Powered By InformationWeek Business Technology Network
 
Welcome Guest. | Log In | Register | Membership Benefits

All News

BeyondTrust Buys eEye  May 10, 2012
eEye co-founder Marc Maiffret now CTO of BeyondTrust

FBI Warns Travelers Using Hotel Networks About New Attack  May 10, 2012
The FBI says attackers are trying to trick users into installing malware with promises of software updates

Linux Users Beware: Patch New Samba Flaw 'Immediately'  April 11, 2012
Samba bug could spur targeted attacks or a worm -- but not all affected systems will get patched

Massive Mac Trojan Attack Still Under Way  April 10, 2012
New, free Flashback Trojan detection and removal tool available from Kaspersky Lab; snapshot of bot counts dropping

Big Mac Botnet Mostly Made Up Of U.S. Machines  April 06, 2012
Major 'wake-up call' for Mac users as Apple OS X Java flaw exploit spreads

Lesson From Pwn2Own: Focus On Exploitability  March 29, 2012
Talented programmers can create attack code quickly, suggesting that firms need to focus on patching easily exploitable -- not just exploited -- flaws

Command Injection Attacks, Automated Password Guessing On The Rise  March 27, 2012
Spam, vulnerabilities, exploit code all on the decline, IBM X-Force report says

Choosing The Right Vulnerability Scanner For Your Organization  March 23, 2012
Vulnerability scanning plays a key role in both security administration and compliance. But which tools are right for you? Here are some tips on how to decide

Simple Settings That Could Curtail Some Attacks  March 20, 2012
Free tool created by eEye Digital Security checks health of key configurations that can reduce risk

The End Of Vulnerabilities?  March 15, 2012
On a global scale, bugs are never going away, but in specific products, early evidence reveals that companies are having success in weeding out flaws

Microsoft Flaw Demonstrates Dangers Of Remote Desktop Access  March 14, 2012
Fear is that attackers will soon come up with exploits for targeted attacks, worms

How To Use Google To Find Vulnerabilities In Your IT Environment  March 13, 2012
The bad guys use search engines to seek out weak spots. Here's how to beat them to the punch

Doman Generation Algorithms Quietly On The Rise, Researcher Says  March 12, 2012
Thought to be dead, DGAs are increasingly being used for botnet command and control, Damballa says

Rogue AV Campaign Infects More Than 200,000 Web Pages  March 07, 2012
Websense has detected a massive infection campaign targeting users with rogue antivirus

Microsoft Studies 10 Years Of Malware And Threats  March 05, 2012
Special report maps malware evolution, and how the least-infected regions keep botnets, other threats at bay

Chrome Shines Bright In Controversial Security Fight  March 02, 2012
The major browsers have all made solid strides in security in the past few years, but Chrome's sandbox makes Google's browser a harder target, researchers say

Fixing Vulnerabilities On A Shoestring  March 01, 2012
A study of 15 vulnerability remediation projects finds only a third of time is actually spent fixing flaws. More on the costs and how to reduce them

Making Windows Secure From The Ground Up  February 16, 2012
Microsoft's Steve Lipner, who was a major proponent of the need for a secure development methodology, talks about the successes of Microsoft's push -- and the costs

Nearly 80% Of All Bugs Are In Third-Party Apps   February 14, 2012
Secunia annual report says only 10 percent of bugs in 2011 were in Microsoft software

How (And Why) Attackers Choose Their Targets  February 07, 2012
To build a sure defense, you need to know what makes you a juicy target. Here are some tips

Can Glass-Box Scanning Find Your Real Bugs?  February 03, 2012
When it works, hybrid -- or 'glass-box' scanning -- combines dynamic, black-box analysis with static, white-box code analysis to find bugs and cut down on false positives

Adobe Calls For Defensive Approach In Security Research  February 02, 2012
Mitigation methods the emphasis at Adobe

FDIC Warns Of 'High Risk' Payment Processors  February 01, 2012
Some third-party payment processing services may not be secure, commission says

Financial Services Industry Employs Microsoft SDL In New Secure Software Model  February 01, 2012
Microsoft meanwhile releases new data showing major drop in bugs and exploitable vulnerabilities in its software over the past year and a half

Famed Hacking Contest Gets Facelift   January 23, 2012
‘Pwn2Own’ will up the ante with more prolonged contest, fewer targets, more payout for first-, second-, third-place winners -- plus an extra Google bounty for cracking Chrome



Vulnerability Management Reports

report Choosing the Right Vulnerability Scanner for Your Organization
Vulnerability scanners can be used to help detect and fix systemic problems in an organization's security program and monitor the effectiveness of security controls. However, a vulnerability scanner can improve the organization?s security posture only when it is used as part of a vulnerability management program, in which products, processes and people are working together to find, identify, prioritize and mitigate threats. Here are some tips on choosing and implementing vulnerability scanners in your enterprise.

report Using Google to Find Vulnerabilities In Your IT Environment
Attackers are increasingly using a simple method for finding flaws in websites and applications: they Google them. Using Google code search, hackers can identify crucial vulnerabilities in application code strings, providing the entry point they need to break through application security. Sound scary? It is, but there is good news: You can use these same methods to find flaws before the bad guys do. In this special report, we outline methods for using search engines such as Google and Bing to identify vulnerabilities in your applications, systems and services--and to fix them before they can be exploited.

report Security Pro's Guide to Patch Management
It's no longer sufficient to patch just Windows, Office and IE. With the massive array of applications now residing on enterprise PCs, and the proliferation of mobile and cloud-based applications, your business is far too vulnerable to exploitation unless you have a solid strategy for patch prioritization, deployment and quality assurance. Follow these steps to put your plan in place.

Other reports from the Vulnerability Management Tech Center:




Featured Webcasts
Featured Whitepapers
Featured Reports