Welcome Guest. | Log In | Register | Membership Benefits

Manage Risk As A Strategy, Comply With Regulations As A Tactic


Posted by Glenn S. Phillips @ 02:42 PM ET | May 17, 2012

Compliance alone should never be the only goal

Continue reading "Manage Risk As A Strategy, Comply With Regulations As A Tactic"


Topics:   Security Views : Compliance Tech Center



Time To Deploy The FUD Weapon?


Posted by Mike Rothman @ 01:23 PM ET | May 16, 2012

When suffering from compliance fatigue, you may have only one option to getting the funding you need to do your job

Continue reading "Time To Deploy The FUD Weapon?"


Topics:   Hacked Off



Dark Reading Launches New Tech Center On Threat Intelligence


Posted by Tim Wilson @ 09:27 AM ET | May 14, 2012

Subsite of Dark Reading will look at collection and analysis of data on emerging threats

Continue reading "Dark Reading Launches New Tech Center On Threat Intelligence"


Topics:   Dark Dominion



Screw Compliance, We're Trying to Survive


Posted by Glenn S. Phillips @ 09:13 AM ET | May 08, 2012

In tough times, compliance efforts may seem optional

Continue reading "Screw Compliance, We're Trying to Survive"


Topics:   Security Views : Compliance Tech Center



Where In Hacking The Ends Justify The Means


@ 09:00 AM ET | May 08, 2012

Do some 'ethical hackers' really have your best interest at heart, or are they more interested in making your private information public?

Continue reading "Where In Hacking The Ends Justify The Means"


Topics:   SophosLabs Insights



Analyzing Android, iOS Apps For Weak Data Protection, Cleartext Passwords


Posted by John H. Sawyer @ 02:54 PM ET | May 04, 2012

Analysis reveals mobile apps designed to protect things like photos and passwords do a poor job, often storing them in plain text with no encryption at all.

Continue reading "Analyzing Android, iOS Apps For Weak Data Protection, Cleartext Passwords"


Topics:   Evil Bytes



Effective Security Policy: Emphasis On Execution


Posted by Amy DeCarlo @ 09:12 AM ET | May 02, 2012

When it comes to mounting a successful defense in what is a fast-changing threat environment, best practices require consistent execution

Continue reading "Effective Security Policy: Emphasis On Execution"


Topics:   Security Services Tech Center : Security Views



What Works For One Does Not Work For Two


Posted by Glenn S. Phillips @ 08:29 AM ET | May 02, 2012

To remain compliant, your approach must grow in scale with your business

Continue reading "What Works For One Does Not Work For Two"


Topics:   Security Views : Compliance Tech Center



How Would You Architect A New Security Monitoring Product?


Posted by Andrew Hay @ 07:28 AM ET | Apr 30, 2012

Cloud, appliance, software? If you were planning on developing a security monitoring platform, which architecture would you use?

Continue reading "How Would You Architect A New Security Monitoring Product?"


Topics:   Security Monitoring Tech Center : Security Views



Security Bugs And Proofs Of Concept


Posted by Adrian Lane @ 02:50 PM ET | Apr 27, 2012

Oracle's recent patch contained exploit code

Continue reading "Security Bugs And Proofs Of Concept"


Topics:   Database Security Tech Center : Security Views



PCI: Dead Man(date) Walking?


Posted by Mike Rothman @ 03:04 PM ET | Apr 25, 2012

Is Visa's program to eliminate the requirement for assessments in lieu of EMV (chip and pin) transactions the death knell for PCI? Not yet, but the writing is on the wall

Continue reading "PCI: Dead Man(date) Walking?"


Topics:   Hacked Off



Coming Soon to Your Smartphone: Mobile Ticketing That Keeps Your Transactions Safe


Posted by Brian Royer @ 10:12 AM ET | Apr 25, 2012

Just because smartphone rail ticketing is a first here in the states doesn't mean mobile malware writers aren't already paying attention

Continue reading "Coming Soon to Your Smartphone: Mobile Ticketing That Keeps Your Transactions Safe"


Topics:   SophosLabs Insights



2012 U.S. Election And Targeted Attack Predictions


Posted by Tom Parker @ 06:38 PM ET | Apr 22, 2012

How the increased level and sophistication of of targeted attacks since 2008 may impact this year's U.S. Presidential election campaigns

Continue reading "2012 U.S. Election And Targeted Attack Predictions"


Topics:   Security Views : Advanced Threats Tech Center



You Need Help, Not An Accomplice


Posted by Glenn S. Phillips @ 09:35 AM ET | Apr 20, 2012

Compliance is about being better and not just proving you are right

Continue reading "You Need Help, Not An Accomplice"


Topics:   Security Views : Compliance Tech Center



The Benefits Of Top-Down Security


Posted by Brian Royer @ 10:21 AM ET | Apr 18, 2012

While enterprise-level breaches often get the attention of C-level suite executives and the members of their IT staff, industry research shows it actually falls to rank and file employees to apply best practices and exercise sound judgment in order to properly contain them

Continue reading "The Benefits Of Top-Down Security"


Topics:   SophosLabs Insights



Log Standards: Put Up, Shut Up, Give Up, Or Throw Up?


Posted by Andrew Hay @ 01:07 PM ET | Apr 16, 2012

Do we need logging standards, or should we just follow the leaders to help direct our logging efforts?

Continue reading "Log Standards: Put Up, Shut Up, Give Up, Or Throw Up?"


Topics:   Security Monitoring Tech Center : Security Views



Your Compliance Is Decaying Every Day


Posted by Glenn S. Phillips @ 11:26 AM ET | Apr 16, 2012

As soon as you train your colleagues about compliance, noncompliance is back in charge

Continue reading "Your Compliance Is Decaying Every Day"


Topics:   Security Views : Compliance Tech Center



Using Reverse Proxies To Secure Databases


Posted by Adrian Lane @ 01:21 PM ET | Apr 12, 2012

A look at database monitoring and reverse proxies

Continue reading "Using Reverse Proxies To Secure Databases"


Topics:   Database Security Tech Center : Security Views



Be Ready To Clean Up That Mess


Posted by Glenn S. Phillips @ 11:14 AM ET | Apr 11, 2012

Compliant systems do more than prevent problems -- they help solve problems that happen

Continue reading "Be Ready To Clean Up That Mess"


Topics:   Security Views : Compliance Tech Center



Utah Medicaid Breach Exemplifies Value Of Encryption And Access Control


@ 08:36 AM ET | Apr 11, 2012

Proactively applying private or public-key encryption coupled with access control won't eliminate data breaches. But it will make it harder for the bad guys to take advantage of you

Continue reading "Utah Medicaid Breach Exemplifies Value Of Encryption And Access Control"


Topics:   SophosLabs Insights



How Much Money Do You Need To Lose Before You Start Monitoring?


Posted by Andrew Hay @ 11:01 AM ET | Apr 09, 2012

At what point does turning a blind eye to the loss of revenue spark the inevitable conversation: 'Maybe we should be monitoring this infrastructure more closely?'

Continue reading "How Much Money Do You Need To Lose Before You Start Monitoring?"


Topics:   Security Monitoring Tech Center : Security Views



Quick-Start Guide: Compiling Mac-Robber For iOS Vuln Research


Posted by John H. Sawyer @ 06:41 PM ET | Apr 05, 2012

How to compile, copy, and run mac-robber on jailbroken iOS devices

Continue reading "Quick-Start Guide: Compiling Mac-Robber For iOS Vuln Research"


Topics:   Evil Bytes



Database Security On The Cheap


Posted by Adrian Lane @ 12:41 PM ET | Apr 04, 2012

A look at some free tools to help tackle database security

Continue reading "Database Security On The Cheap"


Topics:   Database Security Tech Center : Security Views



Quick-Start Guide: Compiling Mac-Robber For Android Vuln Research


Posted by John H. Sawyer @ 05:15 PM ET | Apr 02, 2012

How to compile, copy, and run mac-robber on rooted Android devices

Continue reading "Quick-Start Guide: Compiling Mac-Robber For Android Vuln Research"


Topics:   Evil Bytes



Forensic Approach To Mobile App Vulnerability Research


Posted by John H. Sawyer @ 10:30 AM ET | Mar 30, 2012

Intro to a unique approach for vulnerability research on mobile apps using traditional PC forensic tools

Continue reading "Forensic Approach To Mobile App Vulnerability Research"


Topics:   Evil Bytes




Go on to the weblog archives...






  1. Cookies, Social Media And FireSheep
  2. SMB Guide To Credit Card Regulations, Part 2: The Low-Hanging Fruit
  3. HP And The Scary Corporate Fifth Column Concept
  4. Taking USB Attacks To The Next Level
  5. NoSQL: Not Much, Anyway
  1. Taking Cybersecurity Lessons To The Bank
  2. Researchers See Real-Time Phishing Jump
  3. 'BlackSheep' Sniffs Out Firesheep WiFi-Hacking
  4. Slideshow: Ten Free Security Monitoring Tools
  5. A Different Spin On Sleuthing Stuxnet
  6. M&A Activity Muddles Database Security
  1. Secure Managed Web Hosting Saves 960.gs from Malicious Hackers
  2. Access Governance as a Business Service: An Integrated Strategy for Automation with ITSM
  3. Business Driven Access Management and Governance: Simplifying the Delivery and Governance of Access Throughout
 
 


 
  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag
 
  May 2012
April 2012
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
  June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
 
Featured Webcasts
Featured Whitepapers
Featured Reports