Security News

Syndicate content
Updated: 34 min 19 sec ago

New Twitter Attack Details Emerge

2009, December 21 - 08:00

The attack that took down Twitter Dec. 17 used legitimate credentials to log in and redirect Twitter.com to a site purporting to be under the control of the Iranian Cyber Army. The incident underscores the importance for businesses of keeping an eye on DNS security.

http://www.eweek.com/c/a/Security/New-Twitter-Attack...

Beyond ACTA: Proposed EU - Canada Trade Agreement Intellectual Property Chapter Leaks

2009, December 21 - 08:00

Canada's participation in the Anti-Counterfeiting Trade Agreement negotiations has understandably generated enormous public concern as leaked documents indicate that ACTA would have a dramatic impact on Canadian copyright law. The U.S. has proposed provisions that would mandate a DMCA-style implementation for the WIPO Internet treaties and encourage the adoption of a three-strikes and you're out system to cut off access where there are repeated allegations of infringement.

http://www.michaelgeist.ca/content/view/4627/125/

Top 10 worst tech presents for Christmas

2009, December 21 - 08:00

Here are ten geek gifts for people who’ve been naughty, or not naughty enough.

http://www.pcauthority.com.au/News/163327...

Our [Honey Pot Project] 1 Billionth Spam Message

2009, December 16 - 08:00

On Wednesday, December 9, 2009 at 06:20 (GMT) Project Honey Pot received its billionth email spam message. The message, a picture of which is displayed below, was a United States Internal Revenue Service (IRS) phishing scam. The spam email was sent by a bot running on a compromised machine in India (122.167.68.1). The spamtrap address to which the message was sent was originally harvested on November 4, 2007 by a particularly nasty harvester (74.53.249.34) that is responsible for 53,022,293 other spam messages that have been received by Project Honey Pot.

http://www.projecthoneypot.org/1_billionth_spam_message_stats.php

Getting Started With Full Disk Encryption

2009, December 16 - 08:00

Today, full-system encryption in software is feasible and practical. Here's how to get up and running using solutions from PGP, McAfee, Sophos, and open-source options TrueCrypt and DiskCryptor.

http://www.informationweek.com/news/infrastructure...

Bank's antifraud tactics stun security expert: How much do they know?

2009, December 16 - 08:00

AVG's Roger Thompson discusses brush identity-theft prevention measures

http://www.networkworld.com/news/2009...

Hackers Brew Self-Destruct Code to Counter Police Forensics

2009, December 15 - 08:00

Hackers have released an application designed to thwart a Microsoft-packaged forensic toolkit used by law enforcement agencies to examine a suspect’s hard drive during a raid.

http://www.wired.com/threatlevel/2009/12/decaf-cofee

US and Russia in cyber security talksDecember 14, 2009 by John Lister

2009, December 15 - 08:00

The United States and Russia have begun discussions on increasing security online. The two sides are also said to be working for an agreement to cut the number of online military attacks.

http://tech.blorge.com/Structure:%20/2009/12/14/...

SQL attacks take off in last year

2009, December 15 - 08:00

Online attacks against databases have taken off in the past 18 months, according to data released by IBM’s X-Force security team.

http://www.securityfocus.com/brief/1048

Unu hits Kaspersky a second time with SQL Injection disclosure

2009, December 14 - 08:00

Unu, who has gained a good deal of attention lately, is known for his vulnerability disclosures that center on SQL Injection. In his latest adventures, he returns to a vendor he has targeted in the past, security software specialist Kaspersky.

http://www.thetechherald.com/article.php/200950/4931/Unu-hits...

Four Database Security Tips for Dealing with SQL Injections

2009, December 14 - 08:00

SQL injection placed No. 3 on Verizon's list of the 15 most common attacks in its data breach report. Preventing SQL injections can be the difference between data security and a screaming headline. Here are a few short tips on how to help protect your databases and applications.

http://www.eweek.com/c/a/Security/4-Database-Security-Tips-for...

10 Email Security Lessons To Be Learned From Climategate

2009, December 14 - 08:00

With climate change critics using hacked emails to discredit scientists ahead of COP15, eWEEK looks at what IT managers and security administrators can do to protect their own inboxes

http://www.eweekeurope.co.uk/knowledge/10-email-security...

Adobe fixes critical Flash Player flaws

2009, December 11 - 08:00

Adobe on Tuesday patched seven vulnerabilities in Flash Player, six of them for critical bugs that hackers could use to hijack Windows, Mac or Linux machines.

http://www.computerworld.com/s/article/9142021/Adobe_fixes_critical_Flash_Player_flaws

SQL injection attack claims 132,000+

2009, December 11 - 08:00

A large scale SQL injection attack has injected a malicious iframe on tens of thousands of susceptible websites. ScanSafe reports that the injected iframe loads malicious content from 318x.com, which eventually leads to the installation of a rootkit-enabled variant of the Buzus backdoor trojan. A Google search on the iframe resulted in over 132,000 hits as of December 10, 2009.

http://www.net-security.org/secworld.php?id=8604

Google chief: Only miscreants worry about net privacy

2009, December 10 - 08:00

If you're concerned about Google retaining your personal data, then you must be doing something you shouldn't be doing. At least that's the word from Google CEO Eric Schmidt.

http://www.theregister.co.uk/2009/12/07/schmidt_on_privacy/

The Gawker Guide to Getting Past Airport Security This Holiday Travel Season

2009, December 10 - 08:00

Christmas is coming, so it won't be long before you're walking barefoot through spilled soda and children's vomit at a security checkpoint in some godforsaken airport. Fortunately, the TSA has leaked a sensitive document explaining how to avoid all that.

http://gawker.com/5420989/the-gawker-guide-to-getting-past-airport-security-this-holiday-travel-season

Facebook shuts down Beacon program, donates $9.5 million to settle lawsuit

2009, December 10 - 08:00

Facebook has agreed to shut down a program that sparked a lawsuit alleging privacy violations, and set up a $9.5 million fund for a nonprofit foundation that will support online privacy, safety and security.

http://www.networkworld.com/community/node/48852?hpg1=bn

24,000 employees affected by data breach

2009, December 9 - 14:11

Personal information exposed on the Internet, University working to minimize future threats

www.ndsmcobserver.com/news/24-000-employees-affected-by-data-breach-1.979963

Cybercrime is crime with different tactics – interview with Bruce Schneier

2009, December 9 - 14:05

Cybercrime is just like any other type of crime only with different tactics, Bruce Schneier tells Infosecurity.

www.infosecurity-magazine.com/view/5798/cybercrime-is-crime-with-different-tactics-interview-with-bruce-schneier/

'Fake fingerprint' Chinese woman fools Japan controls

2009, December 9 - 14:04

A Chinese woman managed to enter Japan illegally by having plastic surgery to alter her fingerprints, thus fooling immigration controls, police claim.

news.bbc.co.uk/2/hi/asia-pacific/8400222.stm