Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

Previous Next

Security

September 2009

September 30, 2009

Survey Shows Security Audits Worthwhile But Infrequent

A study conducted by VanDyke Software and independent researcher Amplitude Research shows that while companies feel that securing data networks is important enough to hire outside audit firms, only ... More >

Two Romanians Face Phishing Charges in U.S.

Two Romanians are facing charges in the United States in connection with a massive phishing scam , reports Computerworld . Petru Belbita and Cornel Tonita allegedly set up fake phishing sites to st... More >

September 29, 2009

New Framework to Allow Security Experts to Exchange Info

To improve interoperability of network defenses, a standard vocabulary and message exchange system soon will allow cyber security experts to exchange information on network-attack forensics and vuln... More >

Ant Behavior Inspires Security Experts

The behavior of ants is inspiring security experts to create a strategy for fighting worms, according to TG Daily .   in a concept known as swarm intelligence, "digital ants" wander through co... More >

New Attack Code Exploits Known Windows Bug

Harmony Security Senior Researcher Stephen Fewer has released a new attack code that exploits a critical bug in the Windows operating system that has been known since Sep. 7. According to InfoWorl... More >

Reddit Hit by Cross-Site Scripting Worm

A cross-site scripting worm pummeled social news service Reddit with malicious comments , reports internetnews.com . The worm originated from the account of a user going by the name "xssfinder." Re... More >

'iPhone MMS' Search Results Poisoned

According to Stephan Chenette, the manager of security research at Websense, the top six results for search phrases about iPhone and SMS are poisoned , using the results to steer users to fake Windo... More >

Virus Steals Money from Illinois School Districts

According to Computerworld , several Illinois school districts have been hit by computer intrusions that have resulted in hundreds of thousands of dollars being stolen. As much as $350,000 may h... More >

Microsoft Security Essentials Officially Available Today

V3.co.uk reports that Microsoft's Security Essentials is officially available today . The product offers free malware protection for users of Windows XP, Vista, and 7.   According to eWEEK , ... More >

September 28, 2009

Adobe, McAfee Form Partnership

Adobe and McAfee are joining forces to develop product that combines digital rights management capabilities with data-loss prevention technology, according to InfoWorld . The goal is to give custom... More >

North Carolina Mammography Study Breached

The University of North Carolina at Chapel Hill on Friday began notifying women that their Social Security numbers and other personal data could have been exposed in a breach, reports Computerworl... More >

September 25, 2009

Symantec Research Shows Idaho Gets More Spam Than Any Other State

According to CSOOnline , research performed by Symantec's MessageLabs group shows that in Idaho, 93.8 percent of the e-mail traffic sent to business users is spam-related. Symantec Senior Analyst Pa... More >

Study Shows 9 Percent of Enterprise Machines Are Bot Infected

A three-month study performed by Damballa uncovered 600 different types of botnets on enterprise networks, and of those, only 5 percent were from the more infamous botnets such as Koobface or Zeus/ZD... More >

September 24, 2009

Belfast Get New Cyber Security Research Center

Queen's University in Belfast has opened a new government- and industry-sponsored cyber security research center , reports The Register . The center will focus on embedded security technology for n... More >

Phony 'Monopoly' Invite Turns PC into Spam-Spewing Zombie

According to internetnews.com , McAfee's MX Logic security software team is warning that hackers are trying to snag unsuspecting users with an invitation to play an online game of Monopoly . Says S... More >

Cisco Patches 12 Router Vulnerabilities

Cisco has fixed 12 security flaws in its router firmware in its twice-yearly set of security patches, according to Computerworld .   The bugs affect routers and switches that use the Cisco Uni... More >

SafeScan Warns of Malicious Ads

According to SafeScan, criminals have placed malicious ads on networks managed by Google's DoubleClick, YieldManager and ValueClick's Fastclick network, causing popular Web sites like the Drudge Re... More >

Beware of 'Chat-in-the-Middle' Attacks, Warns RSA

According to V3.co.uk , RSA is warning of a new kind of phishing threat for online banking customers, which they are calling a "Chat-in-the-Middle" attack .   The attack begins as a routine ph... More >

Twitter Hit By A New Phishing Scam

It's hook claims to leave readers "ROFL," but the latest phishing scam aimed at Twitter users does nothing more than attempt to steal passwords and logon credentials, says CSO Online .   The ne... More >

Seagate Makes Self-Encryption Standard on Hard Drives

Seagate has rolled out new hard drives that feature self-encryption as standard , reports V3.co.uk .   Geared toward enterprises, the new Savvio, Constellation and Cheetah lines will now have ... More >

September 23, 2009

Survey: Most Small Companies Do Not Comply with PCI Standards

According to eWEEK , a study performed by the Ponemon Institute and Imperva revealed that although 70 percent of large companies comply with the Payment Card Industry (PCI) Data Security Standard, o... More >

DoD to Again Allow USB Devices to Be Used

Last year, the U.S. Department of Defense banned the use of USB devices after one was blamed for spreading a worm across its networks. According to Dark Reading , the DoD will soon allow USB devices... More >

Malicious Anti-Virus Sites Set to Scam Google Users

According to SC Magazine , hackers have found a way to attack high-ranking sites in the Google algorithm and embed links to malicious, fake anti-virus sites within results. Google users who click on... More >

September 22, 2009

Gartner: Security Spending to Grow This Year

According to Gartner, the worldwide software security market will continue to grow this year despite poor economic conditions.   The analyst firm predicts that the market will increase 8 perce... More >

Cisco Teams With Pelco to Develop IP Security Cameras

Cisco and Pelco have inked a joint development deal where the Pelco Sarix security cameras will be optimized to work with Cisco networking systems, and in turn, Cisco will co-brand the IP-based camer... More >

Microsoft Soon To Release Free Security Software

According to CSO Online , Microsoft alerted beta testers of its new free Security Essentials that their own copy would arrive "in the coming weeks." The company had offered the beta test software to... More >

Microsoft Issues Workaround for SMB Vulnerability

Microsoft has released a temporary fix for a critical vulnerability in the Server Message Block version 2 protocol, according to ChannelWeb . The bug could allow remote hackers to steal data from ... More >

September 21, 2009

Hacking Service Offers Access to Any Facebook Account, $100

A Ukraine-based hacking service claims that "Any Facebook account can be hacked," and for $100, it will provide you with the password and login I.D. to any account you request. Payments can be sent... More >

New Botnet Evades Filters, Causes Increased Click Fraud

A new botnet has emerged that is capable of avoiding detection by some of the more sophisticated filters on Web publishers, ad networks, and even search engines, says CSO Online . Click Forensics, a... More >

September 18, 2009

Defense Firms Diversify Business, Provide Cyber Security

According to Mass High Tech , defense firm Raytheon has been chosen to supply IT security systems for an Arizona-based solar project. Another defense contractor, BAE Systems, has been advertising it... More >

UAB to Create Cyber Crime Training Programs for Law Enforcement

A joint agreement has been signed among the National White Collar Crime Center, the Internet Crime Complaint Center, and the University of Alabama Birmingham (UAB) to develop cyber crime investigatio... More >

September 17, 2009

Microsoft Promotes Secure Software Development With New Free Tools

According to Dark Reading , Microsoft began promoting more secure, cleaner code development last year with its Security Development Lifecycle (SDL) initiative. It continues that strategy with more f... More >

Social Networking Could Prove to Be Tool for Secure Identity Management

Although social networking has been seen as the bane of IT security, when Luke Shepard, a Facebook platform engineer, spoke about how it could help create stronger identity and access management (I... More >

September 16, 2009

Hackers Exploit Celebrity Death News To Spread Malware

According to TG Daily , the latest trend in spreading computer viruses and malware is for hackers to take a huge celebrity news story, place it on a faux Web site laced with viruses and links to fak... More >

No Simple Way to Control Online Identity Theft

Recent news stories about crime rings performing identity theft on a massive scale have many consumers fearing online transactions. CSO reports that sometimes the criminals start the jobs from ins... More >

September 15, 2009

Xirrus Rolls Out New Wireless Security Option

According to SocalTECH.com , Xirrus has rolled out a new product to increase security options for its wireless array systems. Its new RF Security manager provides hardware encryption and security sc... More >

New York Times Web Site Infected by Malicious Banner Ad

According to Bit-tech.net , the New York Times Web site has been infected by an “unauthorized” banner ad that sent out pop-ups alerting readers of a virus and then instructing them to download fake ... More >

SANS Institute Finds Most Vulnerabilities Involve Client and Web Apps

A report released by the SANS Institute has found that the greatest security risks are found in vulnerabilities to client and Web applications, but most organizations spend the least amount of time s... More >

September 14, 2009

Redspin Finds Most Companies Fail Social Engineering Assessment

HPCwire reports that information security assessment firm Redspin, Inc., found 94 percent of the companies it had tested for social engineering attacks had at least one employee who failed the e-mai... More >

Windows 7 Proves More Secure Than Previous Windows Versions

Despite recent reports of bugs that affect Windows 7, the operating system may prove to be more secure than previous versions of Windows. According to DailyTech , Windows 7 features protective blo... More >

September 11, 2009

Apple Releases Snow Leopard Update

AppleInsider reports Apple has released a small bug-fix update for its latest Mac OS X . Regarding the update, Apple says it includes "general operating system fixes that enhance the stability, com... More >

September 10, 2009

Apple Plugs iPhone, QuickTime Security Holes

The Washington Post blogger Brian Krebs reports that Apple has issued a security update to fix several vulnerabilities in the iPhone and iPod Touch. The iPhone version 3.1 offers at least 10 secur... More >

Research Shows Captcha Works

According to TG Daily , Penn State researchers explored whether Captcha images really do prevent automated network attacks . The goal, according to James Z. Wang, associate professor in Penn State'... More >

Cisco Patches DoS Bug

Cisco has patched a DoS vulnerability that affects multiple products.   According to Computerworld , the bug allows attackers to change the state of TCP connections, which would allow an attac... More >

10 Bugs Patched in Firefox 3.5

According to Computerworld , Mozilla patched a total of 10 vulnerabilities in Firefox 3.5. All but one are rated as critical.   Most of the flaws involved stability issues in the application'... More >

Symantec Releases Norton Internet Security 2010

The latest version of Norton security suite, Norton Internet Security 2010, has been released by Symantec.   According to V3.co.uk, the suite offers up a new feature called Quorum , which is ... More >

September 9, 2009

Symantec Finds Phishing Attacks Decline

According to Symantec's September 2009 State of Phishing Report, the number of phishing attacks fell by 45 percent in August. What's more, the use of automated phishing toolkits dropped by 30 perce... More >

Microsoft Confirms Vista, Windows 7 Bug

According to Computerworld , Microsoft has confirmed a bug that affects Windows Vista , Windows Server 2008, and the release candidates of Windows 7 and Windows Server 2008 R2, causing them to cras... More >

Patch Tuesday Addresses Eight Vulnerabilities

According to InformationWeek , September's Patch Tuesday saw five Security Bulletins addressing eight vulnerabilities .   All five are rated as "critical." Three are considered browse-and-get-... More >

September 8, 2009

The Importance of Cyber Security Exercises

With cyber security attacks against public and private information technology and networks escalating in occurrence and complexity, a cyber security exercise can be a good way to test how an organiza... More >

Researchers Find Serious Flaw in Vista, Windows 7

According to Computerworld , researchers have seen exploit code for a flaw that lies in a driver used for the Samba file-sharing feature in Windows.   Bojan Zdrnja, a handler for the SANS Int... More >

Criminals Exploiting IIS Bug, Says Microsoft

Criminals are already starting to exploit an unpatched bug in Mincrosft's IIS server software, says the software giant. According to Computerworld , Microsoft says it is starting to see "limited a... More >

WordPress Warns of Worm

WordPress is warning about a worm that can post malware and spam to some WordPress blogs that are using outdated versions of the blogging software, reports CNET News . According to the company , "... More >

Hackers Increasingly Focusing on ATMs

A report from European security agency Enisa shows a 149 percent rise in ATM attacks last year, according to V3.co.uk .   The report indicates that hackers are increasingly trying to launch a... More >

September 4, 2009

McAfee False Alarm Causes Headache

Some system administrators were inconvenienced by faulty virus definition updates from McAfee . According to The Register, the false alarm flagged legitimate JavaScript files as potentially dangerou... More >

Cloud Could Be Attacked from the Side

Researchers at the University of California-San Diego and the Massachusetts Institute of Technology are warning about the possibility of side channel attacks in cloud computing environments. Accord... More >

Adobe, Oracle Delay Updates

Adobe won't issue its second quarterly patch update on Sept. 8 because it spent most of July scrambling to fix two critical security problems, according to Computerworld .   Adobe admits that ... More >

Microsoft to Release Five 'Critical' Updates; Apple Updates Java for Mac

According to Computerworld , Microsoft will be delivering five security updates for the next Patch Tuesday slated for Sept. 8. All five are rated as "critical." Beyond that, Microsoft has not prov... More >

September 3, 2009

Microsoft: IIS Patch Won't Be Ready for Patch Tuesday

Computerworld reports that Microsoft has released a formal security advisory for a vulnerability in three older editions of Internet Information Services (IIS) server. The advisory comes after t... More >

Big Names Do Well in Virus Bulletin Spam Report

The results of Virus Bulletin's latest round of spam blocking tests are in, and nine of the 12 spam-blocking suites tested passed , reports V3.co.uk . The test looked for each product's ability to ... More >

Malware Writers Targeting California Wildfires

Attackers are targeting the California wildfires in an attempt to infect users with malware, reports V3.co.uk .   According to Sophos, malware writers are using search engine optimization tech... More >

Don't Be Scared By Scareware

Most users are at a loss of what to do when they stumble across a hacked or malicious site pushing scareware, says The Washington Post blogger Brian Krebs. Krebs says trying to click your way out ... More >

September 2, 2009

Anti-Phishing Training from Intrepidus Includes Attachments

According to Network World , Intrepidus Group has added e-mail attachments to its anti-phishing training system .   The original system allows companies to emulate attacks, tracking the abilit... More >

Five More Indicted in Cyber Crime Operation

Five Eastern European men have been indicted by New York prosecutors for a credit card scam that raked in at least $4 million from some 95,000 stolen card numbers, reports Computerworld .   Ac... More >

Microsoft Looking into IIS Vulnerability

Microsoft says it is taking a look at a critical vulnerability in older editions of its Internet Information Services (IIS) server, reports Computerworld . The confirmation comes just after a hack... More >

OpenAjax Alliance Helps Secure Mashups

In an effort to help protect applications from external attacks, the OpenAjax Alliance has released OpenAjax Hub 2.0 , a Web 2.0 mashup application security tool.   According to V3.co.uk , thi... More >

September 1, 2009

Hacker Releases Code for Attack on Microsoft IIS Server

A hacker has posted code to the Milw0rm Web site to exploit a flaw that lies in the File Transfer Protocol software. According to Computerworld , this flaw could be used to take over a system runni... More >

Judge Refuses to Lower Childs' Bail

A county judge has denied former San Francisco IT administrator Terry Childs'  request for reduced bail , reports Computerworld . His bond remains at $5 million.   Childs faces as much as five... More >

Trend Micro Launches Web Gateway Solution

Designed to give IT managers greater insight into employee behavior on the Web, Trend Micro's Web Gateway Security product offers comprehensive URL filtering, zero-hour attack protection and leadin... More >

Security Software Solutions

Security software and strategies to protect valuable company information and insure compliance with global, federal, and state regulations.

Applications for Mid-size Businesses

Applications that mid-sized businesses can use to improve operational efficiency, accelerate growth, and maintain profitability.

Compliance and Risk Mitigation

Compliance and risk mitigation solutions that strengthen data security, automate compliance measures, and reduce TCO for a more viable business future.

Data Warehousing for Business Intelligence

Comprehensive storage solutions for better data access and retrieval, leading to better-informed business decisions.