Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments
  • IT Careers

Previous Next

Security

March 2010

March 31, 2010

Mozilla Patches Older Firefox Browsers

Mozilla has patched 10 vulnerabilities in its older browsers, six of which are rated as "critical" and could be used by attackers to run malicious code on a compromised machine.   According to ... More >

Journalists' Yahoo Accounts Hacked in China; Google Properties Blocked?

According to The Associated Press , it appears that the Yahoo e-mail accounts of at least three journalists and an analyst have been hacked . However, PCWorld.com puts the number closer to eight... More >

March 30, 2010

Ukranian Man Ordered to Pay for Insider Trading Hack

Oleksandr Dorozhko , a Ukrainian energy engineering consultant, has been ordered to pay $580,000 for allegedly "hacking into computer networks or otherwise obtaining electronic access to systems" tha... More >

Research: EMR Fraud to Increase

A study by Javelin Strategy & Research shows that there were more than 275,000 cases of medical information theft in the United States last year. According to InformationWeek , the report foun... More >

Microsoft to Issue Emergency Patch for IE Zero-Day

Microsoft today says it will issue an out-of-band security update tomorrow for the zero-day vulnerability affecting Internet Explorer, reports Computerworld .   Microsoft issued a warning abo... More >

Study: Limiting Admin Rights Mitigates Windows Security Vulnerabilities

According to a report by BeyondTrust, 90 percent of critical Microsoft Windows 7 vulnerabilities can be mitigated by slashing administrator rights, reports CNET News . Adjusting administrator righ... More >

Apple Issues Monster Security Update for Leopard, Snow Leopard

Computerworld reports that Apple has issued a huge security update, patching 92 vulnerabilities in its Leopard and Snow Leopard operating systems. A third of the patches are accompanied by the phr... More >

March 29, 2010

Survey: CEOs See Security as Top Priority

eSecurity Planet reports that, according to an IBM-sponsored study conducted by the Ponemon Institute, 76 percent of the 115 C-level execs surveyed said that they now see reducing potential security... More >

ZeuS Hides Behind Phoney IRS Documents

Sans researcher Kevin Liston is warning of unsolicited e-mail claiming to come from the U.S. Internal Revenue Service that attempts to spread the ZeuS malware.   According to V3.co.uk , the e... More >

Microsoft Defends Windows 7 Security Measures

Just days after researchers in the annual Pwn2Own contest outwitted major Windows 7 defenses to exploit Internet Explorer and Firefox, Microsoft defended its security measures , saying they are an e... More >

Military Warns of Cyber Threat From China

Appearing before the U.S. House Armed Services Committee, Navy Adm. Robert Willard offered a strong warning about cyber threats posed by China , reports Computerworld : U.S. military and government... More >

Symantec: Rustock Botnet Using TLS Encryption to Push Spam

Symantec's MessageLabs is reporting a surge in spam being sent by the notorious Rustock botnet using Transport Layer Security (TLS) encryption. According to PCWorld.com , two weeks ago, spam encry... More >

Student Loan Company Admits Theft of 3.3 Million Borrowers' Data

In what is being called the largest data breach ever, The Wall Street Journal reports that during the weekend of March 20-21, the names, addresses, Social Security numbers and other personal data o... More >

March 26, 2010

Symantec: China Epicenter of Malware

According to a report by Symantec, most of the targeted malware distributed this month came from China even though most of the e-mail servers used to push the scams were physically located in the U... More >

Twitter Hacker Claims Hack Wasn't Malicious

A 23-year-old unemployed Frenchman who is accused of hacking Twitter systems and distributing corporate data says that his actions were not malicious .   V3.co.uk quotes François Cousteix, who... More >

Cisco Issues IOS Security Advisory

Cisco has issued a security advisory addressing 11 flaws that could leave its IOS networking software vulnerable to remote code execution and denial-of-service attacks, reports V3.co.uk .   Th... More >

Hacker Gonzalez Sentenced to 20 Years

InformationWeek reports that a U.S. federal court in Boston has sentenced hacker Albert Gonzalez to 20 years in prison and $25,000 in fines for his role in the security breaches of Barnes & No... More >

Dave & Buster's Settles FTC Complaint over Breach

Dave & Buster's has settled a Federal Trade Commission complaint that the company left consumers' credit and debit card information vulnerable to hackers, reports The Dallas Morning News . &nbs... More >

March 25, 2010

Stolen Computer Puts Vanderbilt Students' Data at Risk

A stolen desktop computer from a Vanderbilt University professor's locked office last month has put 7,174 current and former students' personal information at risk .   According to eSecurity P... More >

Google to Notify Users of Fraudulent Logins

In an attempt to reduce spam and cyber crime, Google says it will notify Gmail users of any fraudulent activity on their accounts. According to V3.co.uk , the search giant will not only provide de... More >

Twitter Claims It's Winning War on Bad Tweets

Twitter boasts that it has slashed spam levels from nearly 11 percent of tweets in August 2009, to less than 1 percent by February of this year, according to V3.co.uk .   Twitter has been pla... More >

Experts Meet on Cyber Crime Strategies

Computerworld reports that more than 300 experts met at the Council of Europe's conference on cyber crime to discuss the 2001 Convention on Cybercrime treaty and ways to foster better cooperation.... More >

iPhone, Safari, IE 8, Firefox Fall in Day One of CanSecWest Contest

As expected, Apple's iPhone and Safari browser, Microsoft's Internet Explore 8 and Mozilla's Firefox were taken down in minutes by hackers at this year's Pwn2Own contest , reports Computerworld . ... More >

March 24, 2010

Secunia Launches Patch Management Utility

A new patch management tool from Secunia checks almost 13,000 applications from more than 2,300 vendors for unpatched vulnerabilities, V3.co.uk reports.   Corporate Software Inspector 4.0 int... More >

New Hosted Web Security Service from Symantec

Symantec is offering a new security service aimed at protecting companies from Web-based attacks.   V3.co.uk says Symantec's new Web Security Monitoring service offers round-the-clock protect... More >

Reporting Service Hopes to Tackle Mobile Spam

Messaging security firm Cloudmark and the GSM Association (GSMA) have announced a worldwide trial to combat the growing problem of mobile spam.   According to V3.co.uk , the GSMA Spam Reportin... More >

IE Attacks More Widespread, Warn Security Companies

Security researchers are warning that an unpatched flaw in Microsoft's Internet Explorer browser is not just being used in targeted attacks anymore. Instead, the exploits are much more widespread ... More >

FBI Official Warns That Cyber Attacks Are 'Existential Threat'

Steven Chabinsky, deputy assistant director of the FBI's cyber division, issued an ominous warning about cyber attacks during a presentation at the FOSE government IT trade show.   According t... More >

March 23, 2010

McAfee Announces New Data Loss Prevention Package

V3.co.uk reports that McAfee has unveiled its McAfee Data Loss Prevention , a new enterprise package aimed at helping companies reduce the risk of data loss.   McAfee says the package can be f... More >

Mozilla Bumps up Firefox 3.6.2 Update

Just days after Mozilla confirmed a critical vulnerability in the latest version of Firefox, the company has decided to push out the update a week earlier than expected , reports V3.co.uk .  ... More >

Symantec Lists 50 Riskiest U.S Cities for Cyber Crime

In an effort to study and rank the nation's riskiest cities for cyber crime, Symantec has released a report that lists the top 50 American cities that are most vulnerable to cyber attacks, Compute... More >

Security, User Interface Flaws Fixed with Opera Update

Recently, Opera has seen gains thanks to Microsoft's browser ballot. This makes the news that Opera has re-launched the latest version of its browser to fix security and user interface flaws all th... More >

March 22, 2010

Cyber Crooks Take Liking to Apple Products

Apple's iPad will likely be a prime target for credit card thieves and online scammers of all types, says The Washington Post .   A disproportionate share of the more than half a billion doll... More >

Russia Fights Scammers by Tightening Rules for .ru Domain

In an effort to combat fraud and inappropriate content, Russia is tightening its procedures for its .ru top-level domain names , according to Computerworld .   Beginning April 1, registrants f... More >

Google Releases Skipfish Security Scanner

In an effort to reduce online vulnerabilities, Google has introduced an open source automated Web security scanning program called skipfish, InformationWeek reports.   According to Help Net... More >

Security Expert to Disclose 20 Holes in Mac OS X

According to The H Security , security expert Charlie Miller plans to disclose 20 zero-day security holes in Apple's Mac OS X at the Canadian CanSecWest security conference. He will not reveal det... More >

March 19, 2010

3,000 HTC Magic Phones Infected with Malware

Following a second instance of the now defunct Mariposa botnet being found on an HTC Magic phone, Vodafone now says as many as 3,000 HTC Magic phones may have malware-tainted memory cards, accord... More >

Google Patches 11 Bugs in Chrome

Just days before the Pwn2Own browser hacking contest is to kick off in Canada, Google has patched 11 vulnerabilities in the Windows version of Chrome, reports Computerworld . Six of the flaws are ... More >

March 18, 2010

FCC Gets Bigger Cyber Security Role with Broadband Plan

According to Computerworld , the National Broadband Plan contains several recommendations that are designed to promote cyber security .   The plan gives the FCC a greater role in creating ... More >

Fired Worker Blamed for Car Immobilization Hack

Police in Austin, Texas, have arrested Omar Ramos-Lopez, a former Texas Auto Center employee, for allegedly exploiting a system used by auto dealers to immobilize the vehicles of people behind with t... More >

Phishers Targeting Facebook Users Again

CNET News reports that McAfee is warning Facebook users about a new phishing scam .   Users are sent an e-mail that appears to be from Facebook saying the company reset their password and urgi... More >

March 17, 2010

Another HTC Magic Phone Plagued with Malware

According to security company Panda, there has been another instance of traces of the now defunct Mariposa botnet being found on an HTC Magic phone. NetworkWorld reports that the malware was agai... More >

Hacker Sued for Allegedly Manipulating Stock Prices

The U.S. Securities and Exchange Commission has accused Valery Maltsev of illegally manipulating share prices by stealing the login credentials of people’s online trading accounts, reports V3.co.u... More >

Researchers Warn of Microsoft Virtual PC Security Hole

Core Security Technologies warns that an unpatched weakness in Microsoft's Virtual PC could leave companies vulnerable.   According to CNET News , the hole could allow an attacker to bypass v... More >

March 16, 2010

Trusteer Offers Malware Forensic Tool for Banks

Computerworld reports that Trusteer has launched a new service designed to allow banks to remotely investigate their customers' computers if it is believed that the PC has been hacked.   The se... More >

McAfee Aims to Allay Cloud Security Fears

In a move that aims to give cloud-computing service providers a way to provide security assurances to their customers, McAfee has announced a vulnerability-assessment scanning service, reports Netwo... More >

March 15, 2010

Free Security Test Tool from Jericho Forum

In an effort to help companies and vendors assess the effectiveness of their security products, IT security group the Jericho Forum is offering a new Self-Assessment Scheme .   According to V3... More >

Man Sentenced for Role in TJX Attacks

Computerworld reports that former Barclays Bank programmer Humza Zaman has been sentenced to four years in prison for his role in the data thefts at TJX Companies Inc. He has also been ordered to ... More >

Microsoft Testing Patch for IE Bug

According to Computerworld , Microsoft is testing a patch for a critical vulnerability in Internet Explorer. Microsoft disclosed the vulnerability in last week's Patch Tuesday release.   Wh... More >

Opposition Web Sites Hacked in Iran

Iran's semi-official Fars News Agency has reports that Iran's Islamic Revolutionary Guards Corps has hacked into 29 Web sites associated with U.S. espionage networks , according to Computerworld . ... More >

March 12, 2010

Estonian Man Jailed for Launching DoS Attack

V3.co.uk reports that Artur Boiko has been sentenced to two years and seven months after being found guilty of creating the Allaple malware to launch a DDoS attack on a local insurance company. &n... More >

Symantec: New Spam Threat Could Overwhelm Corporate Servers

Symantec warns that business networks could be overwhelmed by new trend in spam in which messages are sent via the Transport Layer Security protocol, reports V3.co.uk .   The problem, accordi... More >

.org Domains to Get Tighter Security

Come June, the Public Interest Registry plans to add an extra layer of security known as DNS Security Extensions (DNSSEC) to the .org domain .   Computerworld reports that DNSSEC will be suppo... More >

Zeus Botnet Adds New Capabilities

According to Computerworld , there's a new Zeus toolkit out that promises new capabilities for strengthening the botnet.   Don Jackson, director of threat intelligence at SecureWorks, says Ze... More >

Apple Patches 16 Holes in Safari

Apple's new released Safari 4.0.5 addresses 16 vulnerabilities . According to The H Security , six of the flaws just affect Windows versions of Safari, while the other 10 affect both Mac OS X and W... More >

March 11, 2010

Arkansas National Guard Hard Drive Missing

The Arkansas National Guard has lost an unencrypted backup storage drive that contained the names, Social Security numbers and other unspecified personal information of more than 35,000 guardsmen, ... More >

Webroot: Beware of Fake Windows Update

Internet users should be on the lookout for a malware attack disguised as an official Windows update , warns security firm Webroot.   V3.co.uk says the attack seems to be related to a number o... More >

F-Secure: Adobe Reader Most Exploited Software

Adobe Reader has the unflattering distinction of taking first place as the software most often exploited in targeted attacks.   Computerworld reports that F-Secure says 61 precent of the near... More >

HSBC Admits Data Theft Bigger Than Originally Thought

According to Computerworld , HSBC has admitted that about 15,000 accounts of its Swiss private banking unit may have been compromised after an employee allegedly stole data. HSBC originally put th... More >

Researcher Publishes IE Zero-Day Exploit Code

Computerworld reports that Israeli researcher Moshe Ben Abu has published exploit code for the unpatched Internet Explorer bug that Microsoft disclosed earlier this week as part of its Patch Tue... More >

Former TSA Employee Charged with Computer Tampering

Reuters reports that a former Transportation Security Administration employee has been charged with trying to corrupt a U.S. security database that holds sensitive information used for screening a... More >

March 10, 2010

Drudge Serving up Malware?

Visitors to the Drudge Report are claiming that they got malware after visiting the site. Matt Drudge denies that his site was infecting visitors, but CNET News claims a visitor to the site has pro... More >

Symantec Previews Next-Gen Mobile Security Solution

Symantec is showing off a prototype for what the company calls a next-generation solution to mobile security developed by its research labs.   According to eSecurity Planet , Symantec Mobile R... More >

Secunia: Confusion About Opera Bug Could Hurt Security Efforts

Secunia says that conflicting reports about the severity of a newly reported Opera flaw could be harming efforts to mitigate the threat, according to V3.co.uk . Carsten Eiram, chief security spe... More >

Twitter Launches Link-Screening Service

In an effort to cut down phishing and other malicious attacks, Twitter has launched a link-screening service . Computerworld reports that the service includes a Twitter tool to shorten URLs. Users... More >

Malware Found on HTC Magic Phone

According to Computerworld , Panda Security is investigating how three malware programs got on a recently purchased HTC Magic phone that belonged to a Panda employee.   The phone contained a ... More >

Patch Tuesday Fixes Eight Flaws, Warns of IE Bug

Microsoft's March Patch Tuesday releases saw only two bulletins patching eight vulnerabilities. According to InformationWeek , both bulletins, which affect  Windows Movie Maker and all versions of M... More >

March 9, 2010

Security Mechanisms Inherently Flawed, Say Researchers

According to V3.co.uk , researchers at Cambridge and Edinburgh universities say the security mechanisms used to protect online accounts are inherently flawed .   The paper entitled "What's in ... More >

Apache Patches Critical Flaw

Help Net Security reports that Brett Gervasoni, a researcher and consultant with Sense of Security Labs, has discovered a serious vulnerability in Apache's HTTP Web server . The flaw allows an atta... More >

McAfee Warns of Fake Anti-Virus Scams

According to V3.co.uk , McAfee is using its first Consumer Threat Alert to warn Web users of the dangers of fake antivirus scams .   Not only should users be on the lookout for bogus ads that ... More >

IBM to Pair Technologies for Secure Software Development

Computerworld reports that IBM is making use of two acquisitions to offer an enterprise-level product for security testing and code scanning .   The product will feature Rational AppScan testi... More >

Opera Working on Patch for Critical Browser Bug

Opera is working on a patch for a critical vulnerability in its Windows desktop browser.   According to Computerworld , attacker can exploit the bug, which affects Opera 10, to corrupt memory... More >

Citibank Exposes Thousands of Customers' Social Security Numbers

According the Chicago Tribune , Citibank mistakingly mailed year-end tax statements to 600,000 customers with their Social Security numbers printed on the outside of the envelope . Citi is blaming ... More >

March 8, 2010

Phishers Casting Wider Net, Reeling in High-Value Targets

The Anti-Phishing Working Group's latest phishing activity report shows that phishers are targeting smaller prey and are getting more skillful at accessing the credentials of high-value targets. &nb... More >

RSA: Phishing Attacks Set Record in January

According to security vendor RSA, January saw a 21 percent increase in phishing attacks over the month before.   Fast-flux attacks, in which phishing sites are masked by a constantly changing ... More >

Thai Court Approves Hacker's Extradition to U.S.

A court in Thailand has approved the extradition of a Malaysian man to the United States for his alleged involvement in hacking credit card information, according to an IDG article in The New York... More >

Energizer Software Contains Trojan

The Department of Homeland Security's US-CERT is warning about software that accompanies the Energizer DUO USB battery charger. Computerworld reports that the software contains a Trojan horse tha... More >

March 5, 2010

MobileSitter: A Novel Password Storage Application

MobileSitter , from Germany's Fraunhofer Institute for Secure Information Technology, offers a novel feature over other password-storage applications.   According to Computerworld , the mobile ... More >

Veracode: Half of Business Apps Insecure

According to a study by code-testing company Veracode, 58 percent of software submitted to Veracode for testing is susceptible to application layer attacks . The number jumps to 88 percent when meas... More >

FBI Embeds Agents to Crack Down on Cyber Crime

In an effort to catch cyber criminals, the FBI has started to embed agents with law enforcement agencies in Estonia, the Ukraine and the Netherlands, Computerworld reports. Jeffrey Troy, chief of... More >

Microsoft to Patch 8 Windows, Office Bugs

This month's Patch Tuesday from Microsoft will see two bulletins fixing eight vulnerabilities rated "important" in Windows and Microsoft Office products, according to CNET News .   Computerwo... More >

March 4, 2010

Ponemon: Financial Services Firms Lacking Security

A survey by the Ponemon Institute of 80 large financial firms revealed that poor operating practices leave companies vulnerable to breaches that could expose sensitive data or put customers' and em... More >

Microsoft Proposes Kicking Malware-Infected PCs Off Internet

Should malware-infected PCs be kicked off the Internet? eSecurity Planet reports that Microsoft thinks so, according to Scott Charney, corporate vice president of Trustworthy Computing at Microsof... More >

McAfee Forms Real-Time Threat Response Group

According to V3.co.uk , McAfee has created the Vulnerability Detection and Response Group , which will offer help and advice to organizations about emerging threats.   According to McAfee, the... More >

Spam Filters Sail Through Virus Bulletin Test

Virus Bulletin's latest spam test showed that all 16 products tested passed the test and earned the VB certification, V3.co.uk reports.   Spam filters were put up against more than 250,000 le... More >

EMC, Intel, VMware Join Forces for Cloud Computing Security

This week's RSA Conference saw the announcement of a partnership between EMC, Intel and VMware to improve security and regulatory compliance in cloud computing, according to a Network World story... More >

Damballa: Google Attacks Perpetrated by Amateurs

Security company Damballa says the now infamous Google attacks were carried out by “amateur-level” botnets.   According to eWEEK , researchers were able to trace the botnet's activity back to J... More >

Government Launches Cyber Security Awareness Contest

Looking to get ideas from individuals and industry about how to best engage the American public in a discussion about cyber security, Secretary of the Department of Homeland Security Janet Napolitano... More >

March 3, 2010

Microsoft Re-Releases Windows Patch

Last month, Microsoft yanked a Windows patch that users were claiming caused the so-called Blue Screen of Death.   Following an investigation, Microsoft determined that a rootkit, known as ... More >

RSA: Anti-Virus, Encryption Failing

Experts at the RSA 2010 conference are warning that the effectiveness of traditional anti-virus and encryption systems is failing , V3.co.uk reports.   Even though current successful detect... More >

Spanish Police Arrest Three in Takedown of Mariposa Botnet

Three men that were behind the Mariposa botnet have been arrested by Spanish authorities, according to Computerworld .   In December, a group of volunteers calling itself the Mariposa Working ... More >

Survey: 5.8 Percent of U.S Adults Victims of Medical ID Theft

Financial resources are not the only thing identity thieves are interested in going after. They are also after medical identification data and services, reports Computerworld .   According to a... More >

March 2, 2010

Microsoft Advisory for latest IE Exploit

V3.co.uk reports that Microsoft has issued a security advisory for an unpatched vulnerability in VBScript that could allow hackers to plant malware on Windows XP machines running Internet Explor... More >

Cisco Offers Security Without Borders

NetworkWorld reports that Cisco has announced an initiative known as Secure Borderless Network architecture . The intiative is being described as an "always on" security protection for mobile devic... More >

Lockheed Martin to Open New Internal Security Intelligence Center

In an effort to better predict and protect against increasingly sophisticated cyber attacks, Lockheed Martin is opening a second internal security intelligence center in Denver, Reuters reports. ... More >

Cloud Security Alliance Lists Top 7 Cloud Threats

The Cloud Security Alliance conducted a security study identifying the “seven deadly sins” of cloud computing. Among the top seven threats , according to GCN , are:   Malicious Insiders -- Th... More >

New Security Features for Google's Gmail?

According to a TechCrunch article in The Washington Post, Google is expected to roll out some new security features for Gmail that will cut down on phishing and hacking.   One possible chang... More >

March 1, 2010

Upcoming Census May Bring Scams, Warns Symantec

Certainly, cyber criminals take advantage of current events to dupe users. InformationWeek reports that Symantec is warning users to be on their guard against scams to steal personal information wh... More >

Trojan Pushes Rogue Microsoft Security Essentials

According to eSecurity Planet , a Trojan is masquerading as Microsoft's popular free Microsoft Security Essentials package. The rogue security tool goes by the name Security Essentials 2010.  ... More >

More Than 100 Companies May Have Been Victims of Google Attack, iSEC Says

Security vendor iSEC Partners estimates that more than 100 companies were affected by the Google attack two months ago, reports PCWorld.com . However, as iSEC's Alex Stamos notes, the resemblance... More >

Grum and Rustock Botnets Push Spam to New Levels

Symantec says the Grum and Rustock botnets have pushed spam levels up by 5 percent in February, reports V3.co.uk .   A report from Symantec Hosted Services shows that the Grum botnet had a 51... More >

Wyndham Hotels Attacked By Hacker

Hackers have stolen sensitive customer data from the computer systems of Wyndham Hotels & Resorts .   According to Computerworld , the incident occurred between late October 2009 and Janua... More >

Microsoft Investigates Zero-Day IE Flaw

According to Computerworld , Microsoft is investigating an unpatched vulnerability in VBScript that could allow hackers to plant malware on Windows XP machines running Internet Explorer.   Ma... More >

Application Infrastructure

Learn more about this middleware layer that pools and dynamically provisions infrastruction application delivery resources to lower costs and improve efficiency.

Business Intelligence for Business People

Practical and timely business information for better decisions and improved organizational performance.

NAS & SAN Storage

Oracle offers a complete portfolio of best-of-breed storage products and business-ready storage solutions that optimize performance, maximize data protection and reduce the total cost of ownership for Oracle databases, applications, and heterogeneous data management.

Service-Oriented Architecture (SOA)

Service-oriented architecture is the catalyst that allows today's companies to respond to business demands faster and more effectively than ever.