Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3


Around The Web

REUTERS
Chinese Firm Helps Iran Spy On Citizens
A Chinese telecommunications equipment company has sold Iran's largest telecom firm a powerful surveillance system capable of monitoring landline, mobile and internet communications, interviews and contract documents show

NEXTGOV
Cybersecurity Index Aims To Penetrate The Fog Of Marketing Hype
It's impossible to fix something if you can't even gauge that it's broken. It's a classic problem that systems engineers and defense contractors face: they are staring into a fog of elusive threats made worse by marketers trying to make a sale on security hype

TECHWEEK EUROPE
ENISA Urges Security Monitoring For Cloud Contracts
The European Network and Information Security Agency (ENISA), the European Union?s cyber-security body, has focused its attention on the cloud with a new guide aimed at helping IT procurement teams monitor the security of cloud-based contracts

ZDNET NEWS
Eight Ways To Improve Your Corporate Network Security Posture
Companies need a complete forensics record of every last packet to determine if attackers merely got onto a system or got away with sensitive data

BANKINFOSECURITY
IG Questions Effectiveness Of IRS Monitoring
The U.S. Treasury Department's Inspector General for Tax Administration point out flaws in IT security at the IRS that puts its data at risk. A third of the agency's servers are not monitored by the IRS Computer Security Incident Response Center, which provides round-the-clock security for IRS networks

INFORMATION WEEK
State Department CIO: What's Changed Since WikiLeaks
The agency is deploying new security technology in the wake of WikiLeaks, including auditing and monitoring tools to detect anomalous activity on the agency's classified networks and systems

GUARDIAN UK
Government Plans Increased Email And Social Network Surveillance
Ministers are expected to introduce a new law in May allowing police and security services to extend their monitoring of the public's email and social media communications, according to the British Home Office

FEDERAL TIMES
Agencies Urged To Improve Continuous Monitoring Of IT Systems
Agencies have been slow to invest in tools that continuously monitor federal systems and networks for cyber intrusions, 43,889 of which agencies reported to the Department of Homeland Security last fiscal year

PC WORLD
Sony Says Data Is Protected, Attackers Say It's For Sale
Poor security monitoring is only one factor in Sony's inability to keep track of what exactly hackers have done with its most precious information--the company claims that its data was safeguarded but reports have show that Sony customer data has already hit the black market

BLOOMBERG
Energy Infrastructure Lacks Advanced Defense From Cyber Attacks
A new survey conducted by Ponemon Research on behalf of Q1 Labs shows that the security monitoring and defense mechanisms at the nation's energy providers is sorely lacking in today's threat environment

SECURITYWEEK
Challenges And Strategies For Log Management In The Cloud
SIEM on local infrastructure is hard enough as-is. Add cloud infrastructure to the mix and the task becomes daunting , according to one security expert

SC MAGAZINE
Taming Your "Unknown Unknowns" Through Network Traffic Analysis
One security professional explains how he uses network traffic analysis to find threats to his network that he wasn't initially aware of, making it what he calls a key component of his network monitoring program

CSO MAGAZINE
After 40 Years, Email Security Still Elusive, Experts Say
Four decades after introduction, companies still struggle with monitoring e-mail and enforcing policies to ensure users follow policies and do not send sensitive information outside the perimeter of most organizations

CSO MAGAZINE
After 40 Years, Email Security Still Elusive, Experts Say
Four decades after introduction, companies still struggle with monitoring e-mail and enforcing policies to ensure users follow policies and do not send sensitive information outside the perimeter of most organizations

IT-DIRECTOR.COM
Collaborative SIEM Solutions
A Bloor Research analyst explains some of the limitations in the SIEM market, which he believes still fails to offer complete solutions that offer a total package with real-time analysis of event data and deep-dive analytics performed against log data

TECHNORATI
Computer Rental Store Accused Of Spying On Customers
Aaron?s Inc. is in hot water after installing software on a computer that it leased to a couple without informing them first. The company uses this type of monitoring software to spy on customers following non-payment, however the couple involved had in fact paid their bill

LOGMANAGEMENTCENTRAL.COM
What To Watch For: Five Security Information Management Trends For 2011
Security monitoring experts expect to see log management in the cloud, vendor consolidation, user-centric management, application monitoring and SIEM correlation to be hot topics through the rest of the year

GOVERNMENT COMPUTER NEWS
NIST Aids The Cause Of Real-Time Security
In support of the government push for continuous monitoring within agencies, the National Institute of Standards and Technology released final specs for the latest version of the Security Content Automation Protocol

ZDNET
End-To-End Monitoring, Through The Datacenter To The Cloud
Cloud services must do a better job extending monitoring capabilities across their infrastructures in order to gain the confidence among IT shops necessary for wider-scale deployments

PC WORLD
How To Monitor Your Employees' PCs Without Going Too Far
Employee monitoring can be a delicate and arduous matter, but automated tools and a transparent forthrightness with users can smooth the process


Best Of Web Archive:
Most Recent | 1| 2| 3








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)