Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments
  • IT Careers

Previous Next

Security

April 2010

April 30, 2010

Google Fixes More Chrome Bugs

Google has patched three vulnerabilities rated "high" in the Windows version of its Chrome browser, after fixing seven flaws a week ago, reports The H.   The flaws were labeled with the second... More >

Microsoft Warns of SharePoint Vulnerability

Microsoft issued an advisory late Thursday warning customers of a zero-day vulnerability affecting SharePoint, reports SearchSecurity.com .   It affects SharePoint Server 2007 and SharePoint... More >

April 29, 2010

McAfee: PDF Exploits Skyrocketing

According to Computerworld , Toralv Dirro, a security strategist with McAfee Labs, says exploits of Adobe's PDF format continue to rise in 2010 .   In 2007 and 2008, just 2 percent of all malw... More >

April 28, 2010

Google: Huge Rise in Fake Anti-Virus Scams

According to Google researchers, fake anti-virus software now makes up 15 percent of all online malware . Moreover, it is responsible for 50 percent of all malware sent by advertising, which is a fi... More >

Linux Computers More Likely to Send Spam?

According to the latest MessageLabs Intelligence Report from Symantec Hosted Services, users are five times more likely to get spam from Linux-based computers than Windows PCs, relative to market s... More >

McAfee Offers Business Customers Security Review for Buggy Update

Following its announcement that it would reimburse consumer customers for "reasonable expenses" they have incurred as a result of a f aulty anti-virus update , McAfee says it will provide its bus... More >

SF Network Admin Found Guilty

A jury has found the network administrator accused of locking top administrators out of San Francisco's new computer system guilty of one felony count of denying computer service.   According ... More >

April 27, 2010

Cellcrypt Offers Secure Mobile-to-Office Voice Calling

Cellcrypt announced the availability of its high-strength government-grade encryption application for mobile devices. Enterprise Gateway, which Cellcrypt says enables business executives to securely... More >

April 26, 2010

Stolen Laptop Exposes Data on 3,500 Patients

eSecurity Planet reports that a stolen physician's laptop has put data on more than 3,500 patients who received care at the Massachusetts Eye and Ear Infirmary at risk.   The laptop belonged ... More >

BitDefender Uncovers Malware that Targets iPad

BitDefender is warning iPad users about an e-mail-borne threat that could give hackers unauthorized access to the device.   V3.co.uk reports that the threat comes via an unsolicited e-mail tel... More >

NetGear Rolls Out New ProSafe Firewall

Computerworld reports that Netgear has rolled out the ProSafe Quad WAN Gigabit SSL VPN Firewall , a firewall appliance aimed at the small- to medium-sized business.   The appliance boasts a sp... More >

McAfee to Reimburse Consumers for Buggy Update

Following the recent McAfee update fiasco , the company says it will reimburse its consumer customers for "reasonable expenses" they have incurred as a result of last week's faulty antivirus updat... More >

Blippy Leaks Fifth Credit Card

Just a day after we reported on our Network Security Edge site that Blippy confirmed that four users' credit card numbers were found via Google, the social website has confirmed that a fifth use... More >

April 23, 2010

Survey: SMBs Lackadaisical About Protecting Data

A survey by Panda Security shows that the lackadaisical efforts by small and midsized businesses to protect consumer data makes them a prime target for cyber thieves. eSecurity Planet reports that, ... More >

Microsoft to Fix Faulty Server Patch

According to V3.co.uk , Microsoft is working on an update for a recent security patch for Windows 2000 Server , which released last week as part of this month's Patch Tuesday package .   Ther... More >

Scammers Piggybacking on McAfee Update Fiasco

A buggy McAfee update has scammers swarming.   According to Computerworld , scammers are using their now-traditional technique of poisoning search results, pushing links promoting fake antiv... More >

For Sale: 1.5 Million Stolen Facebook IDs

Researchers at VeriSign's iDefense group have discovered a hacker named Kirllos selling 1.5 million stolen Facebook IDs at rock-bottom prices , according to an IDG News Service article in The New ... More >

April 22, 2010

Survey: Hacking Attempts Double in Two Years

According to PricewaterhouseCoopers' latest biennial Information Security Breaches Survey, nearly two thirds of companies say there have been attempts to break into their networks in the past year,... More >

Buggy McAfee Update Takes Down Windows XP PCs

A buggy update for McAfee's popular antivirus software caused tens of thousands of Windows XP computers to crash or repeatedly reboot.   According to CNET News , the update caused Windows XP c... More >

April 21, 2010

Top 10 Web App Security Risk List Released

The Open Web Application Security Project has released a new version of its Top 10 list of critical Web application security risks .   SC Magazine reports that, according to OWASP, SQL injecti... More >

Spammers Targeting Legitimate Gmail Accounts?

According to Computerworld , Google is looking into reports that hackers are breaking into legitimate Gmail accounts and using them to send spam messages.   Gmail users say hackers appear to ... More >

April 20, 2010

McAfee, Adgregate Target Malvertisers

eSecurity Planet reports that McAfee is teaming with Adgregate Markets, a provider of distributed e-commerce applications, in an effort to root out malware-laden ads and bolster online sales. &nbs... More >

Certegy Reaches Settlement in Florida Data Breach Incident

Following a data breach that exposed more than 5.9 million customer files, Certegy Check Services has reached an agreement with the Florida Attorney General's office that calls the company to drama... More >

Beware of New Mac OS X Malware

According to V3.co.uk , security experts at Intego are warning users to be vigilant following the discovery of a malicious 'HellRTS' tool that targets Mac OS X . A proof-of-concept sample has been ... More >

Google Attack Hits Password System

According to The New York Times , included in the information stolen from Google during Internet attacks in December is a password system, code-named Gaia , that controls access by millions of user... More >

Minneapolis Police Recover Student Loan Data

The Minnesota Department of Safety says it has recovered the missing data of borrowers with the Educational Credit Management Corp. The incident was believed to be the largest-ever case of student-l... More >

April 19, 2010

Trend Micro: New Trojan Threatens Blackmail

A new Trojan spreading from Japan threatens to post the Internet history of infected users, warns security experts from Trend Micro.   V3.co.uk reports that the Kenzero Trojan disguises itsel... More >

April 16, 2010

Google: Spam Volumes Grow, Botnets Responsible

According to Google's e-mail filtering division Postini, there was a 6 percent increase in the volume of unsolicited e-mail in the first quarter compared to a year earlier, reports PCWorld.com . &... More >

Oracle Patches Critical Java Vulnerability

According to Computerworld , Oracle has issued a patch for a critical Java vulnerability.   As we reported on our Network Security Edge site, Google researcher Tavis Ormandy notified Oracle... More >

China Host to Millions of Conficker Infections in 2009

According to a recent annual security report posted on the Web site of China's National Computer Network Emergency Response Technical Team (CNCERT), last year China was home to more than one in four... More >

April 15, 2010

Study Finds Gaps in Federal IT Execs, Staff Views On Cyber Security

According to a study sponsored by CA and independently carried out by the Ponemon Institute, federal IT managers and IT staff don't agree when it comes to their evaluations of the federal governmen... More >

Hackers Exploiting Java Zero-Day Bug

As we reported on our Network Security Edge site, Google researcher Tavis Ormandy decided to publish details about a Java virtual machine bug that attackers could use to run unauthorized programs... More >

Apple Releases Security Update for Leopard, Snow Leopard

Apple has released a security update for users of Mac OS X 10.5 Leopard and 10.6 Snow Leopard that fixes a single vulnerability , according to PCWorld.com .   Security Update 2010-003 for Snow... More >

April 14, 2010

Study: Almost Half of Publicly Disclosed Breaches Don't Include Number of Records Compromised

According to a press release from Perimeter E-Security, almost half of publicly disclosed data breaches do not provide the total number of records compromised. The information comes from the compan... More >

Criminals Targeting Unemployed with Phony Jobs

According to The Wall Street Journal , criminals are preying on U.S. job seekers with so-called mule operations. The article explains:   Cybercriminals post an ad on a job board. Successful j... More >

Facebook Combats Hackers with Legal, Technical Means

Facebook is using legal means in combination with technical measures in order to halt hackers from abusing the site.   The company has beefed up its security team, with as many as 10 percent o... More >

Hackers Access Apache Project Server, Passwords Compromised

According to Computerworld , not only were hackers able to access a server used by the Apache Software Foundation to keep track of software bugs, but they also snagged low-privilege accounts on an... More >

April 12, 2010

Jump in First-Quarter Click Fraud Rate

Click Forensics reports that the click fraud rate for the first quarter of 2010 was one of the highest on record, according to The New York Times .The click fraud rate was 17.4 percent, compared t... More >

Trusteer Researcher Concerned About Potential for PDF Attack Wave

The PDF attack demonstrated by Belgian security researcher Didier Stevens that does not require an underlying vulnerability has Mickey Boodaei, CEO of security company Trusteer, concerned.   C... More >

Adobe Patches Bugs With New Automatic Updater Utility

As Microsoft prepares to patch 25 vulnerabilities in its April Patch Tuesday release, Adobe is set to release security updates for Reader and Acrobat via a new update system, reports Xinhuanet .... More >

Microsoft to Plug 25 Holes in April's Patch Tuesday

Tomorrow Microsoft is expected to release 11 security bulletins to patch 25 vulnerabilities across Windows, Microsoft Office and Microsoft Exchange, according to eWEEK . Five are rated as "critic... More >

April 9, 2010

Oracle Moves Sun Products to Quarterly Critical Patch Update Cycle

Oracle has confirmed it is adding Sun Microsystem's products to its quarterly patch update. There will be 16 patches in total for the Sun products, including Solaris, Sun Convergence, Sun Cluster a... More >

April 8, 2010

70 Arrested in Romanian Raids on eBay Scammers

The Romanian police and U.S. law enforcement officials have arrested 70 people in three cyber crime groups for their roles in scams targeting eBay customers, reports eWEEK .   The Romanian Di... More >

April 7, 2010

Survey: Companies Lagging on Cloud Security

According to a study released by Symantec and the Ponemon Institute, enterprises are falling behind on cloud security. Infosecurity.com reports that only 27 percent of respondents had procedures in... More >

Adobe Researching Ways to Mitigate PDF Attack

Adobe is looking into ways to mitigate a PDF attack demonstrated by Belgian security researcher Didier Stevens that does not require an underlying vulnerability .   An IDG News Service articl... More >

Researcher Demos Wormy PDF Attack

Following a recently demonstrated PDF attack by Belgian security researcher Didier Stevens that does not require an underlying vulnerability, another researcher has discovered a way to spread malic... More >

Foxit Attempts to Fix PDF Vulnerability

Computerworld reports that Foxit has patched it PDF viewer in an effort to protect users against an attack that would allow hackers to force-feed malware to users without exploiting an actual vuln... More >

April 6, 2010

Facebook Scam Targets Whole Foods Fans

According to eSecurity Planet , a new Facebook scam promises a $500 gift card to Whole Foods grocery store. But all the user really gets is their personal data exposed.   The bogus offer cons... More >

Survey: Businesses Not Protecting Most Valuable Secrets

According to a Forrester Consulting survey funded by Microsoft and RSA,  most IT departments are not investing enough in protecting their organizations' most valuable secrets . eSecurity Planet sa... More >

Apple Patches 16 QuickTime Bugs

Apple has released a security update that addresses 16 security vulnerabilities in its QuickTime software on both Mac and Windows platforms, eSecurity Planet reports.   QuickTime 7.6.6 provi... More >

Chinese Hackers Target India Secrets

According to an Associated Press article in The Sydney Morning Herald, Chinese hackers were able to access Indian national security information , 1,500 e-mails from the Dalai Lama's office and oth... More >

Vietnam Calls Cyber Attack Claims 'Groundless'

According to CNET News , Vietnam calls claims that it was involved in recent cyber attacks aimed at squelching critics of a Chinese-backed bauxite mining project in Vietnam "groundless."   As ... More >

April 5, 2010

Stanford Web Site Monitors App Security

With developers scrambling to create new apps for devices like Apple's iPad, it can be hard for users to figure out of they're safe.   According to an Associated Press article on Newsvine.com,... More >

Five Security Takeaways from SonicWall's Matt Medeiros

Speaking at a Churchill Club panel in Palo Alto, Calif., SonicWall CEO Matt Medeiros said malicious attacks are here to stay, so the security industry should be scanning everything that comes in and ... More >

Researcher: Twitter Links Safer Than Google

According to a report by Zscaler Security Research, most short links on Twitter do not pose a security risk . ComputerWeekly reports that Zscaler studied more than 1 million URLs and found that onl... More >

Researcher: Media Hype Pushes IT to Patch Zero-Day Bugs Quickly

According to Wolfgang Kandek, chief technology officer at Qualys, media hype is the biggest driver in persuading IT managers to fix Windows zero-day bugs, reports Computerworld .   After analyz... More >

April 2, 2010

Adobe, Foxit Probe New No-Bug-Needed PDF Attack

Computerworld reports that Adobe and Foxit Software are looking into attacks that use a new tactic that embeds attack code in modified PDF documents .   Attacks on PDF readers are nothing new... More >

DHS Examining Response to Conficker Botnet

The U.S. Department of Homeland Security is looking into the worldwide effort to keep Conficker in check .   According to Computerworld , the report examines how a group of security researcher... More >

April 1, 2010

Audit Finds FBI, DoJ Failing on Identity Theft

eSecurity Planet reports that an audit by the Justice Department's Office of the Inspector General found that the "various efforts" by the FBI and Justice Department to fight identity theft crimes h... More >

Symantec: Conficker Still a Significant Threat

On the year anniversary of the Conficker (aka Downadup) "activation" date, Symantec is warning users that the botnet could still "wreak havoc," reports V3.co.uk .   Last year, there was mu... More >

Microsoft Finds 1,800 Office Bugs with Fuzzing Botnet

In what Microsoft has formally dubbed Distributed Fuzzing Framework, the company was able to tap into the unused computing power of idling PCs to run millions of "fuzzing" tests, uncovering more than... More >

Report: Execs Need to Be Involved in Cyber Security Decisions

According to a new report, executives who aren't involved in cyber security decisions pose a major threat to bottom lines. Lat year, security firm Finjan warned that the cost of cyber crime is runni... More >

Application Infrastructure

Learn more about this middleware layer that pools and dynamically provisions infrastruction application delivery resources to lower costs and improve efficiency.

Data Center Management

Indispensable technologies and best practices to maintain your organization's most valuable asset.

Data Warehousing

Comprehensive storage solutions for better data access and retrieval, leading to better-informed business decisions.

Human Capital Management

Tips, tools, and expert commentary to help you get the most from your company's most valuable asset - its employees.