News & Commentary

Content posted in October 2009
Page 1 / 3   >   >>
New Project Takes Aim At Web Vulnerabilities
Commentary  |  10/31/2009  | 
New open source honeypot sets bait to lure attackers and to gain first hand information on current attack techniques underway.
LinkedIN With 'Bill Gates'
Commentary  |  10/30/2009  | 
Bill Gates invited me to join his LinkedIN network. OK, so it wasn't really Bill Gates, but as far as my email system, spam filter, and email client were concerned, it's perfectly normal for Gates to send me a LinkedIn invitation.
FDIC Warns Banks Of 'Money Mule' Bank Customers
Quick Hits  |  10/30/2009  | 
Financial institutions should be on the lookout for money mules depositing funds stolen via electronic file transfers, says the Federal Deposit Insurance Corp.
Facebook Wins $711 Million From Spammer
News  |  10/30/2009  | 
In addition to financial damages, Sanford Wallace, among the first to be crowned "Spam King," may face jail time.
Federal CIO Kundra Plans Cybersecurity Dashboard
News  |  10/30/2009  | 
The White House, which recently introduced a FISMA reporting tool, outlines plans for new cybersecurity metrics and a dashboard for tracking progress.
Tech Insight: Developing Security Awareness Among Your Users
News  |  10/30/2009  | 
Skip the 'Wall of Shame' and instead try promotional events, penetration testing your users
Global CIO: SAP Eliminates All-Up-Front Payment Requirement
Commentary  |  10/30/2009  | 
In a striking move, SAP is extending to 580 very large customers a plan allowing them to spread payment across multiple years instead of making one big capital-expense payment up front.
CSI Speakers Offer Advice On Risk Assessment, Reporting
News  |  10/30/2009  | 
Security professionals must not be able to only evaluate risk, but also report it in a way top executives can understand, experts say
Getting To Know Your Infrastructure
Commentary  |  10/29/2009  | 
Knowing your network is a fundamental step for building a successful vulnerability management (VM) project.
New Honeypot Mimics The Web Vulnerabilities Attackers Want To Exploit
News  |  10/29/2009  | 
New open-source Honeynet Project tool toys with attackers by dynamically emulating apps with the types of bugs they're looking for
US-CERT Warns Of BlackBerry-Spying Application
Quick Hits  |  10/29/2009  | 
Free PhoneSnoop app listens in on BlackBerry users
NSA To Build $1.5 Billion Cybersecurity Data Center
News  |  10/29/2009  | 
The massive complex, comprising up to 1.5 million square feet of building space, will provide intelligence and warnings related to cybersecurity threats across government.
Global CIO: Hewlett-Packard's Hurd Says Bad IT Means A Bad CEO
Commentary  |  10/28/2009  | 
Hurd offers a startling observation about how the roots of bad IT almost always reside in the corner office, and he explains how HP attempts to address the needs of both the CEO and the CIO.
Facebook Phishing Attack Powered By Zeus Botnet, Researchers Say
Quick Hits  |  10/28/2009  | 
Scam email messages being generated at a rate of 1,000 per minute
iPhone, BlackBerry, Palm Pre All Vulnerable To Spear-Phishing Experiment
News  |  10/28/2009  | 
Phony LinkedIn invitation from 'Bill Gates' lands in smartphone inboxes
Know Your Tools
Commentary  |  10/28/2009  | 
Ever have one of those days where nothing really seems to go right? You're working on something that should be simple and it ends up throwing seemingly unexplainable errors back at you no matter what you try? Then when it does work, you're not sure what you changed that fixed it. Yeah -- me, too.
Global CIO: Greenpeace Shakedown Targets Google, Microsoft, And IBM
Commentary  |  10/28/2009  | 
Greenpeace is mounting a major assault on the business practices of not just those three companies but the entire IT industry. They will lie to get what they want--and here's the proof.
File Virtualization, The Ultimate Cloud Gateway?
Commentary  |  10/28/2009  | 
In our last entry we talked about the use of cloud storage as a backup target, but another ideal use case for cloud storage is to use it as an archive area. Almost every IT organization has old data that they want or must keep, but are struggling with where to keep it. Its ability to identify, automatically move and transparently recall data could make file virtualization the ultimate cloud gateway.
Patch Your Firefox
Commentary  |  10/27/2009  | 
Mozilla just released 16 patches for vulnerabilities in Firefox. Eleven of the flaws are critical, and affect a number of components in the browser.
Global CIO: What CIOs Can Learn From Kindle
Commentary  |  10/27/2009  | 
The real lesson is in the growing power of machine-to-machine wireless links.
MAAWG's Mission Evolving As Botnets, Web Threats Intensify
News  |  10/27/2009  | 
ISP group is starting to look at more than just email abuse as attacks span Websites, social networks
SMB Security Survey Shows Sorry State Of Cyber Safety
Commentary  |  10/27/2009  | 
A new survey of small business cybersecurity offers a bleak picture of the state of things. Bleak unless you're a cybercrook, of course.
SAP, Nokia Partner On Mobile Security
News  |  10/27/2009  | 
With the joint venture's technology, prescription drugs, software, and other goods could be tagged with smart barcodes to protect them from counterfeiting.
AVG Sends Speedy Small Business Security Signal
Commentary  |  10/27/2009  | 
New Internet security and anti-virus products for small businesses from AVG are being touted by the company as both secure and speedy, with an array of promised features and administrative tools that address some of the tech-challenges smaller firms face.
Report: Nearly 6 Million Infected Web Pages Across 640K Compromised Sites
Quick Hits  |  10/27/2009  | 
Startup founded by ex-Google engineers tallies major jump in Website compromises and breadth of the infections
Five Vulnerabilities That Lead To Identity Theft
Quick Hits  |  10/27/2009  | 
ID theft security vendor offers advice on five key areas that end users should watch
ISPs: Email Abuse Down But Not Out
News  |  10/26/2009  | 
Messaging Anti-Abuse Working Group (MAAWG) says ISPs, bad guys at a draw when it comes to spam, malicious email
Top 10 E-mail Blunders Of 2009, So Far
News  |  10/26/2009  | 
Proofpoint's list of the ten biggest e-mail gaffes this year shows that organizations have yet to deal with the risks of e-mail.
UK Jobs Website Hacked
Commentary  |  10/26/2009  | 
The news site Guardian is warning members of its UK jobs site that the site has been breached, and that personal data may been snagged.
Christian Site's Poll Backfires
Commentary  |  10/26/2009  | 
The Alpha Course, a Christian Website, has created an instant Internet poll asking if God exists. So far, 96 percent of respondents clicked on "NO."
Cloud Based Backup, Ready For Business?
Commentary  |  10/26/2009  | 
Cloud based backup services have been successful in the consumer space. Companies like Mozy, Carbonite and others are protecting thousands of laptops and home desktops, but can cloud based backups services move beyond protecting consumer or prosumer data and into the data center? Are cloud based backups ready for business?
Using Evil WiFi To Educate Users, IT Admins
Commentary  |  10/26/2009  | 
For my keynote at Operation WebLock, I was asked to include a demo or two that would leave attendees rethinking some of their current practices. It didn't take a long to come up with a few different possibilities, but I settled on one of my favorite attacks: wireless network- impersonation and connection hijacking.
Smartphones Call For Security-Smarter Users
Commentary  |  10/26/2009  | 
Smartphones, and all the other smartstuff filling our pockets, bags, lives, make for mobile convenience and access -- including access by crooks. Time to get your smartphone-using staff to dial up their security practices.
The ABCs Of DAM
Commentary  |  10/26/2009  | 
Database activity monitoring (DAM) has been the biggest advancement in database security in the past decade. Identity management controls access, and encryption protects data on media, but monitoring verifies usage.
Application Security Is National Security
Commentary  |  10/23/2009  | 
Hacks targeting U.S. government computers are coming from China. We knew that. The Chinese hackers are relying on zero-day software vulnerabilities to exploit critical systems. So, tell me again: why aren't we doing more to require applications be built secure from the start?
Tech Insight: Managing Vulnerability In The Cloud
News  |  10/23/2009  | 
You can't control everything in the cloud, but you can control your data's exposure in the cloud
Trend Micro Secures Virtual, Cloud Servers
News  |  10/23/2009  | 
To address unique server security challenges, Trend Micro is connecting its Deep Security software to virtual machines and the cloud.
Gift Cards Convenient And Easy To Hack
Quick Hits  |  10/23/2009  | 
Researchers reveal hacks for prepaid gift cards
Trusting Trust
Commentary  |  10/23/2009  | 
An old and respected paper about compilers teaches us a lot about network security architecture.
Reducing Storage Complexity In Server Virtualization
Commentary  |  10/23/2009  | 
The storage component of a virtualized server infrastructure has been labeled as complex and expensive. In our prior entries about selecting a storage foundation we discussed what systems and protocols are available that might help simplify and reduce costs for storage in a virtualized environment. Beyond physi
My Hat Is Blue
Commentary  |  10/22/2009  | 
For the past two days I have been back in Seattle. It was almost two years ago I left the city, and was not sure when I'd get a chance to return. Microsoft's BlueHat security conference was a great reason to come back to my favorite rainy city. What is BlueHat?
From Security Perspective, Windows 7 Off To A Rocky Start
News  |  10/22/2009  | 
Experts express consternation over early vulnerabilities, UAC configuration issues
Feds' Security Spending On a Roll: Over 8 Percent Growth Over Next Five Years
Quick Hits  |  10/22/2009  | 
New data from research firm Input finds security spending growing twice that of overall federal IT buying
Evidence Points To China In Cyber Attacks
News  |  10/22/2009  | 
A Northrup Grumman report suggests that the Chinese government is behind a coordinated series of attacks on U.S. government and private sector computer systems.
Major Secure Email Products And Services Miss Spear-Phishing Attack
News  |  10/22/2009  | 
Experiment successfully slips fake LinkedIn invite from 'Bill Gates' into inboxes
Microsoft And Mozilla Compete, Cooperate
Commentary  |  10/22/2009  | 
In its patch release last week, Microsoft described an interesting side effect in one of its bulletins.
FTC Orders ChoicePoint To Pay $275,000 For 2008 Data Breach
Quick Hits  |  10/21/2009  | 
Agency alleges that data broker didn't do enough to protect information after massive breach in 2005
Understanding Hard Drive Performance
Commentary  |  10/21/2009  | 
In the last performance entries we discussed understanding storage bandwidth and understanding storage controllers. Next up is to understand the performance characteristics of the hard drive itself and how the mechanical hard drive can be the performance bottleneck.
Firefox Web Browser Weaponization Redux
Commentary  |  10/21/2009  | 
I've written about the Samurai Web Testing Framework (WTF) LiveCD project and some of the Firefox Add-Ons that can be used to transform Firefox into a highly capable Web application penetration testing tool. Now the Add-Ons included in Samurai and a few others have been bundled together into the Samurai WTF Firefox Collection--essentially, a one-stop shop for Web browser weaponization.
Metasploit Project Sold To Rapid7
News  |  10/21/2009  | 
Open-source Metasploit penetration testing tool creator HD Moore joins Rapid7, commercial Metasploit products to come
Page 1 / 3   >   >>


Veterans Find New Roles in Enterprise Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/12/2018
To Click or Not to Click: The Answer Is Easy
Kowsik Guruswamy, Chief Technology Officer at Menlo Security,  11/14/2018
Understanding Evil Twin AP Attacks and How to Prevent Them
Ryan Orsi, Director of Product Management for Wi-Fi at WatchGuard Technologies,  11/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-5407
PUBLISHED: 2018-11-15
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
CVE-2018-14934
PUBLISHED: 2018-11-15
The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authentication and subsequently record audio from the device microphone.
CVE-2018-14935
PUBLISHED: 2018-11-15
The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.
CVE-2018-16619
PUBLISHED: 2018-11-15
Sonatype Nexus Repository Manager before 3.14 allows XSS.
CVE-2018-16620
PUBLISHED: 2018-11-15
Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.