Security

Resources related to information security, including news and opinion and more on software and application flaws and fixes, data breaches, the inside threat the latest hacker attacks.

How the Phoenix Suns Basketball Team Takes on Social Media Attacks

Every sport has its fans, and the Phoenix Suns basketball team is finding that use of social networking has become one of the main ways to keep in touch with its fan base -- though it can get dicey when basketball fans across the NBA go a little wild before big games. Full Story »

FDA Defends Its Monitoring of Whistleblowers' Email

The U.S Food and Drug Administration (FDA) today said it monitored the private email accounts of nine agency whistleblowers starting in 2010 to determine whether any of them leaked confidential information to the public.

6 Ways to Defend Against Drive-by Downloads

Cybercriminals are increasingly using drive-by downloads to distribute malware without end users knowing something bad has just landed on their machine--until it's too late. Here are six ways IT departments can protect end users from the productivity sink and potential data loss that drive-by downloads create.

Blogger Exposes Major Google Wallet Security Flaw

If you took one look at Google Wallet and said to yourself, "There's no way that's completely secure," it turns out you were right.

Career Advice: the Value of Certs

Computerworld Premier 100 IT Leader Page Petry answers questions about certifications, winning a promotion and more.

How to Get the IRS' Attention: Forge Nearly $8 Million in Tax Returns, Steal Identities

A former Internal Revenue Service employee this week got 105 months in prison for pleading guilty to theft of government property and aggravated identity theft in a case where the guy tried to get away with nearly $8 million in fraudulent tax returns.

Google Expands the Scope of Its Vulnerability Reward Programs to Cover Chromium OS

Google says that both its Web and Chromium security reward programs were a big success

Web App Lets Enterprise Set Security, Sharing for Google Apps Users

A new security tool lets enterprise IT groups set access and share policies for employees, including mobile users, who are working with the online Google Apps suite.

Criminals Open 'Factory Outlet' to Sell Stolen Facebook and Twitter Logins

Security company Trusteer has discovered a 'factory outlet' selling user logins for Facebook and Twitter harvested as a sideline during attempts to steal online bank credentials.

Hackers Attacked Foxconn for the Laughs

Hacker mischiefs calling themselves SwaggSec penetrated the computers at Foxconn, which assembles about 40 percent of the consumer electronics products in the world, and stole data that it posted to the Internet -- apparently just for laughs.

Citadel Banking Malware is Evolving and Spreading Rapidly, Researchers Warn

The open-source development model is helping Citadel's creators patch bugs and add features faster

Antivirus Software Powerless to Stop Data Breach Attacks, Study Finds

arge numbers of data breaches are being initiated by targeted malware that antivirus software simply can't detect, an analysis of 300 real-world incidents from 2011 has suggested.

Researchers Crack Satellite Encryption

Researchers at a university in Bochum, Germany claim to have cracked encryption algorithms of the European Telecommunications Standards Institute (ETSI) that are used to secure certain civilian satellite phone communications.

Know Your Internet Bad Guys

Anyone who makes a habit of wandering around in cyberspace should print this TrendLabs infographic, posted Wednesday, and keep it close at hand. This colorful web poster contains info on Internet bad guys, and helps people avoid getting scammed, hacked, or hurt by malware.

US Gov'T Falling Behind in Social-Media Race, Expert Says

Other governments and some companies are using social media to address dissent, a DARPA program officer said

Trustwave Admits Issuing Man-in-the-Middle Digital Certificate, Mozilla Debates Punishment

The issuing of subordinate root certificates to companies, so they can snoop on SSL-encrypted traffic, is a common industry practice

Europe Cares About Privacy, So You Must Too

In late January, the European Commission published a proposal "on the protection of individuals with regard to the processing of personal data and on the free movement of such data."

FBI Declares Cloud Vendors Must Meet CJIS Security Rules

The FBI Tuesday reaffirmed its rule that all cloud products sold to to U.S. law enforcement agencies must comply with the FBI's Criminal Justice Information Systems (CJIS) security requirements.

Adobe Sets IE As Next Target in Flash Security Work

Adobe plans to tackle Microsoft's Internet Explorer (IE) in its ongoing work to "sandbox" its popular Flash Player within browsers, Adobe's head of security said today.

Symantec Expects Anonymous to Publish More Stolen Source Code

Symantec today confirmed that the pcAnywhere source code published on the Web Monday by hackers who tried to extort $50,000 from the company was legitimate.

FTC Warns Background Screening Mobile Apps May Be Unlawful

The Federal Trade Commission this week said it sent letters to six unidentified mobile applications makers warning them that their background screening apps may be violating federal statutes.

Kaspersky Lab CEO Backs Out of IPO Plans

Kaspersky Lab founder Eugene Kaspersky has cancelled plans for the firm to go public, announcing his intention to buy back a 20 percent stake sold to a private equity investor a year ago.

Hacktivism Trumps Money As Motivation for Denial of Service Attacks

Two-thirds of all DDoS attacks globally were motivated by politics, ideology, nihilism or vandalism.

Denial-of-Service Attacks Are on the Rise, Anti-DDoS Vendors Report

Japan named as primary source of DDoS attack traffic for Q4 2011

Data Breach? Blame Your Third Party's Remote Access Systems

An in-depth study of data-breach problems last year where hackers infiltrated 312 businesses to grab gobs of mainly customer payment-card information found the primary way they got in was through third-party vendor remote-access applications or VPN for systems maintenance.

 
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make to help achieve project success.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center