Welcome Guest. | Log In | Register | Membership Benefits

Ron Was Wrong, Whit Is Right, And What You Need To Know


Posted by Vincent Liu @ 08:48 AM ET | Mar 13, 2012

Clarifying the technical findings on a weakness in RSA crypto keys and some recommendations on how to prepare and protect your assets from the next inevitable crypto weakness discovery

Continue reading "Ron Was Wrong, Whit Is Right, And What You Need To Know"


Topics:   Security Views : Vulnerability Management Tech Center



Can You Train A Great Penetration Tester?


Posted by Vincent Liu @ 01:51 AM ET | Feb 27, 2012

The hacker mindset can't be taught -- it must be developed and refined over time

Continue reading "Can You Train A Great Penetration Tester?"


Topics:   Security Views : Vulnerability Management Tech Center



Fighting 0days With Fundamentals


Posted by Vincent Liu @ 04:53 AM ET | Nov 07, 2011

How to pre-emptively secure systems against 0day attacks that, by definition, we know nothing about

Continue reading "Fighting 0days With Fundamentals"


Topics:   Security Views : Vulnerability Management Tech Center



Pro Pen Testing: The Zero-Knowledge Approach


Posted by Vincent Liu @ 04:36 PM ET | Oct 14, 2011

Special care must be taken in a penetration test that locates targets with 'zero-knowledge'

Continue reading "Pro Pen Testing: The Zero-Knowledge Approach"


Topics:   Security Views : Vulnerability Management Tech Center



Thanksgiving IT Help


Posted by Wolfgang Kandek @ 12:57 AM ET | Nov 23, 2010

Tips for helping family members secure their computers for safe internet browsing and online shopping.

Continue reading "Thanksgiving IT Help"


Topics:   Security Views : Vulnerability Management Tech Center



The What And The Why Of Professional Penetration Testing


Posted by Vincent Liu @ 06:40 PM ET | Sep 20, 2010

Welcome to the first in a series of posts on professional penetration testing. During the course of the next few entries, I will shed light on the often confusing and rarely straightforward world of penetration testing based on my experience during the past decade as both a professional penetration tester and a manager of penetration testing teams.

Continue reading "The What And The Why Of Professional Penetration Testing"


Topics:   Security Views : Vulnerability Management Tech Center



Keep Your Browser Updated


Posted by Wolfgang Kandek @ 09:55 AM ET | Sep 07, 2010

During the Labor Day weekend, I got pulled in by friends and relatives (some remotely) to take care of their computer-related problems.

Continue reading "Keep Your Browser Updated"


Topics:   Security Views : Vulnerability Management Tech Center



No PDF Updates Anymore--Anyone Interested?


Posted by Wolfgang Kandek @ 03:21 PM ET | Jun 29, 2010

Adobe has published its security updates for Adobe Reader and Adobe Acrobat.

Continue reading "No PDF Updates Anymore--Anyone Interested?"


Topics:   Security Views : Vulnerability Management Tech Center



Shed Vulnerabilities With One Simple Rule


Posted by Wolfgang Kandek @ 12:07 PM ET | Jun 14, 2010

A couple of months ago, Secunia's Stefan Frei published a great paper about the patching burden that the average PC user faces every week.

Continue reading "Shed Vulnerabilities With One Simple Rule"


Topics:   Security Views : Vulnerability Management Tech Center



Microsoft SIR, Dissected


Posted by Wolfgang Kandek @ 01:12 PM ET | Apr 28, 2010

Microsoft published Version 8 of its Security Intelligence Report (SIR) this week. The report covers the second half of 2009 and is a massive piece of information with almost 250 pages.

Continue reading "Microsoft SIR, Dissected"


Topics:   Security Views : Vulnerability Management Tech Center



In SSL We Trust? Not Lately


Posted by Wolfgang Kandek @ 09:56 PM ET | Apr 07, 2010

In the past two weeks we have seen multiple problems with SSL, which is used in our Web browsers to protect the privacy and integrity of our electronic transactions.

Continue reading "In SSL We Trust? Not Lately"


Topics:   Security Views : Vulnerability Management Tech Center



How Safari Hacker Finds Bugs


Posted by Wolfgang Kandek @ 03:56 PM ET | Mar 25, 2010

Multiple vulnerabilities in the mainstream browsers and other widely installed software came to light at the CanSecWest conference in Vancouver.

Continue reading "How Safari Hacker Finds Bugs"


Topics:   Security Views : Vulnerability Management Tech Center



Energizer Bunny Gone Bad


Posted by Wolfgang Kandek @ 07:55 PM ET | Mar 10, 2010

Along with the usual security alerts covering the March bulletins from Microsoft and various content management systems flaws, US CERT published an unusual security alert about a product from Energizer, the battery company.

Continue reading "Energizer Bunny Gone Bad"


Topics:   Security Views : Vulnerability Management Tech Center



Boosting Your Defenses Against Botnet Infections


Posted by Wolfgang Kandek @ 02:32 PM ET | Feb 19, 2010

In the past few weeks since the Google/China incident, we have seen a number of interesting blog posts and white papers that provide further details on some of the techniques used by the attackers.

Continue reading "Boosting Your Defenses Against Botnet Infections"


Topics:   Security Views : Vulnerability Management Tech Center



Virtualization Vulnerabilities Up And Coming


Posted by Wolfgang Kandek @ 07:45 PM ET | Feb 11, 2010

Microsoft's February 2010 Patch Tuesday was one of the bigger releases for Microsoft and its clients in the past two years -- 13 bulletins addressing 26 vulnerabilities.

Continue reading "Virtualization Vulnerabilities Up And Coming"


Topics:   Security Views : Vulnerability Management Tech Center



IE 6 Aftermath: Time To Review Your Browser Strategy


Posted by Wolfgang Kandek @ 07:31 PM ET | Jan 27, 2010

The latest update for Internet Explorer is out, and organizations are busy applying or at least certifying the patch on their testbeds.

Continue reading "IE 6 Aftermath: Time To Review Your Browser Strategy"


Topics:   Security Views : Vulnerability Management Tech Center



The Inconvenient Truth Behind Security


Posted by John H. Sawyer @ 02:55 PM ET | Jan 11, 2010

A co-worker forwarded me an e-mail in which the original sender was asking about running vulnerability scans on his own and stated he was concerned about the scans causing downtime while the servers were being tested.

Continue reading "The Inconvenient Truth Behind Security"


Topics:   Evil Bytes : Vulnerability Management Tech Center



Adobe Reader's Patch Tuesday


Posted by Wolfgang Kandek @ 03:43 PM ET | Jan 07, 2010

Next Tuesday, Jan. 12, is Microsoft Patch Tuesday. Beyond the usual patches from Microsoft, we will also get a critical update for a piece of software that increasingly plays a role in exploiting desktop systems -- the Adobe Reader from Adobe Systems.

Continue reading "Adobe Reader's Patch Tuesday"


Topics:   Security Views : Vulnerability Management Tech Center



Improved Security In Microsoft Office 2010


Posted by Wolfgang Kandek @ 05:54 PM ET | Dec 17, 2009

Microsoft has made Office 2010 available in public beta. After playing around with it for a while, I am not yet sure I need any of the new functionality.

Continue reading "Improved Security In Microsoft Office 2010"


Topics:   Security Views : Vulnerability Management Tech Center



New Cloud-Based Wireless Password Cracker


Posted by Wolfgang Kandek @ 02:30 PM ET | Dec 09, 2009

Security reports have consistently pointed out weak or default passwords as a major source for data breaches, similar to the recent Verizon Data Breach Study. Now there's a new service that tests the strength of passwords used in the encryption of wireless access points.

Continue reading "New Cloud-Based Wireless Password Cracker"


Topics:   Security Views : Vulnerability Management Tech Center



The Futility Of Security By Obscurity


Posted by Wolfgang Kandek @ 07:40 PM ET | Nov 30, 2009

Last week saw the launch of Shodan, a search engine for machines (servers, routers, etc.) connected to the Internet.

Continue reading "The Futility Of Security By Obscurity"


Topics:   Security Views : Vulnerability Management Tech Center



Narrowing The Compromise-To-Discovery Breach Time Line


Posted by Chris Novak @ 12:04 PM ET | Nov 20, 2009

Security professionals are intrigued by the fact that for approximately half of the data breach cases Verizon Business works, the victim doesn't realize there's a problem until more than six months after the incident occurred. Another stunning fact: More than two-thirds of incidents we work are discovered by a third-party.

Continue reading "Narrowing The Compromise-To-Discovery Breach Time Line"


Topics:   Security Views : Vulnerability Management Tech Center



Conficker's Next Move


Posted by Wolfgang Kandek @ 04:25 PM ET | Nov 11, 2009

I recently attended a presentation about the current state of the Conficker worm, delivered by Felix Leder and Tillman Werner, two German security researchers from the University of Bonn.

Continue reading "Conficker's Next Move"


Topics:   Security Views : Vulnerability Management Tech Center



Dissecting Microsoft's Latest Security Intelligence Report


Posted by Wolfgang Kandek @ 09:28 PM ET | Nov 05, 2009

This week Microsoft published volume 7 of its Security Intelligence Report (SIR), covering January 2009 through June 2009.

Continue reading "Dissecting Microsoft's Latest Security Intelligence Report"


Topics:   Security Views : Vulnerability Management Tech Center



Fundamental Failures With Incident Response Plans


Posted by Chris Novak @ 01:00 PM ET | Nov 03, 2009

I recently got back from a sizable IT security conference in London. As I've experienced countless times at shows, everyone was most intrigued by the war stories about organizations that were victims of a data breach. Security folks have an innate desire to learn what happened to others so they can prevent encountering the same fate -- or so they say. However, after personally investigating hundreds of data breaches for my clients, there seems to be a number of recurring themes that nobody seems to catch. One in particular is with respect to developing and maintaining an incident response plan.

Continue reading "Fundamental Failures With Incident Response Plans"


Topics:   Security Views : Vulnerability Management Tech Center




Go on to the weblog archives...






  1. Cookies, Social Media And FireSheep
  2. SMB Guide To Credit Card Regulations, Part 2: The Low-Hanging Fruit
  3. HP And The Scary Corporate Fifth Column Concept
  4. Taking USB Attacks To The Next Level
  5. NoSQL: Not Much, Anyway
  1. Taking Cybersecurity Lessons To The Bank
  2. Researchers See Real-Time Phishing Jump
  3. 'BlackSheep' Sniffs Out Firesheep WiFi-Hacking
  4. Slideshow: Ten Free Security Monitoring Tools
  5. A Different Spin On Sleuthing Stuxnet
  6. M&A Activity Muddles Database Security
  1. Secure Managed Web Hosting Saves 960.gs from Malicious Hackers
  2. Access Governance as a Business Service: An Integrated Strategy for Automation with ITSM
  3. Business Driven Access Management and Governance: Simplifying the Delivery and Governance of Access Throughout
 
 


 
  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag
 
  May 2012
April 2012
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
  June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
 
Featured Webcasts
Featured Whitepapers
Featured Reports