working to Fix Flash Vulnerability

Adobe says it is looking into a potential vulnerability in Adobe Reader and Acrobat 9.1.2, and Adobe Flash Player 9 and 10, that is being exploited in the wild. According to CNET News , attackers ar... More >

July 22, 2009

Malware Purveyors Using Erin Andrews to Dupe Users

According to internetnews.com , a virus in the guise of a racey video of ESPN reporter Erin Andrews is infecting both Mac and Windows users. The video does actually exist, but Andrews has taken le... More >

Researchers Find Way Around SSL Protection

Security researchers Mike Zusman and Alex Sotirov have discovered a flaw in the design of Web browsers that permits an attacker to conduct a "Man-in-the-Middle" attack against Web sites with Extend... More >

Firefox Upgrades 3.0.x Versions

Mozilla has released an update for those users still still running 3.0.x versions of Firefox.   According to The Register , Firefox 3.0.12 fixes several security and performance bugs in the o... More >

Group Addresses Software Supply Chain Attacks

The Software Assurance Forum for Excellence in Code (SafeCode) is offering the Software Supply Chain Integrity Framework to help suppliers prevent software from being deliberately compromised durin... More >

Sophos: Time for Social Networks to Grow Up

With nearly a quarter of organizations having been exposed to spam, phishing or malware attacks through sites such as Twitter , Facebook, LinkedIn and MySpace, the time has come, says Sophos, for so... More >

July 21, 2009

Mozilla Holds Crash Bug Triage Day

According to ITWorld , Mozilla is holding a " crash bug triage day " today. Anyone interested in helping to classify open crash bugs in Firefox is invited to participate.   Usually, when a bug ... More >

Innovation: This Message Will Self-Destruct

A group of computer scientists at the University of Washington have developed a security technology that seems straight out of the movies.   According to The New York Times , the researchers ha... More >

Adobe Offers Out-of-Date Reader, Warns Secunia

Secunia is warning that Adobe offers an out-of-date version of Reader to users who download the application from its Web site.   According to Computerworld , when users download the "latest" ... More >

Mozilla Dismisses Firefox Bug

Just days before Mozilla released Firefox 3.5.1 to address a "highly critical" vulnerability, security researchers reported a separate stack-based buffer overflow vulnerability , according to Sof... More >

July 20, 2009

New Twist on Nigerian E-Mail Scam

Sophos says a new version of the infamous Nigerian e-mail scam is making its way around the Internet.   According to ITWorld , like the old versions, the new version claims to come from an Af... More >

How the Twitter Hack Was Done

The hacker who stole confidential Twitter documents was able to do so through a combination of poor password practices , Hotmail's inactive account feature and personal information on the Web, acc... More >

McAfee Gives SaaS Security Platform a Boost

V3.co.uk reports the McAfee is beefing up its Web-based security offerings in order to keep up with the soaring demand for such services. New features include Web filtering, vulnerability scanning... More >

Sophos: U.S. Top Spam Sender

According to Sophos, the U.S. is responsible for 15.6 percent of all junk mail , beating out Brazil for the top spot, reports V3.co.uk . While the U.S. may be the worst country, the Sophos report f... More >

July 17, 2009

Mozilla Fixes 'Highly Critical' Vulnerability

Mozilla has released Firefox version 3.5.1 to close a "highly critical" vulnerability in the browser's JavaScript engine, reports CNET News . Originally slated to be released later in the month, M... More >

Elance Suffers Security Breach

According to a TechCrunch.com article in The Washington Post, development-outsourcing site Elance has suffered a security breach . Elance's security alert site notes that: "hackers discovered a ... More >

July 16, 2009

Malaysia's Ministry of Foreign Affairs Site Hacked

The Web site of Malaysia's Ministry of Foreign Affairs may have given recent visitors more than just Malaysian foreign policy. According to ITWorld , an attacker compromised the site and redirected ... More >

Mobile Malware Can Send, Receive Info

Sexy View, a piece of mobile malware that targets devices running the Symbian S60 OS, is significant because it is the first known malware that spreads by SMS , reports NetworkWorld .   Trend ... More >

Survey Shows Execs Differ on Security Risks

A study by the Ponemon Institute shows that CEOs underestimate the security risks faced by their organizations compared to other C-level executives. Computerworld reports that 45 percent of CEOs b... More >

Twitter Hack Exposes Internal Documents

A recent hack of micro-blogging service Twitter has resulted in the exposure a number of internal documents , reports the San Francisco Chronicle . Executive meeting notes, partner agreements and f... More >

July 15, 2009

Researchers Warn of Potential Keyboard Vulnerability

Poor shielding on some keyboard cables could allow hackers to identify each typed computer character , according to experts from the security firm Inverse Path.   Telegraph.co.uk reports that ... More >

Utah School District Warns of Missing Thumb Drive

The Salt Lake Tribune reports that Canyons School District officials are looking for a missing USB drive that likely contains the personal information of more than 6,000 current and recent employe... More >

Survey: Consumers Reinforce Incentives for Spammers

A survey sponsored by the Messaging Anti-Abuse Working Group indicates that one in six consumers have at some time acted on a spam message , reports Computerworld . This kind of response rate reinf... More >

'Highly Critical' Firefox Vulnerability in the Wild

According to InformationWeek , a "highly critical" vulnerability in the new Firefox 3.5 browser that could allow a remote attacker to execute malicious code is likely being exploited in the wild. ... More >

Nine Vulnerabilities Fixed in July Patch Tuesday

Microsoft's July Patch Tuesday cycle included six security bulletins that address nine vulnerabilities , reports InformationWeek .   As expected , two critical bulletins fixed vulnerabilities ... More >

July 14, 2009

10 Database Fixes Among Oracle Patches

Oracle's quarterly security update includes 10 security patches for its database and also other fixes, reports Computerworld .   Affected database components for three issues include advanced... More >

Attacks Originated in the UK?

A Vietnamese computer security analyst believes the attacks against popular Web sites in the United States and South Korea originated in the UK , reports Computerworld .   U.S. and South Kore... More >

HTC Bluetooth Vulnerability Surfaces

HTC, which has recently made headlines with its Android handsets, is now making news with its devices that run on either Windows Mobile 6 or Windows Mobile 6.1. A vulnerability in an HTC driver insta... More >

Check Point Updates Endpoint Security Platform

Check Point has launched a new version of its endpoint security tool, reports V3.co.uk .   Endpoint Security R72 features WebCheck, which protects enterprise endpoints from Web based threats. ... More >

July 13, 2009

Ponemon Institute: 85 Percent of Businesses Breached

The Ponemon Institute's fourth annual U.S. Encryption Trends Study found that 85 percent of businesses have suffered a data breach in the past year, reports internetnews.com . Lack of encryption s... More >

Microsoft Tackles Browser Security with Gazelle

A Microsoft Research project called Gazelle is looking at ways to protect browsers from malicious or unstable code delivered via plug-ins, ads, and other content whose origin may be unknown, reports... More >

Koobface Worm Resurfaces in Twitter

The Koobface worm has made its way to Twitter, reports DigitalTrends . At least a couple hundred accounts have been infected, according to PCWorld . As a result, Twitter has suspended the accoun... More >

July 10, 2009

Korea DDoS Virus to Shift from Attack to Destroy

Security specialist AhnLab believes that the virus that has been used to launch the DDoS attacks in South Korea will go from attack mode to destroy. Computerworld reports that the virus has been ... More >

Text Scammers Targeting Regional Banks

Computerworld says the next big thing in phishing is scam text messages that prey on small regional banks and their customers.   The scam works this way: Criminals pick a bank and then send b... More >

Six Bulletins for July Patch Tuesday

According to TG Daily , the July Patch Tuesday , scheduled for July 14, will offer six patches, including three critical updates that affect Windows. The rest are considered "important" and affect ... More >

July 9, 2009

IBM Seeks Patents for Data Masking Technology

IBM is hoping to get two patents for its Masking Gateway for Enterprises (aka MAGEN) technology, which can selectively hide data contained in files that hold sensitive information, reports Informa... More >

Security Concerns Sparked by Google Chrome OS

A recent post on the Official Google Blog has caused concern for some security experts. The post reads: "... we are going back to the basics and completely redesigning the underlying security archite... More >

AhnLab: Attacks on South Korean Web Sites to Resume

According to Computerworld , AhnLab believes the denial of service attacks on South Korean Web sites will resume this evening. This time the attacks will be directed at a smaller number of sites t... More >

McAfee Warns of Mac Malware Attack

There's a new attack targeting Mac OS X systems, warns McAfee.   V3.co.uk reports that a Trojan, informally known as "Puper," disguises itself as MacCinema , a video program for OS X systems. ... More >

July 8, 2009

MyDoom Behind U.S., South Korea Site Attacks

According to Korean computer security company AhnLab, an updated version of the MyDoom virus is to blame for the widespread attack on U.S. and South Korean government Web sites, reports Computerwo... More >

North Korea Behind Government Web Site Attacks?

BBC News reports that several U.S. government Web sites have been hit by a computer attack that began on July 4. Among the affected agencies are the U.S. Treasury Department, Secret Service, Fede... More >

July 7, 2009

VirusScan Update Brings Systems Down

A recent McAfee VirusScan update caused havoc for IT administrators across the globe when it falsely reported that a number of critical system files were infected with a Trojan, reports V3.co.uk .... More >

Microsoft Warns of ActiveX Vulnerability

CNET News reports that Microsoft is warning of a vulnerability in its Video ActiveX Control that could let an attacker take control of a PC if the user visits a malicious Web site. The bug affects... More >

July 6, 2009

Adobe to Patch ColdFusion Bug Next Week

According to InfoWorld , Adobe says it will have a patch for its ColdFusion Web development software ready next week. A problem in the FCKEditor rich text editor could allow a system to be hacked.... More >

iPhone 3G Gets Jailbroken, Unlocked

Proving that the iPhone's security features aren't impenetrable, teen hacker Geroge Hotz says he's created an app that can “jailbreak” the iPhone 3G S , reports VentureBeat . The program allows una... More >

July 2, 2009

KnownSec Opens up Malware Database

Beijing-based KnownSec is opening up its massive database of malware found on Chinese Web sites to security companies and national computer emergency response teams. According to Computerworld , t... More >

Apple Working on Patch for iPhone SMS Vulnerability

Apple is working on a patch for an iPhone vulnerability discovered by security researcher Charlie Miller. According to NetworkWorld , a bug in the way iPhones handle text messages received via SMS... More >

Texas Man Arrested for Hacking Clinic Computers

Jesse William McGraw , a.k.a GhostExodus, has been arrested on a charge of felony computer intrusion for installing malware in computers at the Carrell Clinic in Dallas, Texas. According to Comput... More >

July 1, 2009

New Trojan Variant Stealing FTP Credentials

A new variant of the Zeus family of Trojans has surfaced and is harvesting FTP account information from compromised computers, reports InformationWeek .   Security vendor Prevx considers the ... More >

ATM Security Talk Canceled

Juniper Networks has pulled an ATM security talk by one of its researchers scheduled to speak at the Black Hat conference.   According to PCWorld , staff Security Researcher Barnaby Jack was s... More >

Pennsylvania Man Arrested for 'Rolling Stone' DDoS Attacks

According to Computerworld , Bruce Raisley has been arrested for allegedly launching distributed denial-of-service attacks against nine Web sites, including Rolling Stone magazine's site.  ... More >

Hacker Max Bulter Pleads Guilty

Max Ray Butler , aka "Iceman," "Digits," "Darkest" and "Aphex," has pleaded guilty to breaking into several financial institutions and card-processing networks and stealing credit card and identity i... More >