Powered By InformationWeek Business Technology Network
 
Welcome Guest. | Log In | Register | Membership Benefits

Dark Reading's Advanced Threats Tech Center is your gateway to a deeper, more technical level of news and analysis on the newest and most sophisticated cybersecurity threats. Written for security and IT professionals, the Advanced Threats Tech Center is designed to provide in-depth information and perspective on next-generation attacks, exploits, and vulnerabilities, as well as recommendations on how to stop them.

By The Numbers

‘Ware The Exploit Kits

Gray-market toolkits (exploit kits) that allow criminals to use an arsenal of exploits against would-be victims account for more than half of all threats encountered by Internet users.

Chart: Ware The Exploit Kits

 

Source: AVG, Community Powered Threat Report, Q4 2011

Blog

Author Photo Between Source Code And Cyanide

February 09, 2012

What the Symantec source-code leak really means

read more >

Around The Web

THREAT POST
Ongoing Targeted Attack Campaign Going After Defense, Aerospace Industries
Researchers have identified a strain of malwarebeing used in a string of targeted attacks against defense contractors, government agencies, and other organizations by leveraging exploits against zero-day vulnerabilities

GOOGLE BLOG
Android And Security: The Bouncer Service
Google reveals a service,code-named Bouncer that provides automated scanning of the Android Market for potentially malicious software

INFOWORLD
VeriSign Hacked Several Times, Won't Reveal The Details
The company buried the fact of the 2010 incidents involving its Internet domain service in a financial filing the following year. It only came to light in February

IDG NEWS SERVICE
Kelihos Botnet, Once Crippled, Now Regaining Strength
A botnet that was crippled by Microsoft and Kaspersky Lab last September is spamming once again and experts have no recourse to stop it

WIRED
Railroad Association Says Hack Memo Was Inaccurate
A government memo saying a railway was hacked in a targeted attack was incorrect, but a spokesperson declined to elaborate, leaving the public in the dark about what exactly was right and wrong in the memo

THREAT POST
Why Stuxnet-Like Attacks Aren't Going Away
In 2010, the German researcher made headlines as one of the security experts who initially analyzed parts of the Stuxnet worm's code devoted to manipulating programmable logic controllers by Siemens-- why Stuxnet-like attacks are here to stay

WIRED
Anonymous Goes After World Governments In Wake Of Anti-SOPA Protests
Anonymous has launched unprecedented string of attacks on government and business sites around the world, as the anger of the hive that a year ago turned on Egypt?s Mubarak regime turned on governments around the world

IDG NEWS SERVICE
SpyEye Malware Borrows Zeus Trick To Mask Fraud
A powerful bank-fraud software program, SpyEye, has been seen with a feature designed to keep victims in the dark long after fraud has taken place

MORE >>>



Advanced Threats Reports

report Smarter, Stealthier, Sneakier Malware
Increasingly sophisticated and targeted attacks are making it more difficult for organizations to detect and defend against the latest malware. In this compendium of recent coverage from Dark Reading, you?ll get a look at some of the newest -- and most dangerous -- malware on the Web, and what you can do to stop it.

report Secure Software Development Lifecycles: Reducing Risk Throughout the App Dev Process
The application layer has long topped the attacker hit list, and we continue to hear about data breaches exploiting software vulnerabilities. Yet secure application development remains a low priority in most enterprises. In this report, we provide a blueprint for making security an integral part of the software development life cycle.

report Stuxnet Reality Check: Are You Prepared for a Similar Attack?
Stuxnet is a sophisticated, targeted weapon that proved utilities' seemingly isolated SCADA networks could be compromised, potentially disrupting energy production and distribution. In this report, we'll explain how Stuxnet penetrated Iranian nuclear facilities and propagated through their networks, and guide you in protecting against a comparable attack on your organization.

Other reports from the Advanced Threats Tech Center:

Related Content

Proactively Eliminate Risk in Software: HP Fortify Software Security Center
With business software virtually accessible from anywhere, applications now overreach standard perimeter defenses. Enterprises are finding that the effective way to secure software is by employing a Software Security Assurance (SSA) program to proactively eradicate risk.

Expert Guide to Application Security - Real-time Hybrid Analysis
Explore the next generation of hybrid security analysis - what it is, how it works, and its benefits. This white paper details how hybrid application security enables organizations to resolve critical software security issues faster and at a lower cost than any other available technology.

A Mainstay Partners Study: Does Application Security Pay?
Measuring the Business Impact of Software Security Assurance Solutions: a study of 17 organizations that implemented solutions from Fortify Software, combining industry research and benchmark analysis to identify, qualify, and quantify the full range of benefits seen from their SSA investments.

Aberdeen Benchmark Report: Securing Your Applications
Is application security actually "free?" Aberdeen's research confirms that the annual cost of application security initiatives is outweighed by the benefits. Review how all respondents, from Best-in-Class to Laggards, experienced a positive return on their annual application security investments.

White Paper: Rationalizing AppSec Using Fortify
An evaluation of Fortify's software security assurance (SSA) solutions in context of the cumulative impact of software security vulnerabilities and the investments made to address them. Read IANS' assessment and key insights from end users in real-world enterprise software development environments.