Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

Previous Next

Security

February 2010

February 26, 2010

IBM: Massive Rises in Phishing, Malicious Links

IBM's latest X-Force 2009 Trend and Risk Report notes massive rises in phishing and malicious Web links . V3.co.uk reports that hackers are using a variety of techniques to bypass defenses for mone... More >

Twitter Phishing Attack Suckers British Politicians, Journalists

Several British journalists and politicians fell victim to a Twitter phishing scam that pushed a link to a Web site selling sexual-performance drugs, according to PCWorld.com .   One of the vi... More >

February 25, 2010

Symantec: Most Companies Victims of Cyber Attack in 2009

According to Symantec's latest "State of Enterprise Security" study, 100 percent of the 2,100 businesses surveyed had experienced cyber losses of some type in the past year. Seventy-five percent sa... More >

Court Order Strikes Blow to Waledac Botnet

Microsoft's efforts to get rid of the notorious botnet Waledac have been aided by a court order to cut off 277 .com domains associated with the botnet, reports Computerworld .   In its lawsui... More >

February 24, 2010

OpenOffice.org Issues Six Security Patches

A security update from OpenOffice.org addresses six vulnerabilities. V3.co.uk reports that four of the vulnerabilities could be used for arbitrary code execution , while the other two could be u... More >

Intel Reveals It was Hacked in January

Intel has revealed that it was the victim of a "sophisticated" hacker attack in January, Reuters reports.   The attack occurred around the same time as the recently publicized Chinese hacker... More >

February 23, 2010

McAfee Boosts SaaS Security

With more than 575,000 customers using its suite of software-as-a-service security offerings, McAfee has updated its on-demand e-mail and Web protection applications , according to eSecurity Planet... More >

HP, Fortify Streamline Vulnerability Protection

In an effort to streamline the process of detecting and fixing vulnerabilities in software, Hewlett-Packard is working with code analysis vendor Fortify to combine the benefits of dynamic and stati... More >

FTC Warns Nearly 100 Firms of Data Breaches

InformationWeek reports that the Federal Trade Commission has warned nearly 100 organizations in both the public and private sector that they should review their security practices. In the letters... More >

February 22, 2010

New Twitter Phishing Attack in Progress

VentureBeat is warning that Twitter users are starting to receive phishing messages that look like this: “Lol. this you?? http://divinelink.net/?rid=http://twitter.verify.bzpharma.net/login” The l... More >

nCircle to Offer Free Priority Patch Ratings

Security auditing vendor nCircle Network soon will offer free priority ratings for patches coming from Microsoft, Adobe, Apple and others, according to Computerworld .   The "Patch Priority I... More >

U.S. Analysts Suspect Chinese Author in Google Attacks

Following the recent revelation that the hacking attacks on Google and dozens of other American companies have been traced to computers at two Chinese schools , comes word that U.S. analysts believe... More >

February 19, 2010

Adobe Working to Fix Download Manager Bug

Computerworld reports that Adobe is working to fix a bug in Download Manager , software that it uses to improve download speeds of its products.   Security researcher Aviv Raff says the softwa... More >

Chinese Schools Linked to Google Attack

According to The New York Times , the recent attacks on Google and dozens of other American companies have been traced to computers at two schools in China , Shanghai Jiaotong University and the La... More >

February 18, 2010

New Kaspersky Mobile Security Suite Disables Stolen Phones

Kaspersky's new version of its mobile security suite now lets users disable and wipe information on stolen handsets, reports techradar.com . In addition to wiping or crippling stolen phones, Kasper... More >

Symantec: Bredolab Virus Launching Targeted Attacks

Seven different companies have been the victims of targeted attacks by the Bredolab virus , warns Symantec.   In a departure from Bredolab's usual M.O. of sending out mass quantities of spam, t... More >

Google Fixes Buzz for Mobile Flaw

SecTheory has discovered a cross-site scripting vulnerability in Google's Buzz for Mobile service that could allow an attacker to hijack a Buzz account or run a phishing scam, according to CNET Ne... More >

City of Norfolk Hit with Mysterious Malicious Code

Computerworld reports that malicious code that suddenly appeared on an internal virtual print server took out nearly 800 computers used by the city of Norfolk, Va.   The code, which was activ... More >

Rootkit Behind Blue Screens, Says Microsoft

Following reports that a Windows patch in this month's Patch Tuesday caused the so-called Blue Screen of Death , Microsoft now says a rootkit was behind the crashing of Windows PCs.   According... More >

Massive Botnet Infects 75,000 Computers

Security researchers at NetWitness have discovered a massive botnet known as Kneber that has affected at least 75,000 computers at 2,500 companies and government agencies worldwide for the past 18 ... More >

February 17, 2010

Wipro Probes $4 Million Fraud by Employee

During the course of a year, an unnamed employee embezzled $4 million from Indian outsourcer Wipro after allegedly obtaining a colleague's online password, according to an IDG story in The New Yo... More >

Adobe Patches 'Critical' Reader, Acrobat Flaws

As promised , Adobe has released two out-of-band patches for a pair of "critical" vulnerabilities in Reader and Acrobat . V3.co.uk reports that the vulnerabilities could let an unauthorized user ... More >

ScanSafe: Malicious PDFs Make up 80 Percent of Exploits

According to ScanSafe, rogue Reader documents made up 80 percent of all exploits at the end of 2009. Computerworld reports that malicious PDF files made up a little over half of all exploits track... More >

Experts Predict Safari to Go Down in Hacking Contest

With the Pwn2Own hacking challenge approaching, experts are already putting out their predictions.   Aaron Portnoy, security research team lead with Pwn2Own sponsor 3Com TippingPoint, is pretty ... More >

Cyber Attack Scenerio Shows U.S. Unprepared

Cyber ShockWave , a simulated war game conducted by non-profit organization the Bipartisan Policy Center, demonstrated a lack of preparedness for the U.S. administration to react quickly to a cyber a... More >

February 16, 2010

Brocade, McAfee Collaborate on Security

Brocade and McAfee have teamed up to deliver end-to-end network security, reports the Silicon Valley/San Jose Business Journal . The companies say that critical security capabilities will be integr... More >

France Accuses U.S. Cyclist of Hacking

According to a Reuters article on internetnews.com, French officials are accusing American rider Floyd Landis of hacking into an anti-doping laboratory computer in an effort to prove the laborato... More >

Stolen Laptops Puts AvMed Customers at Risk

According to internetnews.com , more than 200,000 AvMed Health Plan subscribers may have been left vulnerable to identity theft after a pair of laptops were stolen from a conference room at the co... More >

Zeus Resurfaces to Target Government, Military Workers

Websense is warning that the Zeus Trojan has resurfaced with a new wave of attacks targeting government and military workers. According to V3.co.uk , the attack involves a bogus e-mail claiming to... More >

Bogus AV Program Pushes Live Tech Support

Computerworld reports that Symantec researchers are warning about a fake antivirus product known as Live PC Care that is offering victims live technical support.   Once users install the bogu... More >

Hacker 'Iceman' Sentenced to 13 Years

Max Ray Butler, aka "Iceman," has been sentenced to to 13 years in federal prison for hacking into financial institutions and stealing credit card account numbers, according to Computerworld . He a... More >

Pwn2Own Focuses on Smartphone Exploits

The annual hacking contest Pwn2Own will award $15,000 to anyone who can break into an iPhone, BlackBerry Bold, Droid or Nokia smartphone, reports Computerworld . Any successful exploit of the pho... More >

February 15, 2010

Shell Investigating Data Breach

A database containing contact details for 176,000 workers of Royal Dutch Shell has been copied and sent to groups opposed to the oil company's practices. The e-mail allegedly came from a group of She... More >

February 12, 2010

Spammers Already Targeting Google Buzz

Spammers wasted no time targeting Google's newly launched social-networking site, Google Buzz. Websense is warning of phishing scams disguised as quit-smoking guides that are causing headaches for ... More >

Adobe to Patch Flash, Reader, Acrobat Flaws

Here we go again: Adobe has issued a security bulletin to address a "critical" vulnerability in its Flash software , as well as one for an "important" bug in its LiveCycle and ColdFusion software, a... More >

Microsoft Halts Windows Patch Blamed for Blue Screens

According to eWEEK , Microsoft is investigating reports that a Windows patch issued as part of this month's Patch Tuesday is causing the so-called Blue Screen of Death.   Users have been repo... More >

February 11, 2010

Ceridian Victim of Data Security Breach

eSecurity Planet reports that a hacker was able to access Ceridian's Internet payroll system in late December, potentially compromising the sensitive data of more than 27,000 workers. The exposed ... More >

Australian Government's Planned Porn Ban Prompts DDoS Attack

A group campaigning against Australia's plan to ban Internet pornography has targeted official Australian Web sites , including the main Australian government site and the Australian Parliament Hous... More >

Cyber Crooks Pushing Valentine's Day Malware

Just like any other holiday, Valentine's Day is bringing out cyber criminals .   According to V3.co.uk , security experts are warning of fresh Web-based attacks targeting Valentine's Day enthu... More >

Mozilla Admits Firefox Add-On Malware Claim a False-Positive

According to Computerworld , Mozilla has acknowledged that it falsely accused SourceTec Software Co. of infecting a Firefox add-on with attack code.   As we reported on our Network Security ... More >

Users Claim Windows Patch Causes Blue Screen of Death

Users are reporting that Microsoft's latest Patch Tuesday release is crippling Windows XP PCs with the notorious Blue Screen of Death.   According to Computerworld , Microsoft's support forum... More >

February 10, 2010

Delays May Shelve Europe's SIS System Update

According to V3.co.uk , delays in updating a government database used for national security across Europe threatens to shelve plans to overhaul the system.   The Schengen Information System (... More >

Astaro Offers Basic UTM Software for Free

In an effort to address a growing desire for greater flexibility, lower cost and lower risk investments, unified threat management vendor Astaro has modified the way it licenses and sells its securi... More >

Encryption Vendor Sues Tech Giants for Patent Infringement

Encryption vendor TecSec is suing several large tech vendors , including IBM, Sun Microsystems, Cisco Systems and Oracle, for patent infringement, according to Computerworld .   TecSec alleges ... More >

Microsoft's Patch Tuesday: 26 Holes Patched in 13 Bulletins

This month's Patch Tuesday from Microsoft included 13 security bulletins addressing 26 vulnerabilities in Windows and Office.   InformationWeek reports that Andrew Storms, director of security... More >

February 9, 2010

Kaspersky: China Source of Most Malware in January

According to research by Kaspersky Lab, China was the source of most of the malware sent in January. SC Magazine reports that China was responsible for 36.2 percent of malware infecting the Inter... More >

Reseller Sentenced for Selling Phony Cisco Routers

Yongcai Li (aka Michael Lee) has received a 2 1.2-year prison sentence following an investigation by the FBI into counterfeit computer equipment.   According to V3.co.uk , Li sold counterfeit ... More >

Happy Safer Internet Day!

Security experts are using the European Union's annual Safer Internet Day initiative to renew warnings about online fraud and malware, especially on social-networking sites. According to V3.co.uk ... More >

Adobe Issues Apology for 16-Month-Old Flash Bug

Adobe Systems has apologized for failing to patch a 16-month-old bug in Flash Player, according to Computerworld .   The bug was first reported on Sept. 22, 2008, by security researcher Matthe... More >

Poughkeepsie, N.Y., Victim of Security Breach

The town of Poughkeepsie, N.Y., is the latest victim of a security breach in which $378,000 was stolen from the town's TD Bank NA account, Computerworld reports. Nine attempts to steal money were... More >

February 8, 2010

Smart Grid Security Investments to Increase

According to Pike Research, annual spending on smart grid cyber security will more than triple, reaching $3.7 billion in 2015. InformationWeek reports that there are a number of activities driving... More >

New Printer Security Solution from Ricoh

To help companies monitor printer use and protect access to sensitive documents, printer manufacturer Ricoh has unveiled a new document security solution, V3.co.uk reports.   The Flex Secure ... More >

China Shuts Down Hacker Training Site

China's state-run Xinhua news agency has reported that three people have been arrested on suspicion of selling hacking tools online.   According to The Wall Street Journal , their business was ... More >

February 5, 2010

Websense: Users Putting Too Much Faith in Search Results

According to Websense's latest "State of Internet Security" report, users are falsely putting faith in the security of search results .   V3.co.uk says the report shows almost 14 percent of se... More >

EPIC Wants Info on Google-NSA Partnership

The Electronic Privacy Information Center wants details on the partnership between Google and the National Security Agency, so it has filed a Freedom of Information Act (FOIA) request with the Nati... More >

Hacker Pleads Guilty to VoIP Attacks

Edwin Pena has pleaded guilty to hacking into several VoIP networks between 2004 and 2006 and then reselling millions of stolen minutes. According to Computerworld , Pena is scheduled to be senten... More >

February's Patch Tuesday to See 13 Security Updates

On Tuesday, Feb. 9, Microsoft will release 13 security updates patching more than two dozen vulnerabilities in Windows and Office, reports Computerworld .   Five of the updates are considered... More >

February 4, 2010

Trusteer: Two-Thirds of Users Reuse Online Banking Credentials

Making work easier for cyber criminals, a Trusteer report found that two-thirds (73 percent) of internet users use their online banking credentials on other Web sites. Forty-seven percent use their... More >

McAfee Gives SMBs a Quickstart

V3.co.uk reports that McAfee's new platform, called Security Quickstart, offers a combination of management and training for SMBs. The offering provides training, software support and consulting s... More >

Leaked Data a Boon for Cyber Criminals

According to fraud database firm Lucid Intelligence, since 2007 incidences of personal data being stolen and sold online have jumped 230 percent , reports V3.co.uk .   Although the number of ... More >

Researcher Slams Verisign for Not taking Action Against Malicious Sites

Andrew Fried, CEO of security consultancy Deteque and a former senior special agent with the U.S Department of the Treasury, says Verisign is failing to take action against dozens of sites that he ... More >

Microsoft Warns of Another Flaw in IE

Microsoft is warning about another flaw in Internet Explorer that could result in unauthorized disclosure of information for users running its browser on older operating systems, reports CNET News... More >

Google Teams up With NSA

According to The Wall Street Journal , Google is working with the National Security Agency to investigate the cyber attacks that Google announced publicly last month.   As Reuters notes, th... More >

Researcher Demos How to Get Around Oracle Database Security

At the Black Hat conference, David Litchfield, a researcher at NGS Consulting, demonstrated how to subvert security in the Oracle 11g database by taking advantage of zero-day vulnerabilities that c... More >

February 3, 2010

Researcher Hacks TPM Chip: 'There's Nothing I Can't See'

Christopher Tarnovsky, a researcher at Flylogic Engineering, claims he has hacked an Infineon SLE 66 CL PC processor that is used to protect computers, smartcards and even Microsoft's Xbox 360 gami... More >

Intelligence Official Warns Lawmakers of U.S. Terror Attack

The New York Times reports that Dennis C. Blair, the director of national intelligence, has warned lawmakers that Al Qaeda and its affiliates will likely attempt a large-scale attack on American s... More >

Cyber Thieves are Advertising Online for Contractors

Kevin Stevens, a threat intelligence analyst for SecureWorks, says cyber thieves are starting to advertise online for contractors.   According to Reuters , they are looking for people who are... More >

TrustWave: Old Security Flaws Still a Major Threat

According to a report by TrustWave, companies are so busy chasing down the latest vulnerabilities that they are overlooking the most common, frequently exploited ones. As a result, companies continu... More >

Apple Patches Five Bugs in iPhone OS

Computerworld reports that Apple has patched five vulnerabilities in the iPhone's operating system.   According to PCWorld.com , the five security fixes are for CoreAudio, ImageIO, Recovery... More >

February 2, 2010

Connecticut Attorney General Sues Health Net

According to InformationWeek , Health Net is facing a lawsuit by the Connecticut attorney general for failing to adequately protect the medical records of hundreds of thousands of customers whose ... More >

Possible Phishing Attack Forces Some Twitter Users to Reset Password

A possible phishing attack has Twitter locking some users out of their accounts and asking them to reset their passwords, according to a TechCrunch article in The Washington Post.   The messa... More >

Researcher: Adobe Not Entirely Responsible for Flash Risk

According to a security researcher, Adobe's Flash technology is at risk, but it's not entirely Abode's fault.   eSecurity Planet reports that Senior Foreground Security analyst Mike Bailey's re... More >

MI5: China Hacks UK Businesses

V3.co.uk reports that MI5 is warning UK companies that the Chinese government may have used computer devices that contain Trojan software to gain access to their computers with the goal of remotel... More >

Pushdo Targets Web Sites With Junk SSL Connections

Computerworld reports that the Shadowserver Foundation is warning that hundreds of Web sites are being pestered by computers infected by the Pushdo (aka Pandex or Cutwail) botnet. Among the sites ... More >

February 1, 2010

Sophos: Significant Rise in Social Networking Spam, Malware

A Sophos investigation shows that more than half the users of social networking have been sent spam over the site, while more than a third have received malware.   SC Magazine reports that duri... More >

Iowa Gaming Commission Confirms Attack on Server

The Iowa Racing and Gaming Commission has confirmed that a hacked server has exposed about 80,000 names , birth dates and Social Security numbers for casino and racetrack employees in Iowa, says SC... More >

Google to Pay Bounty for Chrome Vulnerabilities

Google says it will pay researchers $500 for each vulnerability they find in the Chrome browse r and its underlying open source code, reports Computerworld . "Particularly severe or particularly c... More >

UK Has No Plans to Switch from IE6

According to The Register , the UK government is not at all concerned about the safety of Microsoft's Internet Explorer 6.   France and Germany have issued warnings against using IE 6 follow... More >

Data Center Management

Indispensable technologies and best practices to maintain your organization's most valuable asset.

Database Management

Data management tips and techniques that insure ease of access, comprehensive security and absolute privacy for your invaluable company information.

Application Performance Management

Application delivery and performance tools for Web applications to insure high availability and productivity.

Service Oriented Architecture (SOA)

Service-Oriented Architecture is the catalyst that allows today’s companies to respond to business demands faster and more effectively than ever.