Bip Bip - Information Security News
EPA Reveals Locations of "Secret" Coal Ash Storage Sites - About - News & Issues
Source: NetworkStrike
Publish date: Tuesday, June 30th, 2009

read more

Websense Positioned as a Leader in Magic Quadrant for Content ... - SYS-CON Media (press release)
Source: NetworkStrike
Publish date: Monday, June 29th, 2009

read more

US confident hours before leaving Iraqi cities - The Associated Press
Source: NetworkStrike
Publish date: Monday, June 29th, 2009

read more

Brief: Jackson searches resemble attack to Google
Source: SecurityFocus
Publish date: Monday, June 29th, 2009
Jackson searches resemble attack to Google
Brief: Firms atwitter over social-net threats
Source: SecurityFocus
Publish date: Tuesday, June 23rd, 2009
Firms atwitter over social-net threats
NAC Appliances Hardest Hit In Network Security By Economic Downturn, Report Says
Source: Dark Reading
Publish date: Monday, June 29th, 2009
Infonetics expects a struggling NAC appliance market to rebound big-time by 2013, to nearly $700 million
FTC Issues Final Order In CVS Caremark Data Security Case
Source: Dark Reading
Publish date: Thursday, June 25th, 2009
FTC issues final order censuring CVS Caremark for mishandling customer data
Relaunched Google Search Service Fingers Malware-Spreading Advertisers
Source: Dark Reading
Publish date: Friday, June 19th, 2009
'Anti-Malvertising' lets Website owners do background checks on potential online advertisers
Presentation Sécurité des systèmes d'information : les enjeux 2009-2010
Source: HSC - Nouveautés
Social engineering training could disrupt botnet growth
Source: Security Wire Daily News
Brian Sears
Publish date: Wednesday, June 24th, 2009
Security pros should address social engineering attacks with end users, helping them identify the tactic and possibly have an impact on botnet viability.


Symantec offers endpoint protection management, monitoring services
Source: Security Wire Daily News
Neil Roiter
Publish date: Tuesday, June 23rd, 2009
Symantec responds to pain points of managing endpoint protection with two managed services to help deploy and maintain antivirus, NAC products and endpoint security suites.


Financial security pros expect improved funding in second half of 2009
Source: Security Wire Daily News
Marcia Savage
Publish date: Monday, June 22nd, 2009
A SearchFinancialSecurity.com survey indicates a security spending rebound in financial services with companies investing in authentication, encryption and network access control.


Greater Precision in Timing Attacks Using DoS
Source: ha.ckers
Publish date: Sunday, June 28th, 2009
Because of all of the stuff that happened over the last week or so regarding Slowloris, I started thinking about other ways to use DoS to aid in existing attacks. A lot of times it’s really the opposite of what an attacker wants to do. Typically the attacker wants to keep the system [...]
SB09-180: Vulnerability Summary for the Week of June 22, 2009
Source: NetworkStrike
Publish date: Tuesday, June 30th, 2009

Vulnerability Summary for the Week of June 22, 2009

Softtek Launches New Application Security Services at the Gartner ... - Business Wire (press release)
Source: NetworkStrike
Publish date: Monday, June 29th, 2009

read more

Cloud security and the changing role of IT - V3.co.uk
Source: NetworkStrike
Publish date: Monday, June 29th, 2009

read more

Brief: Adobe re-patches Shockwave player
Source: SecurityFocus
Publish date: Thursday, June 25th, 2009
Adobe re-patches Shockwave player

>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
Pain-Free Migration to Unified Communications
Source: IT Security
Publish date: Wednesday, June 24th, 2009
WHEN: Wednesday, July 15thTime: 10am PT / 1pm ET Join us today!>>SPONSORED BY:  Qwest Business Solutions®Learn why Unified Communications is an economic necessity and how to easily and...
Tech Insight: Database Security -- The First Three Steps
Source: Dark Reading
Publish date: Friday, June 26th, 2009
A guide to locating sensitive data in databases -- and finding a strategy to protect it
Security Poised To Grab Bigger Piece Of IT Pie, Gartner Says
Source: Dark Reading
Publish date: Wednesday, June 24th, 2009
Analyst firm Gartner predicts security spending will comprise a larger percentage of overall IT budgets
Firewall rule management best practices
Source: Network Security Tactics
Michael Cobb
Publish date: Tuesday, June 23rd, 2009
Given the growing complexity of firewalls, organizations often have hundreds, even thousands, of rules to review and manage. But configuration doesn't have to be overly complicated. Michael Cobb offers best practices that can allow you to make changes to a company rule set without losing any sleep.


New Trojan stealing FTP credentials, attacking FTP websites
Source: Security Wire Daily News
Robert Westervelt
Publish date: Monday, June 29th, 2009
A new Trojan has collected up to 80,000 unique FTP server logins and is injecting malicious code into thousands of FTP websites.


TJX to pay $9.75 million for data breach investigations
Source: Security Wire Daily News
Robert Westervelt
Publish date: Wednesday, June 24th, 2009
The company agrees to pay legal expenses related to investigations conducted by 41 Attorneys Generals and establish a data security fund for states.


Incident response planning
Source: Security Wire Daily News
Robert Westervelt
Publish date: Monday, June 22nd, 2009
Jack Phillips, managing partner of security research firm, IANS, talks about how companies can prepare to appropriately handle a security incident.


What is a browser? Video may change your security training strategy
Source: SecurityBytes
Publish date: Friday, June 19th, 2009
If a major piece of your security strategy revolves around employee training, the following video might be a major setback. Many security pros pride themselves on the amount of training they give their employees. But I wonder, is it all for naught? A Google employee took a camera and microphone onto the streets of New York [...]
Detecting MITM/Hacking Proxies Via SSL
Source: ha.ckers
Publish date: Sunday, June 21st, 2009
There are several different ways for MITM/hacking proxies to handle SSL. They can create a self signed root cert that the attacker/user accepts once, they can do a per site snake oil cert, or they can simply downgrade the attacker/user to HTTP (a la Moxie’s sslstrip). Any of those work, and it’s kind [...]
Improved FISMA scores don't add up to better security, auditor says - FCW.com
Source: NetworkStrike
Publish date: Tuesday, June 30th, 2009

read more

Apple CEO Steve Jobs back at work few days a week
Source: NetworkStrike
Publish date: Monday, June 29th, 2009

Apple says CEO Steve Jobs is back at work a few days a week and working from home other days.

read more

Microsoft Assessment and Planning Toolkit 4.0 beta available
Source: NetworkStrike
Publish date: Monday, June 29th, 2009

MAP Toolkit 4.0 is an integrated planning toolkit that makes it easier for you to quickly identify what servers, workstations and network devices are in your environment. There is no agent that has t...

Brief: Pentagon signs off on Cyber Command
Source: SecurityFocus
Publish date: Wednesday, June 24th, 2009
Pentagon signs off on Cyber Command
Essential Tips to Better Secure Your Email Today...Plus Collaboration and IM Tomorrow
Source: IT Security
Publish date: Wednesday, June 24th, 2009
It’s not just about email anymore. You know it, I know it, and Cybercriminals know it. Implement systems that cost-effectively reduce security risks to your real-time communications! You will le...
Booming Underground Economy Makes Spam A Hot Commodity, Expert Says
Source: Dark Reading
Publish date: Friday, June 26th, 2009
Booming underground markets make spam even easier and more lucrative than before, researcher says
DNSSEC Showing More Signs Of Progress
Source: Dark Reading
Publish date: Monday, June 22nd, 2009
The Domain Name System (DNS) security protocol is finally making inroads on the Internet infrastructure front, but big hurdles remain for widespread, smooth adoption
Presentation Cinq questions sur la vraie utilité de l'ISO 27001
Source: HSC - Nouveautés
MasterCard increases PCI compliance requirements for some merchants
Source: Security Wire Daily News
Marcia Savage
Publish date: Monday, June 29th, 2009
Company now requires merchants that process one million to six million transactions annually to have onsite assessment by a PCI QSA. Visa says it won't follow suit.


Cybersecurity czar candidate questions clout of new position
Source: Security Wire Daily News
Robert Westervelt
Publish date: Tuesday, June 23rd, 2009
Former U.S. Congressman Tom Davis, a leading candidate for the White House cybersecurity czar, says the job has a number of major challenges to overcome.


Gartner sees better days ahead for security budgets
Source: Security Wire Daily News
Robert Westervelt
Publish date: Monday, June 22nd, 2009
Investments in managed security services, intrusion prevention systems and multifunction firewalls help buoy IT security budgets.


Cligs URL shortening flaw highlights social networking ills
Source: SecurityBytes
Publish date: Thursday, June 18th, 2009
Could flaws in social networks send the Internet spiraling out of control? A flaw discovered in URL shortener Cligs (Cli.gs) last weekend demonstrates the fragility of the social networking ecosystem and how potentially dangerous it could be. Cligs competes against TinyURL and Bit.ly, which dominate link shortening on Twitter. It is recognized as the 4th most used [...]
HTTP Longevity During DoS
Source: ha.ckers
Publish date: Saturday, June 20th, 2009
One of the things I noticed early on in my testing of Slowloris was that not every server reacted like you’d expect it to. Some gave database errors - I’m assuming because the database connections had different limits than the HTTP server. Whatever the reason, it only seemed vaguely interesting at first, from [...]