Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

Previous Next

Security

November 2009

November 30, 2009

The Importance of Security ROI Framework Analysis

Writing on our CTO Edge site, blogger Steve Gold points out the importance of a security ROI framework analysis . Such an analysis, he says, quantifies projected ROI for security investments by in... More >

China Warns of New Panda Virus

China is warning about a new version of the Panda virus that wrecked havoc on millions of PCs in the country three years ago, reports Computerworld .   According to McAfee, the new worm varia... More >

Prevx Warns Microsoft Patches Cause Black Screen

According to U.K. security company Prevx, Microsoft's latest round of security patches is causing some computers to seize up and display a black screen, making the computer useless. PCWorld report... More >

November 25, 2009

Verizon Issues 'Cyber Monday Alert'

SideJackers, the hackers who hang out near popular Wi-Fi hotspots hoping to snag user IDs and passwords, are expected to be out in droves this holiday shopping season.   According to internetne... More >

Federated ID Comes to Microsoft Azure

According to InformationWeek , Microsoft has announced a Microsoft Identity Platform built into its Azure cloud that invokes a "claims-based architecture" to establish a federated identity for use... More >

November 24, 2009

'Godfather of Spam' Gets 51-Month Prison Sentence

Alan Ralsky, the self-proclaimed "Godfather of Spam," was sentenced to 51 months in prison for a scheme that used spam to manipulate stock prices to make a profit.   According to NetworkWorld... More >

Romanian Hacker Cracks Symantec Web Server

According to vnunet.com , a Romanian hacker known only as Unu has broken into a Symantec Web server using a blind SQL injection attack. Unu was able to access sensitive information, such as custom... More >

Microsoft Issues IE Vulnerability Security Advisory

Microsoft has issued a security advisory for the zero-day exploit aimed at Internet Explorer, reports Computerworld . Security Advisory 977981 provides guidance and workarounds for an issue that ... More >

November 23, 2009

Survey Shows Workers Steal Corporate Data Despite Penalties

A survey by Cyber-Ark of  300 office workers in New York City revealed some interesting findings concerning the impact of the recession on ethics and security.   According to this press release... More >

Suggestive Worm Invades Facebook

AVG blogger Nick Fitzgerald reports that a new Facebook worm uses a suggestive come-on to lure unsuspecting users into clicking a link. A link to the same lure page is then posted on the victim's ... More >

Visa, MasterCard Warn Banks of Suspected Card Breach

Visa and MasterCard are warning banks of possible fraudulent credit card transactions following a data breach in Spain, according to Computerworld . European customers who may have had transaction... More >

Hacker Posts Code for Attack on Older Versions of IE

PCs running older versions of Microsoft's Internet Explorer browser could be at risk of a new attack, thanks to an unidentified hacker who posted attack code to the Bugtraq mailing list, reports C... More >

November 20, 2009

Missing Hard Drive Contains 1.5 Million Records

According to Computerworld , a hard drive with seven years' worth of personal information on about 1.5 million customers of Health Net of the Northeast Inc. has been reported missing -- six months... More >

UK Climate Research Unit Hacked

Examiner.com reports that the UK's Climate Research Unit at the University of East Anglia suffered a security breach in which thousands of e-mails and documents were accessed. The stolen data was ... More >

Microsoft Helps Discover Flaw in Google Plug-In for IE

Another flaw has been discovered in Google's Chrome browser, reports The Register . The flaw in the Google Chome Frame plug-in for Internet Explorer users, discovered with the help of Microsoft, al... More >

Cisco Offers Free iPhone Security App

A free iPhone security app is now available from Cisco, reports CNET News . The application allows users to get real-time customized alerts on new security threats, as well as other information for... More >

November 19, 2009

Four Jailed for Using Trojan to Steal from Bank Accounts

Four UK-based men have been sentenced to jail for using a Trojan to steal money from bank accounts, reports SC Magazine . The four  --  Azamat Rahmonov, Shohruh Fayziev, Joao Dos Santos Cruz and P... More >

Phishing Scam Targets 'Verified by Visa' Authentication Program

Webroot is warning of a phishing scam that makes use of the ‘Verified by Visa' authentication program to target holiday shoppers who buy gifts online.   According to SC Magazine , the bogus e... More >

FTC Accuses Online Check-Writing Service of Not Authenticating Users

Online check-writing service Qchex.com has been slapped with a civial complaint by the Fedral Trade Comission for allegedly allowing customers to create and e-mail checks without verification of th... More >

November 18, 2009

Sources of Malware Are Spreading

Although October’s threat stats show that the level of malware coming from the usual top 10 countries, like Brazil and the U.S., is decreasing, that doesn't mean spam and virus levels are decreasing,... More >

MassMutual Database Hacked

internetnews.com reports that one of MassMutual's employee databases was compromised , exposing an unknown number of employees' personal data for a unknown amount of time.   The company says t... More >

Public Wi-Fi Connections Put Smartphones at Risk

According to a report by SMobile Systems, smartphones connecting via unencrypted Wi-Fi hotspots can be easily compromised. Computerworld reports that the authors used an array of existing tools to... More >

Health Care Affiliates Putting Patients at Risk, Survey Shows

A survey by Healthcare Information and Management Systems Society (HIMSS) Analytics found that companies that do business with health care providers, such as accounting firms, are unprepared to mee... More >

T-Mobile Employees Allegedly Sold Customer Data

InformationWeek reports that T-Mobile employees allegedly stole the personal information of thousands of customers and sold it to competing service providers for lead generation. The information b... More >

November 17, 2009

Study Finds Discontent with Network Security

A Ponemon survey points to frustration about today's endpoint security .   According to NetworkWorld , a survey of the United States, the UK, Australia, New Zealand and Germany shows that whil... More >

Most Security Products Fail Quality Tests

According to The H Security , only 4 percent of the security products tested by independent tester ICSA Labs are certified on the first try. The main problem was in many cases the failure of a pro... More >

InZero Boasts World's First Truly Secure Computer

InZero Systems has unveiled a "revolutionary new computer hardware" that eliminates the threat of network-originated data compromises and virus attacks, according to an e-mail press release.   ... More >

McAfee: Nations May Be Paying Criminals for Botnet Attacks

A new report by McAfee, " Virtually Here: The Age of Cyber Warfare ," indicates that nations that want to disrupt their enemies' banking, media and government resources can simply order botnet attack... More >

Microsoft Issues Advisory on Windows 7 Zero Day

Microsoft has issued an advisory for the zero-day bug in the Server Message Block protocol of Windows 7 and Windows Server 2008 R2 system, reports ChannelWeb .   The advisory says the vulnera... More >

November 16, 2009

IBM Offers Virtualization Security

IBM's new Virtual Server Security product is designed to secure each layer of the infrastructure of a virtual server, reports InformationWeek .   The software is built for VMware's vSphere pla... More >

Imperva Discovers Yahoo Site Flaw

Data security firm Imperva says it has found a new flaw in a Yahoo site that could lead to a large-scale data breach.   According to V3.co.uk , the SQL injection flaw is on the Yahoo jobs sit... More >

Wiresoft Launches Firegate, Issues 'Hack Us' Contest

Wiresoft has unveiled Firegate, an all-in-one product aimed at SMBs. It offers firewall, individually configurable spamwall, unlimited VPN support, content filtering and antivirus protection, accordi... More >

November 13, 2009

Google Patches Two Security Holes in Chrome

According to CNET News , Google has updated its Chrome browser to address two security holes .   One bug fixed by Google Chrome 3.0.195.33 could have allowed a malicious Web site to set custom... More >

Payment Transfer System Target of Spam Campaign

According to NetworkWorld , a new spam campaign originating from the Pushdo botnet is targeting the National Automated Clearing House Association, a financial transfer system that handles trillion... More >

McAfee: Spam Levels at All-Time High

Recent numbers from McAfee indicate that spam levels are at an all-time high , reports V3.co.uk .   McAfee says spammers have recovered faster than expected after the McColo shutdown . The se... More >

Flash Flaw Puts Most Sites at Risk

Security researchers at Foreground Security say a flaw in Adobe's Flash can be used to compromise nearly every Web site that allows users to upload content, reports Computerworld .   The prob... More >

November 12, 2009

iPhone Hit by Second Worm Attack

Another worm attack has hit the iPhone. This is the second one this week.   SC Magazine reports that this new worm does not make any noticeable changes to the user's device. Classified as i... More >

Configuration Errors Put Data at Risk

Loosely configured IP networks have resulted in the loss of millions of records, according to a study by Yankee Group.   internetnews.com reports that 37 companies have lost almost 132 million... More >

Researcher Reveals Windows SMB Bug

Computerworld reports that security researcher Laurent Gaffie has posted details and proof-of-concept exploit code for a new unpatched bug in Windows 7 and Server 2008 R2 that could lock up the sy... More >

Safari 4.0.4 Serves up Security Fixes

According to CNET News , Apple has released a security update for Safari to address a wide range of problem points in both Windows and Mac.   Two of the vulnerabilities addressed by version 4... More >

November 11, 2009

Survey Finds Patient Data at Risk

According to a study from the Healthcare Information and Management Systems Society, many health care organizations are not ready for new federal regulations and other security challenges.   Inf... More >

Microsoft Patches Critical Windows Kernel Vulnerability

Microsoft's November security patch included three bulletins rated as "critical."   According to InformationWeek , one of the critical vulnerabilities addresses a Windows kernel flaw that c... More >

Online Users Less Anxious Over Security, Survey Says

According to a global survey, "Unisys Security Index: Global Summary," anxiety about Internet security , personal safety and national security is down from six months ago.   NetworkWorld repor... More >

Group Hijacks Hundreds of Facebook Groups

Claiming to highlight a major security weakness in Facebook, a group that calls itself Control Your Info has taken over hundreds of Facebook groups , reports Computerworld . More than 200 groups ha... More >

Eight Hackers Indicted in $9 Million Fraud Ring

According to The Wall Street Journal , the Department of Justice has indicted eight Russian and Eastern European computer hackers for allegedly breaking into ATMs in hundreds of cities worldwide a... More >

November 10, 2009

Koobface Targeting Google Reader Accounts

Users with Google Reader accounts on social-networking sites should beware, warns Trend Micro.   According to SC Magazine , a Google account that is controlled by Koobface is hosting a page w... More >

Trend Micro CTO Warns About Cloud Security

Dave Rand, CTO of security vendor Trend Micro, warns that there will be widespread data theft as more organizations move their information into the cloud. V3.co.uk quotes him saying: Between now ... More >

Symantec Report Shows Increase in Spam, Phishing

According to Symantec's latest "State of Spam and Phishing" reports, nearly 90 percent of all e-mail messages are either spam or phishing attempts.   More spam messages were coming from the As... More >

Snow Leopard Update Addresses 40 Security Issues

According to InformationWeek , Apple's Mac OS X 10.6.2 (aka Snow Leopard) update addresses 40 security vulnerabilities . Many occur in the open source components of Mac OS X.   A login bypass ... More >

November 9, 2009

Stolen Laptop Puts Doctors' Info at Risk

A stolen laptop has put the personal information of more than 10,000 doctors and dentists at risk , reports internetnews.com . The personal laptop was stolen after an Anthem Blue Cross and Blue Shi... More >

Firefox Tops Cenzic's Vulnerability List

According to application security vendor Cenzic's security trends report for the first half of 2009, Mozilla's Firefox browser led the way in terms of total vulnerabilities. internetnews.com reports... More >

Security Tips for Mac Newcomers

Although examples of OS X viruses and spyware doing damage to real Mac users is astoundingly rare, such threats do exist. In fact, Apple regularly releases fixes for newly-discovered vulnerabilities.... More >

Firefox Crash Bug Fixed

On the heels of the release of its recently updated browser, Mozilla has rushed out a fix for a crash bug that programmers inadvertently introduced.   According to Computerworld , Firefox 3.5... More >

Microsoft to Offer Security Guidelines for Agile

Microsoft plans to release security guidelines for developers using the Agile code-development process, reports Computerworld . The principles come from Microsoft's Security Development Lifecycle (... More >

First iPhone Virus in the Wild

According to V3.co.uk , the world's first iPhone virus is now in the wild. The virus targets users who have jailbroken their phone.   The virus seems to be confined to Australia. It changes t... More >

November 6, 2009

Gumblar Renews Activity, Says ScanSafe

According to ScanSafe researcher, the Gumblar botnet has renewed activity , reports Computerworld . Mary Landesman, a senior security researcher with ScanSafe, says Web sites still infected with Gu... More >

Microsoft to Issue Six Patches for 15 Vulnerabilities

According to InformationWeek , Microsoft plans to address 15 vulnerabilities in this month's Patch Tuesday.   Of the six security bulletins, four are for Windows and two are for Office , spe... More >

November 5, 2009

Symantec: CEOs Vulnerable to Phishing Attacks

Symantec warns that CEOs and other C-level executives are increasingly becoming victims of sophisticated phishing attacks, often masked as official communications from government agencies, reports ... More >

Teen Hacker Held Dutch iPhones for Ransom

According to internetnews.com , a clever teenage hacker sent an unsolicited and unremovable message to Dutch iPhone users that have jailbroken their devices . The message states: Your iPhone's been... More >

McAfee Announces Web, E-Mail Appliance for SMBs

Aimed at SMBs, McAfee has announced its E-mail and Web Security Appliance 5.5 . According to V3.co.uk , the appliance reduces system administration requirements by offering comprehensive security a... More >

Software Makers in Race to Fix SSL Bug

Software makers around the world are scrambling to fix a serious bug in the SSL protocol that lets attackers intercept secure SSL communications between computers using a man-in-the-middle attack, ... More >

November 4, 2009

New Trojan Goes After Mac Users

Symantec is warning Mac users of a new attack disguised as a classic video game. SC Magazine reports that a Trojan called Trojan.Loosemaque is designed to look like a Space Invaders/Galaga-style g... More >

Kaspersky Rolls Out Security for Macs

According to internetnews.com , Kaspersky Lab has released a new security product designed to thwart growing malware threat to Macs . Anti-Virus for Mac stops Mac users from becoming "incubators" f... More >

Google Helps with Password Protection

In an effort to allow users to securely register at Web sites without having to go through a lengthy sign-up process, Google is rolling out new technology called hybrid onboarding , reports interne... More >

Microsoft's 'Exploitability Index' Not Very Reliable

Microsoft's attempt to predict whether hackers will create reliable exploit code for its bugs are right only 27 percent of the time , admits the company.   Computerworld reports that the "Expl... More >

Adobe Fixes Five Bugs in Shockwave

According to PCWorld.com , Adobe is fixing five vulnerabilities in its Shockwave Player .   Classified as "critical," the update affects version 11.5.1.601 and earlier versions. Four of the bu... More >

Bug Fixes from Sun, Research in Motion

Sun Microsystems addresses multiple vulnerabilities with its Java 6 Update 17, reports The H Security . The bugs include various buffer and integer overflows caused by crafted audio and image files... More >

November 3, 2009

M86 Buys Finjan

In an effort to strengthen its Web security product offerings, M86 Security has purchased most of the assets of Finjan , reports PCWorld . The deal will add Finjan’s line of secure Web gateway and... More >

Bank Employee Charged with Identity Theft, Fraud

In a 149-count indictment, Adeniyi Adeyemi , an employee of the Bank of New York Mellon, has been charged with defrauding charities, non-profits, and other organizations of more than $1.1 million ov... More >

Malware Writers Capitalize on Google Wave Interest

Symantec says malware writers are already taking advantage of public interest in Google Wave. V3.co.uk reports that a new wave of Trojans are exploiting the heightened interest in the new invitat... More >

Could New ICANN Rules Open Door for Phishers?

The Information Systems Audit and Control Association is warning that the recent decision by the Internet Corporation for Assigned Names and Numbers to allow non-Latin characters in URL addresses c... More >

Feds Bust Cable Modem Hacker

According to Computerworld , Ryan Harris has been arrested on computer intrusion charges for hacking cable modems .   The Department of Justice claims that Harris sold customizable cable modem... More >

November 2, 2009

Former CEO Indicted for DoS Attacks

A grand jury has indicted Khalid Shaikh , former CEO of YouSendIt, on four counts of mail fraud for allegedly launching four DoS attacks against the company's servers, reports InfoWorld . He was ind... More >

Conficker Infects More Than 7 Million PCs

Researchers at the volunteer-run Shadowserver Foundation say the Conficker worm has now infected more than 7 million computers . InfoWorld reports that researchers have kept track of Conficker inf... More >

Microsoft Security Report: Number of Worms More Than Doubled

According to a new Microsoft security report, the prevalence of computer worms more than doubled during the first half of 2009, reports seattlepi.com . Since Microsoft's last Security Intelligence... More >

Swedish Police Network Hit by DDoS Attack

Sweden's police administration Web site was crippled following a DDoS attack that flooded the site with information requests, reports V3.co.uk . Traffic spiked from from 800 requests a second to mo... More >

Microsoft Security Essentials Does Well in AV-Comparatives Test

According to latest test by independent security researchers AV-Comparatives, Microsoft’s Security Essential product was among the top-rated security software products .   The test pitted 16 di... More >

Database Management

Data management tips and techniques that insure ease of access, comprehensive security and absolute privacy for your invaluable company information.

Service Oriented Architecture (SOA)

Service-Oriented Architecture is the catalyst that allows today’s companies to respond to business demands faster and more effectively than ever.

Decision Management

Applications, management tools and industry advice on how to optimize your data for better business decisions.

Security Software Solutions

Security software and strategies to protect valuable company information and insure compliance with global, federal, and state regulations.