Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

Previous Next

Security

January 2010

January 29, 2010

Cisco Warns of Flaws in MeetingPlace

Cisco has issued a security advisory for users of its Unified MeetingPlace conferencing tool, reports V3.co.uk . The fix addresses versions 5, 6 and 7.   Some flaws could allow an attacker to ... More >

419 Scams Still Duping World

According to Dutch private investigation company Ultrascan, the highest-ever annual losses for advance-fee frauds (aka 419 scams) occurred in 2009. Computerworld reports that the company estimate... More >

Cable Modem Hacking Suspect Arrested

The FBI has arrested 26-year-old Matthew Delorey for allegedly selling modified cable modems that allowed free Internet access, according to Computerworld .   Federal authorities claim that D... More >

House Leaders Want Web Site Defacement Investigated

As we reported on our Network Security Edge site, dozens of Congressional Web sites were defaced by a group known as the Red Eye Crew. Now lawmakers want answers.   According to Computerwor... More >

iPad Security Concerns

Although the Apple's iPad has not officially been released, experts are already talking about possible security concerns, reports CNET News . There are a lot of "ifs," but it's still worth consideri... More >

January 28, 2010

Apache Makes Some Changes to SpamAssassin

In a move to improve spam detection, Apache's SpamAssassin 3.3.0 now separates its rules engine from the core product, reports eSecurityPlanet . Daryl O'Shea, Apache SpamAssassin's project managem... More >

Dasient: Web Page Malware Infections Double

Security startup Dasient has issued a report that shows the number of Web pages infected with malware has nearly doubled in the last quarter compared to a year ago.   According to SFGate , th... More >

Survey: Execs Have Growing Fear of Cyber Attacks

According to a survey of 600 computing and computer-security executives in 14 countries by the Center for Strategic and International Studies and McAfee, there is concern about the growing threat of... More >

January 27, 2010

StopBadware Spins Off From Harvard

According to an Associated Press article on Newsvine.com, research organization StopBadware has decided to leave its Harvard University roots and spin out on its own.   The organization, ori... More >

Researchers Label 3-D Secure as Insecure

V3.co.uk reports that University of Cambridge researchers have released a blistering attack on the 3-D Secure protocol used by Visa and MasterCard to authenticate online customers, calling it "a t... More >

Bank Sues Cyber Theft Victim

Lubbock, Texas-based PlainsCapital bank is suing its customer , Hillary Machinery  of Plano, which was hit by an $800,000 cyber theft incident, reports Computerworld . This interesting twist could t... More >

January 26, 2010

BlueCross BlueShield Suffers Security Breach

eSecurity Planet reports that a thief managed to steal 57 BlueCross BlueShield computer hard drives from a closet at Chattanooga, Tenn. call center. Now the company has to tell hundreds of thousan... More >

Fewer Security Breaches, But Cost Rises

According to the Ponemon Institute, the number of security breaches may have fallen last year, but the cost per incident is up . V3.co.uk reports that the average per-incident cost of a security b... More >

Google Patches Baker's Dozen of Chrome Bugs

Google's newest release of its Chrome browser patches 13 security vulnerabilities , six of which Google ranked as "high." Details on four of the six have been blocked so as to prevent hackers from e... More >

Nebraska Man Pleads Guilty to Scientology Web Attack

Computerworld reports that Brian Thomas Mettenbrink , of Grand Island, Neb.,has agreed to plead guilty to charges related to a January 2008 attack on Web sites of the Church of Scientology.   ... More >

NetApp, Cisco, VMware Team up For Cloud Security

According to V3.co.uk , NetApp, Cisco and VMware have teamed up to offer a design architecture that will provide more efficient and secure virtualized data centers for cloud computing.   The ... More >

More Vulnerabilities Discovered in IE

On the heels of an emergency software update , a research firm has uncovered still more flaws in Microsoft's Internet Explorer.   According to Telegraph.co.uk , Core Security Technologies clai... More >

January 25, 2010

MessageLabs: UK Most Popular Phishing Target

According to the latest spam reports from MessageLabs, the UK is the most popular phishing target with one in every 253.6 e-mails sent being connected to a phishing operation, reports V3.co.uk . O... More >

HP Expands Secure Advantage Program

In an effort to help enterprises adopt and maintain security protection online and offline, HP is expanding its Secure Advantage program with two new services aimed at helping companies secure thei... More >

DDoS Attacks Strike Chinese Human Rights Sites

In an incident separate from the Google attacks, five Chinese human rights sites were attacked by hackers, according to Computerworld .   The Chinese Human Rights Defenders site was hit by a ... More >

Twitter Widget Flaw Leaves Users Vulnerable

Security researcher Mike Bailey warns that a flaw in Twitter’s Web site has left the login credentials of users vulnerable to hackers, reports The Globe and Mail .   The bug takes advantage o... More >

China Denies Involvement in Google Attack

China denies that it had any involvement in a hacking attempt against Google and several other companies, reports The Associated Press . The incident has led Google to threaten to quit China . &nb... More >

Only 20 Percent of Federal Agencies Meet DNS Deadline

According to DNS vendor Secure64, only 20 percent of federal agencies met the Dec. 31 deadline to deploy new authentication mechanisms on their Web sites, reports Computerworld .   In August ... More >

January 21, 2010

Verizon, McAfee Join Forces for Internet Security

Verizon and McAfee have teamed up to provide an upgraded version of Verizon Internet Security Suite to FiOS Internet and high-speed broadband customers, according to eSecurity Planet .   The V... More >

Micrososft Warns of 17-Year-Old Windows Bug

Microsoft is warning users of a 17-year-old bug in the kernel of all 32-bit versions of Windows that hackers could use to hijack PCs, reports Computerworld .   The vulnerability, which was di... More >

Comcast Ditches McAfee for Symantec

Comcast is expanding a test of its new security program to all customers and replacing McAfee's Internet security suite with Symantec's Norton offering , reports PC Magazine . As TechnologyLive n... More >

Microsoft's Out-of-Band IE Patch Coming Thursday

According to InformationWeek , Microsoft plans to release on Thursday an out-of-band patch for the critical vulnerability in Internet Explorer that was used to attack Google and other companies. &... More >

January 20, 2010

Network Solutions Customers Hit by Hack

Several hundred Web sites hosted by Network Solutions have been defaced by hackers , reports Computerworld .   The company says the incident is a "limited attack on Web sites hosted on Network... More >

Security Researcher Finds China Link in Google Hack

SecureWorks researcher Joe Stewart claims to have found code that links the cyber attacks on Google and 34 other companies to China, reports and IDG story in The New York Times.   Stewart sa... More >

F-Secure: Chinese Cyber Attacks Hitting Defense Contractors

According to F-Secure, the Chinese cyber attacks that hit Google and many other companies are now targeting some U.S. defense contractors .   Computerworld reports that malicious PDF files tha... More >

Apple Releases Security Update for 12 Bugs

V3.co.uk reports that Apple has released patches to fix 12 vulnerabilities in the company's Snow Leopard and Leopard operating systems, including seven Adobe Flash Player flaws.   According t... More >

Microsoft to Release Out-of-Band Patch for IE Flaw

The Wall Street Journal reports that Microsoft is promising to release an emergency software patch to fix an Internet Explorer browser flaw that is believed to have played a role in the Chinese ha... More >

January 19, 2010

Google Investigates Possible Inside Help in Attacks

After a much-publicized cyber attack that rocked the company's infrastructure in mid-December, Google has launched an investigation of its staff in China, reports PCWorld.com .   Although Goo... More >

France, Germany Warn Against Use of IE6

France and Germany are warning against the use of Internet Explorer 6 following attacks against Google and 33 other organizations, according to InformationWeek .   As we reported last week, a ... More >

January 15, 2010

ABI: Sales of Mobile Security Solutions to Increase

ABI Research is predicting a big increase in sales of mobile security solutions as smartphones advance both in capability and as a target for the bad guys, according to eSecurityPlanet .   In... More >

New York Bank Suffers Security Breach

internetnews.com reports that a New York bank is warning more than 8,000 customers that their their account login information may have been compromised in November after a hacker illegally accesse... More >

Guilty Pleas Entered for Identity Theft Schemes

Romanian national Cornel Ionut Tonita has pleaded guilty to a charge related to a phishing operation that attempted to defraud customers of banks such as Citibank and Wells Fargo, reports Computerw... More >

IE Vulnerability Used in Google Attack

Computerworld reports that Microsoft has admitted that a critical and unpatched vulnerability in Internet Explorer was used in the attack against Google and other companies' networks.   Accor... More >

January 14, 2010

New Security Suites from Trend Micro

Trend Micro has introduced four new security suites geared toward enterprises and medium-sized businesses.   As SCMagazine reports, Trend Micro Enterprise Security Suite is a centrally manag... More >

Survey: Security Concerns Holding Some Back from Virtualization

According to CDW's survey, "Server Virtualization Life Cycle Report," enterprise customers recognize the inherent benefits of virtualization, but they are still gun-shy about virtualizing their most ... More >

Google Moves Gmail to HTTPS

Following recent hacking attempts by China on its e-mail service, Google has decided to move its Gmail to a more secure protocol. According to SFGate , HTTPS access to Gmail is now the default ... More >

January 13, 2010

'Human Error' Behind Google Data Leak

Google is blaming human error for an e-mail that went out to users of its business listings service that contained potentially sensitive business data, reports PCWorld.com .   According to I... More >

Russian Security Firm Frustrated with 'Responsible Disclosure'

A small Russian firm has decided to release details of zero-day exploits in business software every day for the rest of January.   According to V3.co.uk , Intevydis is frustrated with the "re... More >

Critical Update from Microsoft, But Focus on Adobe

Microsoft has started the year out with a single "critical" patch for January's Patch Tuesday. PCWorld.com reports that the patch targets a vulnerability in the embedded Open Type font engine. Al... More >

Facebook and McAfee Team up for Security

CNET News reports that McAfee and Facebook have formed a partnership that will offer Facebook's 350 million users a free six-month subscription for McAfee's Internet Security Suite software, follo... More >

January 12, 2010

Symantec Snags Gideon Technologies

ABC News reports that Symantec has agreed to purchase risk-management software maker Gideon Technologies.   Symantec hopes the deal will increase its slate of threat-assessment products. The ... More >

McAfee: Spammers Exploiting Free Online Hosters

According to McAfee's December 2009 Spam Report, spammers are getting past anti-spam filters by exploiting online hosting companies that provide free domains and web hosting, V3.co.uk reports. Mc... More >

Kaspersky Fails Virus Bulletin Spam Test

Of the 15 anti-spam products tested by the Virus Bulletin spam test, all but one were awarded the testing firm's VBSpam award, reports V3.co.uk .   Kaspersky was the loser because although it... More >

Iranian Hackers Hijack China's Top Search Engine

According to The Wall Street Journal , Iranian hackers may be behind an attack the brought down China's top search engine, Baidu. Baidu users have reported seeing a banner for the "Iranian Cyber A... More >

January 11, 2010

Security Flaw Bypasses Verizon Droid Screen Lock

According to TechCrunch article in The Washington Post, Android OS version 2.0.1 has a security flaw that makes it easy to bypass the phone's screen-lock security mechanism. Simply hitting the "B... More >

Heartland Reaches $60 Million Settlement with Visa Issuers

V3.co.uk reports that Heartland Payment Systems has reached a $60 million settlement with Visa issuers to compensate them for losses incurred after the huge data breach in 2008. Heartland Chairman... More >

Oracle Readies 24 Security Fixes

On Tuesday, Oracle will release 24 security vulnerability fixes that apply to hundreds of its products, reports V3.co.uk . The news comes after Microsoft announced it would be posting one of its ... More >

January 8, 2010

Lojack for Laptops Makes Use of New Intel Security Features

Absolute Software’s Lojack for Laptops is making use of Intel's newest line of notebook chipsets for 2010 , reports VentureBeat .   The chips boast a new security feature that can remotely be... More >

TwitSweeper Kills Twitter Spam

Emerge 2 Digital has created an application that helps Twitter users block spam , reports Convince&Convert blogger Jay Baer.   According to Baer, TwitSweeper scans every bio, screen nam... More >

Juniper Fixes Router-Crashing Bug

Juniper Networks has released seven security advisories, reports Computerworld . Among them is a patch for a bug that can crash the company's routers . All routers using the JunOS operating system ... More >

Single Security Update for January Patch Tuesday

Next week's Patch Tuesday will see only a single security update . According to Computerworld , the patch will address a vulnerability rated "critical" in Windows 2000. The bug also affects Windows... More >

January 7, 2010

Tampa Company Secures Computer Systems with Biometrics

Tampa-based Realtime North America is using biometric technology to help companies and government agencies tighten their computer security, reports TBO.com .   In addition to the recognition ... More >

SpamAssassin Bug Blocks E-Mail

SC Magazine reports that a bug in SpamAssassin over the New Year caused many e-mails to be erroneously flagged as spam and blocked.   The bug has to do with the date stamp. InfoWorld explai... More >

Smartphone E-Mail Services Fail to Block Spear Phishing Messages

According to research by PacketFocus CEO Joshua Perrymon, even the most current smartphone e-mail security appliances, services and clients cannot detect spear-phishing messages .   SC Magazine... More >

Hackers Zero in on Adobe's Unpatched Reader Vulnerability

Predictions that Adobe will be a top target in 2010 may be holding true. The SANS Institute's Internet Storm Center reports that hackers are actively exploiting a critical vulnerability in Adobe R... More >

January 6, 2010

Facebook Users Getting Messages Pointing to Suspicious Site

According to SC Magazine , Facebook users have been receiving direct messages with a link to a suspicious Web site .   The message says a friend has recommended that the user visit the "binsse... More >

End of Decade Causes Problems for Symantec

The new year has brought problems for Symantec. According to InfoWorld , the company is warning that its Endpoint Protection Manager server product is falsely marking signature updates issued this ... More >

FBI Probes Online New York School District Theft

The FBI is investigating a security breach in which cyber criminals tried to steal about $3.8 million from a New York school district's online accounts just before Christmas.   According to C... More >

January 5, 2010

Security Flaw Causes Kingston to Recall USB Drives

Certain models of Kingston Technology's DataTraveler secure USB flash drives are being recalled due to a flaw that could allow a hacker to gain access to the user's password, reports Computerworld... More >

1 Million Massachusetts Residents Affected by Security Breaches

According to boston.com , one in six Massachusetts residents has had credit card numbers, medical records or other personal information leaked or stolen over the past two years.   The leaks, ... More >

RandomStorm Snags Damn Vulnerable Web Application

RandomStorm has acquired the open source vulnerability testing application Damn Vulnerable Web Application , reports SCMagazine . The application was developed by security blogger and ethical hacke... More >

10 Security Challenges to Watch Out for in 2010

With 2010 freshly upon us, there are lots of predictions about what the new year will bring. With computing in a state of change, cyber criminals are taking advantage of new technologies to launch a ... More >

F-Secure Releases Mobile Phone Anti-Theft Tool

Lost or stolen smartphones now have a new layer of protection thanks to a new tool from security vendor F-Secure.   V3.co.uk reports that F-Secure has released its Anti-theft for Mobile softwa... More >

Spanish, Iranian Site Hacks Highlight Dangers of XSS Attacks

Recent attacks on the Spanish EU presidency site and the official site of the Iranian president illustrate the dangers of cross-site scripting (XSS) attacks , say security experts.   V3.co.uk ... More >

January 4, 2010

TSA Drops Travel Bloggers' Subpoenas

According to an Associated Press article on Newsvine, the Transportation Security Administration has dropped the subpoenas it had issued to two Internet bloggers in an attempt to find the leaker ... More >

McAfee: VoIP Vulnerabilities Increasing

A new white paper, "VoIP Vulnerabilities," by McAfee Labs found that security vulnerabilities continue to plague the VoIP environment , reports EnterpriseVoIPPlanet .   McAfee found nealry 60 ... More >

Greening IT with Server Consolidation

Learn how virtualization reduces the TCO of managing your date, while contributing towards your sustainability efforts.

Business Intelligence

Best-practice tools, strategies and technologies for determining and managing the data you need to make better business decisions.

Application Performance Management

Application delivery and performance tools for Web applications to insure high availability and productivity.

Cost Cutting through Server Consolidation

Products, management tools, and industry insights that enhance the value of virtualization for your business.