Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4


Around The Web

NETWORK WORLD
Biggest Insider Threat? Sys Admin Gone Rogue
Privileged insiders can pose the threat to companies, especially the people that put the network together and keep it running

CIO.com
Security Quiz: How Well Do You Know the Insider Threat?
Inside attackers tend to be motivated by revenge and greed and make use of privileges that should have been revoked or limited, according to quiz

V3
ArcSight Upgrades Tackle The Insider Threat
Enterprise Security Manager gets an upgrade to better combat security issues posed by insiders, analyzing who had access to to data at what time, for example

SOFTPEDIA
Security Researchers Express Concern over PlayStation 3 Hack
Recent hack that lets anyone create code that runs on PlayStation 3 gaming systems could serve as a catalyst for malware development on the PS3

TECHEYE
Cyber Attacks On Hospitals And Power Grids "Likely"
The rollout of smart meters and the slow adoption of patches in the utilities and energy sectors leaves security weak, especially to disgruntled insiders, according to a study by the Georgia Tech Information Security Center

TECH HERALD
NCSAM: Trust Abused - Looking At Threats From The Inside
Imperva executive discusses the threat posed by insiders

NETWORK WORLD
State IT Security Pros Feeling Big Budget Squeeze
States need more centralized authority and a large budget to secure their networks, finds a study conducted by the National Association of State CIOs

GOVERNMENT COMPUTER NEWS
Report: WikiLeaks Source Exploited Security Flaw
A U.S. State Department program lacked a feature that could have alerted officials to the unauthorized download of diplomatic cables

VERIZON
2010 Data Breach Investigations Report
An analysis of the 141 cases worked by Verizon's Incident Response Team or the U.S. Secret Service in 2009. Insiders were a factor in 48 percent of the cases.

EWEEK
Fighting Insider Threats Spotlighted at DEFCON Conference
An analysis of 18 different insider attacks by Fortify Software researchers finds most took months to plan. The biggest factor spurring attacks? The economic downturn.

NEXTGOV
What About Countering Insider Threats?
The Defense Information Systems Agency requests less than 1 percent of its $289 million budget for information systems security operations and maintenance on systems to prevent insider attacks.

SAN FRANCISCO CHRONICLE
Cybercrime Costs Firms $3.8 Million Yearly
A four-week survey of 45 U.S. firms finds that the group as a whole suffered 50 successful attacks per week, with losses ranging from $1 million to almost $52 million.

INFORMATIONWEEK
Wi-Fi Deployments Vulnerable To New Insider Attack, Says AirTight Networks
A vulnerability in the WPA2 wireless security protocol allows malicious insiders to block network traffic or steal confidential information, says AirTight Networks.

TECHREPUBLIC
The Barbarians Are Already Inside The Gates: Mitigating Insider Threats
Controls are necessary to prevent disgruntled employees and malicious insiders from hurting the business.

IT BUSINESS EDGE
Five Steps to Preventing Insider Data Breaches
Identifying your organization's privileged accounts and changing the credentials to those accounts regularly are two of the ways to secure against insider activity.

BANK INFO SECURITY
A Tale Of Three Breach Reports
Three recent breach reports agree that outside attackers cause more data loss and harm than insiders, but disagree over whether most insiders are malicious or not.

HELP NET SECURITY
Insidious: How Trusted Employees Steal Millions And Why It's So Hard For Banks To Stop Them
New book sheds light on how internal attacks work, and what companies can do about them

OFFICE OF INADEQUATE SECURITY
Breach Reports Decline In 2009, But What Does It Mean?
Did incidents actually decline during the year, or are companies simply deciding not to report them?

WASHINGTON POST
TSA Nominee Misled Congress About Accessing Confidential Records
Nominee may have inappropriately accessed a federal database, violation privacy laws

HELP NET SECURITY
Credit Card Provider Suffers Breach, Personal Data Lost
When laptop is stolen from third-party contractor, MBNA is forced to report data loss


Best Of Web Archive:
Most Recent | 1| 2| 3| 4








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)