Newsletters Welcome, Guest Log In | Register
News:

Security

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments
  • IT Careers

Previous Next

Security

September 2010

September 30, 2010

AVG Updates SMB Antivirus Software

AVG has updated its small business antivirus software to offer enhanced Web and social-networking protection and improved detection rates, reports V3.co.uk .   AVG said it used customer feedba... More >

IE Users Face Biggest Risk from DLL Hijacking Attacks

According to Computerworld , research by Slovenian security company Acros Security indicates that Internet Explorer users running Windows XP are particularly vulnerable to "DLL load hijacking," wh... More >

Security Breach Exposes Former U-Florida Students' Info

More than 200 former University of Florida students have been notified that their personal information may be at risk.   According to The Miami Herald , 239 students' information was compromis... More >

September 29, 2010

Maine Department of Education Probes Data Breach

According to The Portland Press Herald , the Maine Department of Education is is deleting all student Social Security numbers and ordering an outside review of the security of its data-collection s... More >

Microsoft Issues Emergency Patch for ASP.Net Flaw

Following an admission last week that a vulnerability in ASP.Net's encryption was being actively exploited, Microsoft has delivered an emergency patch , reports Computerworld .   As the MS1... More >

September 28, 2010

NYC Hospital Exposes Info of 6,800 Patients

A security breach at the New York Presbyterian Hospital/Columbia University Medical Center has exposed the personal information of as many as 6,800 former patients , reports boston.com . The inform... More >

McAfee: Web 2.0 Breaches Costing Companies Millions

While many business professionals concede the value of social media and collaboration, they are right to be concerned about security threats associated with Web 2.0, according to a new McAfee-commiss... More >

ChoicePoint Breach Victims Await 'Paltry' Settlement

Victims of consumer data integrator ChoicePoint's most recent security breach soon will be getting their settlement checks from the Federal Trade Commission, but they may hardly be pleased. eSecuri... More >

'Cleaned' PCs Not Safe from Stuxnet

On the heels of reports that the Stuxnet worm has infected at least 30,000 of Iran's Windows PCs , Liam O Murchu, manager of operations on Symantec's security response team, says he has discovered a... More >

U.S. Tests Defenses with 'Cyber Storm III'

Today, the Department of Homeland Security will test the nation's response to a cyber attack with a simulated large-scale attack on critical infrastructure. According to TG Daily , the goal of Cybe... More >

September 27, 2010

Spammers Target Bank Info of LinkedIn Users

Cisco has warned that cyber crooks have targeted LinkedIn users with a scheme designed to get their bank account information, reports The Sydney Morning Herald .   The people behind the attac... More >

Comcast Hackers Sentenced to 18 Months

Hackers Christopher Lewis and Michael Nebel , who were convicted of defacing Comcast's website two years ago, have been sentenced to 18 months in prison, according to Computerworld .   The pai... More >

Iran: At Least 30,000 Industrial PCs Infected with Stuxnet

Computerworld reports that Iranian officials have confirmed that the Stuxnet worm has infected at least 30,000 Windows PCs in the country.   Symanetc's research shows that nearly 60 percent o... More >

September 24, 2010

Report: Most .Gov Domains Fail to Meet DNSSEC Adoption Mandate

IID (Internet Identity) has announced the results of the first independent study into the deployment of DNSSEC across a majority of .gov domains, and it's not good.   According to this press re... More >

Botnet Operators Move From China to Russia, Says M86 Security

A recent government crackdown in China seems to have forced many botnet operators to resurface in Russia , according to M86 Security. V3.co.uk reports that in the past month 5,000 new spam domains ... More >

FBI Looking Into 'Here You Have' Worm

Computerworld reports that the Federal Bureau of Investigation has launched an investigation into the "Here You Have" worm that plagued inboxes earlier this month.   Shortly after news of the... More >

September 23, 2010

Cisco Patches 12 Bugs in IOS

Cisco has released an update to address 12 vulnerabilities in its Internetwork Operating System , reports Computerworld .   Cisco says the bugs could be used to possibly crash the router. &nbs... More >

Maine Supreme Court Dismisses Damage Claims in Hannaford Breach Cases

Computerworld reports that Maine's Supreme Court has handed down a ruling that consumers affected by the Hannaford Bros. data breach cannot collect damages from the company unless they suffered un... More >

September 22, 2010

Symantec: Mobile Workers Pose Security Threat

According to a new MessageLabs Intelligence Report from Symantec, workers are 35 percent more likely to violate corporate surfing policies when they are on the road, rather than in the office. &nbs... More >

Veracode: Software Has 'Unacceptable' Levels of Vulnerabilities

Testing firm Veracode says developers are not meeting industry security standards when creating new software.   V3.co.uk reports that Veracode collected data on 2,900 applications and found t... More >

Twitter: Website Upgrade Caused Mouseover Flaw

Twitter is blaming a security flaw that redirected users to third-party websites without their consent on a site upgrade , according to TG Daily .   As we reported on our Network Security Edg... More >

September 21, 2010

Stuxnet Spreads Via P2P Channels; Iranian Nuclear Reactor the Target?

Symantec says its research shows that Stuxnet malware is not only controlled via a command and control infrastructure, but can also spread via a peer-to-peer communications channel , reports Inform... More >

Microsoft Warns of Nasty ASP.Net Bug

Microsoft is warning users of a critical bug in ASP.Net that could be exploited by attackers to hijack encrypted Web sessions and steal usernames and passwords from websites, reports Computerworld... More >

Apple Patches AFP Bug in Snow Leopard

Apple has released Security Update 2010-006 for Snow Leopard.   PCWorld.com reports that the update addresses one specific bug in Mac OS X 10.6.4's AFP file-sharing implementation. The flaw... More >

September 20, 2010

Students, Staff at Risk Following Rice University Data Breach

More than 7,000 Rice University students and staff members are at risk following the theft of a storage device containing the names, Social Security numbers and other personally identifying informat... More >

Adobe Decides to Issue Flash Patch Early

Adobe has moved up the delivery of a patch for a critical Flash Player vulnerability , and will patch the flaw today , according to Computerworld .   As we reported last week , the flaw that ... More >

Google Boosts Security with Two-Step Verification

In an effort to provide additional protection against phishing and malware attacks, PCWorld.com reports that Google has introduced a two-factor authentication option to Google Apps . According to ... More >

Insurance Applicant Sues Anthem Blue Cross Over Breach

The Los Angeles Times reports that insurance applicant Patrick Magorien has filed suit against Anthem Blue Cross insurance , claiming that it failed to protect his confidential information from com... More >

September 17, 2010

Report: Security Exploits Becoming More Complex

The "2010 Top Cyber Security Risks Report" from HP's TippingPoint DVLabs, Qualys and The SANS Institute finds that attackers are increasing their use of complex obfuscation techniques for PDF explo... More >

AVG Finds 20,000 Compromised Social-Networking Pages

New research by security vendor AVG uncovered nearly 20,000 compromised Web pages belonging to the top 50 social-networking sites.   According to V3.co.uk , Facebook was home to 11,701 of the... More >

Google Patches 10 Vulnerabilities in Chrome

According to Computerworld , Google has fixed 10 vulnerabilities in Chrome , including one rated as "critical" on the Mac. Of the remaining bugs, six were ranked as "high" and three were pegged as ... More >

Security Firm Issues Home-Brewed Patch for Adobe Reader Bug

Security firm RamzAfzar has crafted a patch for a critical bug in Adobe Reader that hackers are already exploiting, reports Computerworld .   Adobe warned of the bug, which is in Reader's and... More >

September 16, 2010

SMBs Hurt by Social Network Malware, Says Panda

According to Panda Lab's "Social Media Risk Index for Small to Medium Sized Businesses," a third of SMBs have been hit by malware from social networks .   CNET News reports that Facebook took ... More >

Apple Patches Two QuickTime Bugs

Apple has patched a pair of flaws in QuickTime that it has known about for months.   One is in the QuickTime plug-in used by Microsoft's Internet Explorer. HP's TippingPoint originally reporte... More >

September 15, 2010

McAfee: Beware of 'Free' Music Links

McAfee warns that users searching for free music may be opening themselves up to malware attacks.   According to V3.co.uk , it may not be the names of popular music groups that pose a heightene... More >

Stuxnet Worm Has Infected 14 Plants, Says Siemens

Siemens says the Stuxnet worm, which is designed to attack Siemens industrial control systems, has infected at least 14 plants , according to Computerworld . However, Siemens says that the worm has... More >

Survey Identifies Technologies That Head Off Data Breaches

According to a survey by security firm Imperva and security research firm Securosis, the best way to reduce the number of data breaches involves technology to protect applications and databases alo... More >

Stuxnet Worm Targets Four Microsoft Zero-Day Bugs

According to eWEEK , security researchers say that the Stuxnet worm has been targeting four zero-day vulnerabilities in Windows in an effort to infect industrial control systems.   In July , ... More >

September 14, 2010

Student Data Exposed in CCNY Laptop Theft

The personal information of more than 7,000 students attending City College of New York may have been compromised following the theft of a laptop last month, reports eSecurity Planet .   The ... More >

Damballa: Beware of Commercial, On-Demand DoS Botnet

Security firm Damballa is warning about a commercial, on-demand DDoS botnet that has been growing at the rate of about 10,000 infected machines every day for the past several months. Computerworld... More >

Adobe Discloses Critical Zero-Day Hole in Flash Player

eWEEK reports that Adobe is warning of a zero-day flaw that affects Flash Player versions 10.1.82.76 and earlier on Windows, Macintosh, Linux, Solaris and Android operating systems. According to ... More >

September 13, 2010

'Here You Have' Worm Created by Anti-U.S. Hacker?

According to Computerworld , an anti-U.S. hacker, known as Iraq Resistance, has taken responsibility for a fast-spreading e-mail worm that crippled corporate networks last week.   As we repor... More >

PandaLabs: 57,000 Malicious Sites Created Each Week

According to PandaLabs, the research arm of security software vendor Panda Security, scammers are creating 57,000-plus new malicious websites each week to steal passwords and banking or credit card... More >

Microsoft Steps in to Mitigate Adobe Reader, Acrobat Attacks

Microsoft has stepped up to offer help in protecting users against a recent zero-day attack against Adobe's Reader and Acrobat products.   According to Computerworld , Microsoft's Enhanced M... More >

September 10, 2010

'Here You Have' E-Mail Worm Wrecks Havoc

An e-mail virus with the subject line "Here you have" has been plaguing inboxes, reports ABC News .   Dmitri Alperovitch, vice president of threat research at McAfee, explains that it's essent... More >

September Patch Tuesday to Fix 13 Vulnerabilities

Microsoft's September Patch Tuesday will include fixes for 13 vulnerabilities that affect Windows, Internet Information Services, and Microsoft Office, reports CNET News . Four of the bulletins a... More >

September 9, 2010

Apple Patches Three Safari Bugs

Computerworld reports that Apple has patched three vulnerabilities in Safari , including what most researchers are calling a "DLL load hijacking" bug.   With its updates to Safari 5.0.2 and Sa... More >

Apple's iOS 4.1 Patches 24 Vulnerabilities

Apple's iOS 4.1 update for its iPhone and iPod Touch fixes 24 security vulnerabilities .   According to Computerworld , 19 of the bugs are tagged with the phrase "arbitrary code execution," Ap... More >

Adobe Issues Critical Warning for Acrobat, Reader Bug

Computerworld reports that Adobe is warning users about an unpatched bug in its Reader and Acrobat products. According to the advisory : A critical vulnerability exists in Adobe Reader 9.3.4 and ... More >

Symantec: Cyber Crime a Global Problem

A new report by Symantec shows that cyber crime has become a widespread global problem. "The Norton Cybercrime Report: The Human Impact" found that more than 65 percent of the 7,000 participants in ... More >

September 8, 2010

Spammers Exploit Facebook Bug to Post Scam Messages

Facebook says it has fixed a bug that allowed a spamming worm to automatically post messages to users' walls.   According to Computerworld , the scam pushed surveys that offered Best Buy and ... More >

Google Spam Bug Blamed on Routing System Update

Google is blaming a bug that turned Gmail users into unintentional spammers on a routing system update.   The problem, which started Aug. 19, affected 2.5 percent of users. While the bug, whic... More >

Mozilla Patches 15 Firefox Bugs

Mozilla has addressed 15 vulnerabilities in Firefox , including 11 labeled as critical, reports Computerworld .   One patch addressed a flaw that attackers could exploit to bypass a site's cro... More >

September 7, 2010

Nigerian Man Sentenced to 12 Years for 419 Scam

U.S. District Judge Janet Hall has sentenced a Nigerian man to 12 years in prison for sending out bogus e-mails offering victims big bucks if they helped him move cash to the United States.   ... More >

Microsoft Probes 2-Year-Old IE8 Bug

According to Computerworld , Microsoft is investigating a 2-year-old bug in Internet Explorer 8 that can allow hackers to hijack Web mail accounts, steal data and send illicit tweets.   The v... More >

September 3, 2010

Secunia Tracks Down Missing Patches

PCWorld.com reports that Secunia has updated its Personal Software Inspector (PSI) so that it silently looks for missing patches and applies them from multiple vendors soon after their release. &n... More >

Pushdo May Have Taken Hit, But Spammers Stay Busy

Despite the fact that researchers were able to shut down 20 of 30 command and control servers being used by the Pushdo botnet, security experts say it has not stopped spammers.   eWEEK report... More >

Microsoft Adds to Security Toolkit for Windows Apps

To combat common security exploits used by malware, Microsoft has released the Enhanced Mitigation Experience Toolkit (EMET) 2.0 , which adds two new mitigations to the four already supported in the... More >

Facebook Adds Remote Logout Feature

To help users kick spammers out of legitimate accounts, Facebook has launched a new security feature that allows users to see which computers and devices are logged into their Facebook accounts, re... More >

September 2, 2010

Heartland Settles with Discover Card for $5 Million

According to Computerworld , Heartland Payment Systems will pay Discover $5 million to settle claims stemming from the massive data breach disclosed by the payment processor last year.   He... More >

Researchers Hope Botnet Takedown Will Yield Valuable Data

As we reported on our Network Security Edge site, researchers at the University of California-Santa Barbara and Germany’s Ruhr-University Bochum managed to cripple the PushDo botnet . Now, they're... More >

September 1, 2010

Researchers Launch 'Month of Bugs'

Starting today, reports Computerworld , Abysssec Security Research plans to kick off a "Month Of Abysssec Undisclosed Bugs," in which the group will target unpatched vulnerabilities in software fr... More >

Server Management

Management tips and product information to leverage the best value from your server investment.

Human Capital Management

Tips, tools, and expert commentary to help you get the most from your company's most valuable asset - its employees.

Service-Oriented Architecture (SOA)

Service-oriented architecture is the catalyst that allows today's companies to respond to business demands faster and more effectively than ever.

Application Infrastructure

Learn more about this middleware layer that pools and dynamically provisions infrastruction application delivery resources to lower costs and improve efficiency.