How (And Why) Attackers Choose Their Targets
To build a sure defense, you need to know what makes you a juicy target. Here are some tips
Can Glass-Box Scanning Find Your Real Bugs?
When it works, hybrid -- or 'glass-box' scanning -- combines dynamic, black-box analysis with static, white-box code analysis to find bugs and cut down on false positives
Adobe Calls For Defensive Approach In Security Research
Mitigation methods the emphasis at Adobe
FDIC Warns Of 'High Risk' Payment Processors
Some third-party payment processing services may not be secure, commission says
Financial Services Industry Employs Microsoft SDL In New Secure Software Model
Microsoft meanwhile releases new data showing major drop in bugs and exploitable vulnerabilities in its software over the past year and a half
Famed Hacking Contest Gets Facelift
‘Pwn2Own’ will up the ante with more prolonged contest, fewer targets, more payout for first-, second-, third-place winners -- plus an extra Google bounty for cracking Chrome
Third-Party Vulnerability Counts Down? Not Quite
Trend data from Frost & Sullivan shows that vulnerabilities reported by third parties were lower in 2011, but companies such as Secunia and TippingPoint are seeing greater demand
New Version Of Carberp Trojan Targets Facebook Users
Malware attempts to steal money by duping the user into divulging an e-cash voucher
Possible New Zero-Day Windows 7 Flaw Under Investigation
Specially crafted webpage viewed with Safari causes 'blue screen of death,' remote execution
Security Holes In Software Decreased This Year, Early Data Shows
The number of vulnerabilities disclosed to the public fell in 2011, as did the proportion of flaws that were exploited -- is secure development paying off?
Zero Day Initiative: One Year After Throwing Down The Disclosure Gauntlet
Vulnerabilities reported mostly in big-name software vendors' products, and SCADA zero-day flaws on the rise, according to ZDI's annual report
Exploited Apps Depend On Attack Vector
While some data shows Java to be the most attacked software application, other software gives the program a run for the title
The Dark Side Of Java
Metasploit adds new module for latest Java attack as the application is rapidly being targeted by cybercriminals
Firms Slow To Secure Flaws In Embedded Devices
While operating systems and PC applications have evolved fast patch mechanisms, the proliferation of slow-to-patch embedded devices leaves companies vulnerable.
Windows 8 To Streamline Patching Reboots
Only one restart per month to coincide with Patch Tuesday
Zero-Day BIND Flaw Crashes DNS Servers
ISC issues temporary patch to stop more DNS BIND server crashes, but no details yet on the actual flaw
Product Watch: New RedSeal App Lets Enterprises Benchmark Security Risk, Attack Surface
New RedSeal 5 application offers a way to deliver dashboards on enterprise security posture, company says
The Curious Case Of Unpatchable Vulnerabilities
The annual Verizon breach investigations report has consistently shown that fewer -- and in the most recent edition, only five of 381 -- attacks exploit vulnerabilities that could have been patched. Should companies re-evaluate their priorities?
A Security Pro's Guide To Patch Management
With so many applications and vulnerabilities in the enterprise, the question is which patches to deploy first -- and which ones don't need to be deployed at all, experts say
Time To Automate Web Defenses?
Tying vulnerability scanners and Web application firewalls together can help tighten up Web security without developer pain, but trust is still a problem.
Metasploit For The Masses
New version of free Metasploit tool aimed at newbie penetration testers
More Exploits For Sale Means Better Security
Selling exploits can help companies test their systems, but is there room for an independent market?
Flaw In HTC Android Phone Exposes User Data, Researcher Says
Android flaw could enable attackers to steal smartphone users' GPS location, SMS data, and phone numbers; manufacturer says it is looking into the issue
Study: Mobile Exploit Releases On Track To Double This Year
Mobile exploits, critical vulnerabilities on track to skyrocket by the end of 2011, IBM X-Force study says
In-House Malware Analysis: Why You Need It, How To Do It
In-depth malware analysis can be part of a comprehensive vulnerability management strategy. Here's how to get started
Microsoft Claims Another Botnet Takedown
After taking down Rustock botnet, software giant says it has neutralized Kelihos
Outdated Browsers Leave Many Enterprises Vulnerable To Attack
Despite efforts to get users to update browsers, the search for better security only begins with a patch.
Free 'HoneySink' Tool Captures Botnet Traffic
First open-source 'sinkhole' tool released by Honeynet Project
Microsoft Still Spots Lots Of Zeus Infections
Rumors of Zeus' merger into SpyEye may have been exaggerated -- for now, anyway
Windows 8 To Come With AV Baked In
Microsoft will knit its Microsoft Security Essentials into the next-generation Windows OS
Managing The Risk Of Flaws In Third-Party Software
Companies need to focus on finding and resolving vulnerabilities in software libraries on which their own products rely, say experts.
Tech Insight: Three Hardware Tools For Physical Penetration Testing
How to hack yourself like a social engineer would do
Breached CA Underscores Need To Examine Who You Trust
Who do you trust? Most companies don't know, but they need that information to close vulnerabilities
New Free Tools Simplify Analysis Of Android Malware
What did you do over your summer break? Two graduate students wrote tools that address heightened concern over eventual attacks against the Android platform
Workarounds Issued For 'Apache Killer' Attack
Apache team spells out mitigation strategies, patch expected within 24 hours
Researcher To Release Free 'Slow HTTP Attack' Tool
'Slowhttptest' could be expanded to test for so-called "ApacheKiller" hack
Botnets And Google Dorks: A New Recipe For Hacking
Attackers finding new ways to automate the use of Google search engine to hunt for vulnerabilities, Imperva researchers say
'Willysy' osCommerce Injection Attack Affects More Than 8 Million Pages
Malware exploits vulnerability in popular online merchant platform, Armorize says
Researchers Launch Tool To Close The Development-Testing Gap
A cautious semi-automated approach the way to go, Black Hat researchers sCurrent vulnerability scanning tools aren't keeping pace with Web app development technology, Black Hat speakers say
Metasploit Pro Gets SIEM, Cloud Integration
Rapid7's new Metasploit Pro release, 4.0, automates more workflow tasks
Most IT Security Pros Disabling Security Functions In Favor Of Network Speed
New survey shows dilemma faced by organizations over performance tradeoffs with network security products
Researchers Prepare Google Hacking Tools For Black Hat -- Hot Diggity!
Family of search tools to be launched at Black Hat conference will help security teams and pen testers find searchable flaws before bad guys, Stach & Liu researchers say
More Windows Kernel Vulnerabilities May Yet Emerge, Researcher Says
After issuing dozens of patches this year to shore up security vulnerabilities in the Windows kernel, Microsoft may still have more work to do, Black Hat speaker warns
New Research Names Top 10 Malware Delivery Networks
Malware delivery networks are an emerging category of malicious networks that are distinct from botnets, Blue Coat study says
Enterprises Should Patch For Vuln Criticality, Not App Popularity, Researchers Say
Organizations could reduce risk significantly by changing patching priorities, according to Secunia
Researchers Report New, 'Indestructible' Botnet
TDL-4 botnet features new defenses, Kaspersky researchers say; other experts not so sure about the "indestructible" part
LulzSec Takes Credit For CIA Site Takedown
After cracking a Senate website and exposing 26,000 porn users, hacker group LulzSec targets CIA
Enterprises Skimp On Testing Third-Party Code
70 percent run security, vulnerability assessments on internal code, but only 35 percent do the same for third-party code they bring in-house, Forrester/Coverity report finds
Disabling Features Make Some Microsoft Bugs Unexploitable
eEye study finds that disabling two well-known features in Microsoft products would prevent attackers from exploiting 12 percent of vulnerabilities
Another Researcher Hit With Threat Of German Anti-Hacking Law
German software firm warns researcher who disclosed a vulnerability in its software and offered to help
How (and Why) Attackers Choose Their Targets
To protect company and customer data, we need to determine what makes it so vulnerable and appealing. We also need to understand how hackers operate, and what tools and processes they rely on. In this report, we explain how to ensure the best defense by thinking like an attacker and identifying the weakest link in your own corporate data chain.
Security Pro's Guide to Patch Management
It's no longer sufficient to patch just Windows, Office and IE. With the massive array of applications now residing on enterprise PCs, and the proliferation of mobile and cloud-based applications, your business is far too vulnerable to exploitation unless you have a solid strategy for patch prioritization, deployment and quality assurance. Follow these steps to put your plan in place.
In-House Malware Analysis: Why You Need It, How to Do It
Vulnerability management identifies and closes exploitable holes in your enterprise network. But some systems remain vulnerable, and traditional antivirus and perimeter defenses are proving less effective against sophisticated malware, targeted attacks and zero-day exploits. In this report, we show you how malware analysis, tied closely to incident response, is an essential complement to enterprise vulnerability management programs.
Other reports from the Vulnerability Management Tech Center:
| Sponsored by: |
The Ponemon Institute 2012 State of the Endpoint
The 2012 State of the Endpoint study, sponsored by Lumension and conducted by Ponemon Institute, determines how effective organizations are in the protection of their endpoints and what they perceive are the biggest obstacles to reducing risk. The study is focused on four topics on the state of endpoint security: risk, productivity, resources and complexity.
The CISOs Guide to Measuring IT Security
Many organizations continue to blindly blaze into new technology territory without fully understanding the inherent IT risks. As a CISO, you must be able to facilitate business productivity without the risk. If you can accurately measure your security posture and communicate in terms of business risk as opposed to bits and bytes, you can effectively gain buy-in from key executives on important security initiatives. Learn the key steps to enhancing your security visibility so that you have a voice at the executive table.
Think Your Anti-Virus Software Is Working? Think Again
We've been so bombarded by computer viruses, worms, Trojan horses and other malware that we've become acclimated to their presence. We subscribe to an anti-virus (AV) offering and hope for the best. Trouble is, AV hasn't been keeping up. Studies show that even though most organizations use AV, more and more are succumbing to attacks. It's time to shift from the status quo to a new, more effective endpoint security approach, called intelligent whitelisting, which affords greater protection, productivity, and efficiency.
Unruly USB Devices Expose Networks to Malware
It's pretty easy for organizations to get so wrapped up about what goes out on USB drives that they forget to protect against what comes in their environments via USB. And with attacks inflicting increasingly greater damage following uncontrolled connection, it's time that organizations got serious about this threat. The key to USB security is balancing productivity with protection.
Reducing Local Admin Exposure Through Application Whitelisting
In today's Windows environment, users are accustomed to having local administrator privileges that allow them to download a variety of applications and potentially misconfigure their PCs. While standard wisdom may be to simply solve the problem by revoking local administrator rights on users' systems, the reality is that this may not be an option. Fortunately, there's hope - through application whitelisting.
MORE NEWSFEED >>>