Welcome Guest. | Log In | Register | Membership Benefits

All Storage Security Stories

Application Security Inc.'s New DbProtect Active Discovery Finds Forgotten And Previously Unknown Databases

    February 15, 2012
DbProtect Active Discovery uses database protocol-based validation

Product Watch: Startup Rolls Out New Approach To User Authentication

    February 14, 2012
WWPass offers single device that authenticates users to many systems; secure storage technology protects data by storing it in geographically distributed fragments

Backupify Announces Security Best Practices, Adds Multiple Layers Of Protection To Cloud Application Data Backup

    February 01, 2012
Backup solutions provider successfully completes penetration testing

Survey Of Security And Audit Pros, DBAs Reveals Responsibility Disconnect, Lack Of Management Commitment Impedes Database Security Efforts

    January 30, 2012
Results reveal that the greatest challenge to database security may actually come from organizational issues

Vormetric Announces Record Revenues For 2011

    January 26, 2012
Revenues increased 40 percent year over year

Application Security, Inc. To Host Webinar Roundtable To Help Bridge The Gap Between Security Pros And DBAs

    November 23, 2011
AppSecInc’s own CTO Josh Shaul will lead the discussion

Idera Announces SQL Compliance Manager 3.5

    November 16, 2011
Solution has added new detailed tracking of potentially dangerous activity on SQL Servers

INSIDE Secure And IDT To Offer USB Security Token Solution

    November 14, 2011
INSIDE AT90SO72 is based on a high-performance, low-power, 8/16-bit enhanced RISC CPU

Vyatta Adds Virtual Firewall to dinStack Technology Coalition

    November 01, 2011
dinCloud secures hosted virtual desktop with Vyatta Network OS

Sourcefire To Extend Intrusion PreventionTo Red Hat Enterprise Virtualization Platform

    October 24, 2011
Also joins the Open Virtualization Alliance

eEye Announces Industry’s First Vulnerability Management Solution For Virtualized Applications

    October 20, 2011
Solution is now available as part of eEye's Retina suite of products

Blancco, DestructData Partner To Expedite Certified Data Erasure Of Loose Drives

    October 05, 2011
Blancco’s certified data erasure software will power a series of DestructData erasure appliances for loose drives

Imation Completes Acquisition Of IronKey's Security Hardware Business and Enters Partnership With IronKey For Online Services

    October 05, 2011
Imation receives an exclusive license from IronKey for its secure storage management software and service

TRICARE, SAIC Report Loss Of Data On 4.9 Million

    September 29, 2011
Loss of backup tapes at TRICARE puts personal data of military personnel at risk

Kingston Introduces New Ultra-Secure USB Flash Drive

    September 28, 2011
DataTraveler 6000 meets data-at-rest regulations

Imation To Acquire IronKey's Security Hardware Business

    September 20, 2011
Imation will receive an exclusive license from IronKey for its secure storage management software and service

Rapid7 Releases Nexpose 5.0

    September 19, 2011
Nexpose 5.0 addresses security challenges presented by virtualization technologies and increase of malware

New Free Tool Helps Gather Attackers' 'Footprints'

    August 10, 2011
Researchers show how to gather 'footprints' left behind by attackers

When Consumers Go To The Cloud, Businesses Should Watch Out

    June 30, 2011
Companies should take a look at what cloud services their employees are using following last week's authentication bug at Dropbox, security experts say

Dataguise Announces Enterprise Security Intelligence For Data Privacy

    June 24, 2011
Dataguise will introduce DgSuite 3.5 featuring DgDashboardT for actionable intelligence

Imperva Files Registration Statement For Proposed Initial Public Offering

    June 21, 2011
Number of shares, price range have not yet been determined

Trustwave Introduces File Integrity Monitoring In The Cloud

    June 21, 2011
FIM checks for additions, modifications, or deletions of sensitive files or other stored data

Application Security, Inc. Adds Real-Time Blocking And Virtual Patching To Database Activity Monitoring Solution

    June 13, 2011
DbProtect now includes rights management support for DB2 and Sybase environments

FireHost Upgrades Secure Hosting Service

    June 09, 2011
Announces Solid State Drive Storage and Virtual Load Balancing that’s specific to cloud environments

EldoS Corp. Unveils Security For Windows Phone 7, LDAP, And WebDAV Protocols

    June 02, 2011
SecureBlackbox includes HTTP(S) server components and WebDAV client and server components

Researchers Devise Hardware-Based Encryption For 'Instant-On' Devices

    June 01, 2011
New algorithm protects user data stored long-term in main memory in next-generation smartphones, laptops, desktops

Symantec To Acquire Clearwell

    May 19, 2011
Clearwell's eDiscovery solution enhances Symantec’s Enterprise Vault eDiscovery capabilities

BeyondTrust Acquires Lumigent Technologies

    May 17, 2011
In addition, BeyondTrust announced the release of PowerBroker Database

AppSec's AppDetectivePro Earns Common Criterial Certification

    May 02, 2011
AppDetectivePro discovers, examines, report,s and proposes fixes for database security vulnerabilities and misconfigurations

AppSec And Securosis Team Up To Provide Comprehensive Guide For Database Security Programs

    April 13, 2011
Guide provides insight into all common database security tasks

McAfee Delivers Comprehensive Database Security Solution

    March 23, 2011
Database security is a key element of McAfee’s overall strategy

Backup Files Put Database Information At Risk

    March 11, 2011
Cord Blood Registry breach a cautionary tale in the need for encryption, key management, and secure physical transport of database back-up media

Imperva Expands SecureSphere

    March 09, 2011
Adds agent-based monitoring and auditing for DB2 z/OS mainframe databases

Lessons Learned From WikiLeaks: Not So Much

    March 08, 2011
IT and security professionals routinely use USBs, smartphones, and tablets to move and back up confidential files, and their organizations haven't made changes in the wake of the WikiLeaks leaks

Imation Acquires ENCRYPTX

    March 03, 2011
Acquisition includes a portfolio of software solutions and intellectual property that allow enterprises to protect, encrypt, control, and manage “data at rest”

Report: Majority Of Workers Expose Businesses To Malware And Data Loss

    March 02, 2011
BlockMaster data reveals attitudes to handling portable devices, such as USBs

LogLogic Introduces Database Security Manager 4.1

    February 25, 2011
Unifies traditional security with data access controls for 360 Insight

McAfee: 75% Of Organizations Not Confident They Will Pass An Audit, Half Have Already Failed

    February 23, 2011
Survey indicated strong growth for risk and compliance products in 2011

AVG Technologies Announces 'AVG LiveKive'

    February 17, 2011
Free, cloud-based storage solution will be released in beta version next week

Identity Finder Unveils Advanced Identity Protection And Data Leakage Prevention Solution

    February 14, 2011
Identity Finder 5.0 includes new searching support for e-mail systems and enterprise servers

Kingston Digital Rolls Out Secure USB Solutions

    February 14, 2011
Kingston rolls out two fully managed, cost-effective, secure USB solutions for the enterprise

Rocela Launches Oracle Database Support Services

    February 11, 2011
DBA Support Services provide organizations with a cost effective way of managing their Oracle databases

Arrow Expands Security Portfolio With IronKey Endpoint Protection

    February 11, 2011
Companies are targeting the enterprise market and resellers that service these customers

Report: Electronic Health Information Under Attack

    February 09, 2011
Redspin report finds two-thirds of all records breached resulted from laptops or other portable media devices

BreakingPoint Unveils FireStorm Cyber Tomography Machine

    February 09, 2011
Network processor powers three-slot chassis that simulates application traffic at 120 Gbps

Sentrigo Rolls Out New Hedgehog Enterprise Suite

    January 18, 2011
New version includes added support to Hedgehog DBscanner for Sybase and MySQL

Application Security, Inc. Announces Database Activity Monitoring For DB2 On IBM z/OS

    January 12, 2011
Partners with NEON Enterprise Software to deliver enterprise security, risk and compliance solutions

Trend Micro Announces Network Attached Storage Security With Built-In Antivirus

    January 11, 2011
Trend Micro NAS Security is optimized for NAS-based Linux operating systems

Sentrigo Secures $6 Million In Series C Funding

    December 21, 2010
Round included participation from existing investors Benchmark Capital and Stata Venture Partners

Dataguise Offers Free One-Day Risk Assessment Service To Identify Unprotected Sensitive Data Across Databases

    December 09, 2010
R.A.P.I.D. Service uses Dataguise DgDiscoverT, an automated database security solution










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)