Welcome Guest. | Log In | Register | Membership Benefits

All Application Security Stories

Trend Micro Releases HijackThis Source Code To sourceforge.net

    February 17, 2012
HijackThis scans a computer to find settings changed by spyware, malware, or other unwanted programs

PandaLabs Reports Presence Of New Powerful Bot Spread By Email

    February 16, 2012
Ainslot.L bot scans computers and removes other bots it finds

Commtouch Launches Outbound Spam Protection Module For Parallels Plesk Panel

    February 15, 2012
Solution prevents blacklisting of hosting provider networks

How To Defend Your Database From Malicious Insiders

    February 13, 2012
The biggest threat to your sensitive information might be those who are authorized to access it. Here are some tips on how to defend your organization

StopTheHacker Launches

    February 13, 2012
New Web security-as-a-service firm comes out of stealth mode with new funding and new services

ControlScan Launches ProTect Managed Security Services

    February 10, 2012
Service improves the security of websites and Web applications

Tech Insight: Penetration-Testing Your Cloud Provider

    February 10, 2012
Vulnerability assessments and penetration tests can be a great way to validate the security posture of these organizations

Websense Reports Record Revenues For Fourth Quarter And Fiscal Year 2011

    February 09, 2012
Fourth quarter revenue of $92.7 million, up 7 percent year-over-year

New Privacy, Security, Anti-Tracking Software For Internet Explorer

    February 08, 2012
Cocoon prevents computer from directly touching the Internet

New Data Shows Rapid Surge In Phishing Email

    February 08, 2012
Yet spam in December 2011 and January 2012 at the lowest levels in five years

Big Data Means Big Security Problems, Study Says

    February 03, 2012
Large data stores often contain "toxic" data that is sensitive to business, Forrester report says

Adobe Calls For Defensive Approach In Security Research

    February 02, 2012
Mitigation methods the emphasis at Adobe

Financial Services Industry Employs Microsoft SDL In New Secure Software Model

    February 01, 2012
Microsoft meanwhile releases new data showing major drop in bugs and exploitable vulnerabilities in its software over the past year and a half

Google, Facebook, Bank Of America Behind New Email Security Standard

    January 30, 2012
New specification for preventing phishing and email domain abuse likely to help email security, but will enterprises adopt it?

DNSSEC Error Caused NASA Website To Be Blocked

    January 25, 2012
Comcast’s new DNSSEC-based service detected improper signing of NASA site

Zscaler ThreatLabZ Releases Free Service To Analyze Web Risk

    January 25, 2012
Zulu analyzes URLs and assesses risk posed by suspicious Web content

Qualys Launches New Freemium Web Security Service For SMBs

    January 20, 2012
FreeScan performs comprehensive scans on websites or publicly facing IP addresses

F5 Announces Earnings For Q1 FY2012

    January 20, 2012
Revenue up 19.9% year-over-year

Klocwork Insight 9.5 Creates New Benchmark For Developer-Friendly Source Code Analysis

    January 20, 2012
Klocwork Insight introduces an on-the-fly user model

Federal Reserve Bank Contractor Arrested For Alleged Code Theft

    January 20, 2012
Suspect admitted to stealing U.S. Treasury Dept.-owned program from the bank for use in his own private business

Sandia Labs Offers Online DNSSEC Tool

    January 12, 2012
New free visualization tool helps government agencies, businesses in their DNSSEC implementations

Prolexic Revenues Increase 45 Percent In 2011

    January 12, 2012
Significant investments in staffing, R&D and network capacity to accommodate growth

Have A Comment? Dark Reading Offers New Commenting System

    January 06, 2012
New Dark Reading commenting platform will make it easier, more secure for readers to add their input to DR stories

Saudi Hackers Steal, Leak Israeli Credit Card Accounts

    January 03, 2012
Self-professed arm of Anonymous leaks thousands of account numbers and associated information

.TK Is Growing Exponentially To Become The Largest And Safest Country Code Domain In 2012

    December 28, 2011
Dot TK is the only domain name registry that requires having an active website on each domain

Siemens To Patch Major SCADA Authentication Holes Next Month

    December 22, 2011
Researcher discloses serious security flaws in Siemens products

7 Housekeeping Duties For Better Database Security In 2012

    December 21, 2011
Segmenting, hardening, encrypting, insuring, and planning -- a few good New Year's resolutions for database administrators

Yubico Delivers Secure Access For Web Sites And CMS

    December 13, 2011
Swedish ISP customer Frobbit! is using the YubiKey to ensure secure access to its Wordpress site

Google Wallet Stores Some Payment Card Data In Plain Text

    December 12, 2011
'Significant' amount of unencrypted data leaves Android phones at risk, researchers say

Qualys Launches New Version Of Web Application Scanner

    December 09, 2011
QualysGuard WAS uses the cloud/QualysGuard SaaS platform

NT OBJECTives Releases Free SQL Invader

    December 09, 2011
Free tool provides pen testers and developers the ability to demonstrate SQL Injection vulnerabilities in Web applications

Government Agencies Harbor The Most Vulnerable Applications

    December 08, 2011
Newest Veracode State of Software Security report finds SQL injection flaws declining overall in all industries

New Fidelis Tool Offers Greater Visibility Into Potential Microsoft Email Threats

    December 07, 2011
Decoder for Fidelis XPS helps to eliminate outbound and inbound threats

New Zero-Day Adobe Attack Under Way

    December 06, 2011
Adobe working on emergency patch for Adobe Reader and Acrobat 9.x for Windows

Centrify Centralizes Management Of Mac User Populations In The Enterprise

    November 29, 2011
Centrify DirectControl for Mac OS X includes support for automated digital certificate enrollment

Former Iron Mountain Chief Bob Brennan Becomes CEO Of Veracode

    November 29, 2011
Brennan will help Veracode extend its footprint within the rapidly growing application security space

Who's In Your Database? A Look At Access Control Strategies

    November 17, 2011
What's the best way to provision database users and control access to sensitive data? Here's a guide that offers some answers

Symantec Rolls Out Cloud-Based Instant Messaging Security Service

    November 14, 2011
IMS.cloud is designed to scan every IM sent to or coming from an organization

Siemens Joins SAFECode

    November 14, 2011
Dr. Frances Paulisch, head of the company-wide Software Initiative at Siemens, will join SAFECode’s board

Adidas Takes Websites Offline Following Security Breach

    November 08, 2011
Hackers claim to have acquired and posted 500,000 email addresses and clear-text passwords from Adidas websites

Security Still An Afterthought, Study Says

    November 04, 2011
Despite widespread threats and breaches, most enterprises still ignore security issues when building new apps, Ernst & Young survey says

Tech Insight: Managing Privileged Accounts

    November 04, 2011
Strategies for identifying, managing, and auditing privileged accounts

A Security Pro's Guide To Patch Management

    November 03, 2011
With so many applications and vulnerabilities in the enterprise, the question is which patches to deploy first -- and which ones don't need to be deployed at all, experts say

Secunia Launches Vulnerability Coordination Reward Program

    November 02, 2011
Researchers to be rewarded for coordinating software vulnerabilities

Veracode: Top 5 Most Exploited App Security Flaws

    October 28, 2011
Flaws that could be lurking in your organization's software portfolio

NortonLive Ultimate Help Desk Now Supports Macs

    October 27, 2011
NortonLive Ultimate Help Desk now supports Mac OS 10.5 and above

IBM Closes on Acquisition Of Q1 Labs

    October 26, 2011
Q1 Labs will join the newly formed Security Systems division

Time To Automate Web Defenses?

    October 25, 2011
Tying vulnerability scanners and Web application firewalls together can help tighten up Web security without developer pain, but trust is still a problem.

RSA Delivers Integrated, Strong And Invisible Authentication For Mobile Applications

    October 12, 2011
Releases SDKs that integrate strong one-time password or risk-based authentication into mobile apps without need for separate authentication device

SonicWALL Announces Suite Of Application Traffic Analytics Tools

    October 11, 2011
Software suite provides insight into real-time and historical network bandwidth utilization, application traffic, security threats, and employee productivity










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)