Welcome Guest. | Log In| Register | Membership Benefits

Amazon's SimpleDB Not Your Typical Database


Posted by Adrian Lane @ 04:08 PM ET | Feb 6, 2010

Several cloud providers offer databases specifically designed for cloud deployment. Amazon's SimpleDB, while technically a database, deviates from what most of us recognize as a database platform. Although SimpleDB is still in prerelease beta format, developers have begun designing applications for it.

Continue reading "Amazon's SimpleDB Not Your Typical Database..."

Comment on this blog entry
Topics:   Database Security Tech Center : Security Views



New Flaws Pry Lid Off Cloud Frameworks


Posted by Robert Richardson @ 12:21 PM ET | Feb 5, 2010

A new set of vulnerabilities came to light this week at Black Hat DC, and its appearance provides a good look at our bleak "next-gen" security future.

Continue reading "New Flaws Pry Lid Off Cloud Frameworks..."

Comment on this blog entry
Topics:   CS Island



'Brand' Your Employees


Posted by Gadi Evron @ 06:14 AM ET | Feb 5, 2010

You might want your product to be in the news every day, and for your PR to create miracles for you. But if you want attention, then your company must speak out on big security issues and news.

Continue reading "'Brand' Your Employees..."

Comment on this blog entry
Topics:   Hacked Off



Litchfield's Last Hurrah


Posted by Kelly Jackson Higgins @ 05:44 PM ET | Feb 3, 2010

Yesterday was David Litchfield's last day at NGS Software, and he commemorated the milestone by dropping a zero-day vulnerability in Oracle's 11g database at Black Hat DC. He also surprised the audience -- and possibly himself -- by awarding Oracle a "B+" final grade for security in 11g, after nearly 10 years of keeping Oracle on its toes by calling out vulnerabilities in its database technology.

Continue reading "Litchfield's Last Hurrah..."

Comment on this blog entry
Topics:   Dark Dominion



Updated Tool Targets Facebook Security


Posted by John Sawyer @ 02:15 PM ET | Feb 3, 2010

Security issues surrounding social networking sites make me cringe. I understand their practical applications, but they are also the platform for easy delivery of exploits through social engineering. I've seen many systems compromised by the unconscious click on a Facebook link that users' nonchalance on similar sites and their trust in the Internet frustrates me to no end.

Continue reading "Updated Tool Targets Facebook Security..."

Comment on this blog entry
Topics:   Evil Bytes



Tool Helps Prepare For Disaster


Posted by Rob Enderle @ 09:19 AM ET | Feb 3, 2010

When I see an event like the Haiti earthquake, I worry that we treat disaster preparedness much like we do data backup -- we don't really think about it until it's too late. We are faced with putting in place a plan to deal with disaster, and then realize we don't aren't properly prepared. But I might have found a tool that can help.

Continue reading "Tool Helps Prepare For Disaster..."

Comment on this blog entry
Topics:   Hacked Off



When Software Glitches Are Fatal -- Literally


Posted by John Sawyer @ 02:50 PM ET | Feb 1, 2010

Hearing about how many companies were hacked during the Aurora attacks due to a software vulnerability in Microsoft's Internet Explorer (IE) is frustrating. Now another attack is ready to be unveiled at Black Hat DC that also uses an IE "feature." The thought of what can and has happened because of these flaws is scary -- theft of personal information, espionage, identity theft, etc. -- but what happens when software glitches lead to death?

Continue reading "When Software Glitches Are Fatal -- Literally..."

Comments(2)
Topics:   Evil Bytes



70% Rise In Malware: Time To Block Facebook?


Posted by Graham Cluley @ 11:19 AM ET | Feb 1, 2010

New research published by Sophos today reveals a 70 percent increase in the number of companies reporting spam and malware attacks via social networks.

Continue reading "70% Rise In Malware: Time To Block Facebook?..."

Comment on this blog entry
Topics:   Insider Threat Tech Center : SophosLabs Insights



Wiping Out Wimpy Passwords


Posted by Adrian Lane @ 01:11 PM ET | Jan 29, 2010

Recent breaches at Rockyou.com and Hotmail illustrate the consistency of human behavior: Since the dawn of access control systems, users continue to choose easily guessed passwords.

Continue reading "Wiping Out Wimpy Passwords..."

Comments(2)
Topics:   Database Security Tech Center : Security Views



IE 6 Aftermath: Time To Review Your Browser Strategy


Posted by Wolfgang Kandek @ 07:31 PM ET | Jan 27, 2010 The latest update for Internet Explorer is out, and organizations are busy applying or at least certifying the patch on their testbeds.

Continue reading "IE 6 Aftermath: Time To Review Your Browser Strategy..."

Comments(1)
Topics:   Security Views : Vulnerability Management Tech Center



TechCrunch Hacked Again: Foul-Mouth Hacker Embarrasses Top Blog


Posted by Graham Cluley @ 02:51 AM ET | Jan 27, 2010

Technology blog TechCrunch has been hacked for the second time in 24 hours.

Continue reading "TechCrunch Hacked Again: Foul-Mouth Hacker Embarrasses Top Blog..."

Comment on this blog entry
Topics:   SophosLabs Insights



TechCrunch Hacked


Posted by Graham Cluley @ 04:10 AM ET | Jan 26, 2010

The immensely popular blog TechCrunch has been compromised by hackers who posted an offensive message on its home page.

Continue reading "TechCrunch Hacked..."

Comment on this blog entry
Topics:   SophosLabs Insights



Johnny Depp Death Crash Video Launches Malware Attack


Posted by Graham Cluley @ 06:40 AM ET | Jan 25, 2010

An Internet rumor that Hollywood superstar Johnny Depp has died in a French car crash is being taken advantage of by cybercriminals, who have planted malware posing as video footage of the accident.

Continue reading "Johnny Depp Death Crash Video Launches Malware Attack..."

Comment on this blog entry
Topics:   SophosLabs Insights



Operating In An Insecure World


Posted by John Sawyer @ 02:47 PM ET | Jan 22, 2010

I've heard of the idea of operating day-to-day with the assumption that your organization is already compromised, and I just saw it reiterated in the Tenable Security Blog, but I think it's a tough one to swallow for most organizations. There has to be some level of trust within an organization, otherwise, how could you get any business done. But as tough as it is to accept, there is value in taking this approach.

Continue reading "Operating In An Insecure World..."

Comment on this blog entry
Topics:   Evil Bytes



Google/China Reality Check Amid The Fog Of Cyberwar


Posted by Gadi Evron @ 11:00 AM ET | Jan 21, 2010

We've all heard about the Chinese attacks against Google by now. We've heard of Google's moral standing, how corporations now impact international relations, and how censorship is bad and freedom is good. However, some important questions lost in the fog of war need to be asked.

Continue reading "Google/China Reality Check Amid The Fog Of Cyberwar..."

Comments(2)
Topics:   Hacked Off



User Security After The Google Hack


Posted by John Sawyer @ 02:10 PM ET | Jan 20, 2010

Last week's news about the Google hack has really raised some eyebrows. Doe-eyed users have learned the harsh truth that anyone can be hacked. The news of 20 or more other companies also being targeted along with Google made the impact that much worse.

Continue reading "User Security After The Google Hack..."

Comment on this blog entry
Topics:   Evil Bytes



Emergency Microsoft Internet Explorer Patch Arrives Thursday


Posted by Graham Cluley @ 01:28 PM ET | Jan 20, 2010

The IT world sighed with relief at the news that Microsoft is releasing an out-of-band patch for Internet Explorer on Thursday, Jan. 21.

Continue reading "Emergency Microsoft Internet Explorer Patch Arrives Thursday..."

Comment on this blog entry
Topics:   SophosLabs Insights



What Data Discovery Tools Really Do


Posted by Adrian Lane @ 09:00 AM ET | Jan 20, 2010

Data discovery tools are becoming increasingly necessary for getting a handle on where sensitive data resides. When you have a production database schema with 40,000 tables, most of which are undocumented by the developers who created them, finding information within a single database is cumbersome. Now multiply that problem across financial, HR, business processing, testing, and decision support databases -- and you have a big mess.

Continue reading "What Data Discovery Tools Really Do..."

Comments(1)
Topics:   Database Security Tech Center : Security Views



Share Your New Security Innovations


Posted by Gadi Evron @ 04:00 PM ET | Jan 15, 2010

I am working with InformationWeek Analytics to create an analysis of the year's top five technology innovations in the security arena. If you are a vendor and believe you have the next big thing, then you should contact us.

Continue reading "Share Your New Security Innovations..."

Comment on this blog entry
Topics:   Hacked Off



The Cybersecurity Czar's First Big Test


Posted by Kelly Jackson Higgins @ 12:21 PM ET | Jan 14, 2010

I'm still waiting for Howard Schmidt, the new cybersecurity czar, to weigh in on the Chinese cyberattacks revealed this week. Sure, Chinese hackers going after American interests and human rights activists is nothing new to the IT security world, but this latest development is big, and it could be a defining moment for Schmidt's new post.

Continue reading "The Cybersecurity Czar's First Big Test..."

Comment on this blog entry
Topics:   Dark Dominion



Discovery And Your Database


Posted by Adrian Lane @ 10:13 AM ET | Jan 13, 2010

Database discovery is the act of locating databases on a network. Years ago, this was simple because companies had only one or two databases. Now just about every application created relies on database services to provide data integrity and transactional consistency.

Continue reading "Discovery And Your Database..."

Comment on this blog entry
Topics:   Database Security Tech Center : Security Views



We Have Nothing To Say -- Or Do We?


Posted by Gadi Evron @ 02:05 AM ET | Jan 12, 2010

The first rule of appearing smart, they say, is to keep quiet, but keeping quiet doesn't help your PR. What are you to do?

Continue reading "We Have Nothing To Say -- Or Do We?..."

Comment on this blog entry
Topics:   Hacked Off



Iranian Cyber Army Attacks Chinese Search Giant


Posted by Graham Cluley @ 01:22 AM ET | Jan 12, 2010

China's No. 1 Website has fallen victim to a group of hackers calling themselves the "Iranian Cyber Army," who replaced the site's home page with a political message.

Continue reading "Iranian Cyber Army Attacks Chinese Search Giant..."

Comments(2)
Topics:   SophosLabs Insights



The Inconvenient Truth Behind Security


Posted by John Sawyer @ 02:55 PM ET | Jan 11, 2010

A co-worker forwarded me an e-mail in which the original sender was asking about running vulnerability scans on his own and stated he was concerned about the scans causing downtime while the servers were being tested.

Continue reading "The Inconvenient Truth Behind Security..."

Comments(1)
Topics:   Evil Bytes : Vulnerability Management Tech Center



When PDFs And Flash Files Attack


Posted by John Sawyer @ 02:18 PM ET | Jan 8, 2010

It's getting harder to protect our users from threats coming at them from seemingly trusted places. The Websites they've been using for years are suddenly the source of attacks through malicious advertisements being pushed to the "trusted" site by a third-party advertising service. File format attacks against Adobe's Flash and Acrobat are becoming the exploit du jour for attackers.

Continue reading "When PDFs And Flash Files Attack..."

Comment on this blog entry
Topics:   Evil Bytes




Go on to the weblog archives...