Click here

Security Best Practices: Archive: July 2010 

Review: AirWatch Enterprise Package

Turn-key service delivers Web-based control over employee smartphones helping businesses manage iPhones, Android-based devices, BlackBerrys, and Windows Mobile smartphones.

Security in Virtual Environments

A CA white paper examines the key security measures required to ensure the safe deployment of cloud computing technologies.

Millions of Home Routers at Risk

New tool demoed at the Black Hat security conference shows how easy it is to attack routers--and how to defend against those attacks.

General to U.S. Officials: 'Quit Whining, Act Like a Man, Defend Yourself'

At Black Hat Thursday, retired General Michael Hayden, a former director of the CIA, compared cyberspace to other military domains, such as air, land, and sea, and likened it to the North German Plain during the Cold War.

Mariposa Botnet Kit Supplier Arrested

Law enforcement agents in Slovenia working with the FBI arrested a 23 year-old Slovenian man they say is responsible for creating and selling the Butterfly botnet kit used to build the Mariposa botnet.

SSL Study Shows Most Sites Incorrectly Configured

Black Hat research takes a deep look at SSL security and finds it lacking due to a number of common configuration issues.

Microsoft Brings Security Outreach Message to Black Hat

Microsoft expands security disclosure program as it tries to work closer with researchers and other software vendors, including Adobe.

Dell Rolls Out Security Services, Hardware for SMBs

Offerings for small businesses with big security needs range from a complete hardware solution from Juniper to managed services from KACE.

Organized Crime Involved in Most Data Breaches

U.S. Secret Service and Verizon also say the vast majority of breaches could have been avoided with basic precautions.

Sourcefire Launches Razorback Open Source Security Framework

New open source project set to correlate security information from multiple types of technologies with a defense security router.

Spammers Love Short URLs

Symantec's July 2010 MessageLabs Intelligence report finds that the percentage of spam containing shortened hyperlinks has increased significantly over the past year.

Cisco Details Enterprise Security Threats

The Quarterly Global Threat Report offers insight into the types of attacks happening on enterprise networks. Adobe Reader/Acrobat, Sun Java, and Adobe Flash were the three most common malware targets over the first half of 2010.

Whitelisting Advances with New Bouncer App

The latest whitelisting release from CoreTrace adds application intelligence capabilities and more permissive options for new application installation.

Cyber Crime Costs on the Rise: Study

Resolving various cyber crime attacks costs the typical organization almost $4 million a year, according to the latest survey from ArcSight and the Ponemon Institute.

Black Hat USA 2010 Preview

At Black Hat USA 2010 Las Vegas, mobile apps, Internet infrastructure enterprise networking, and more go under the microscope starting Wednesday, as security researchers probe all manner of Internet connectivity and security issues.

Endpoint Security Protection

A Sophos white paper examines the importance of endpoint security.

Microsoft: IE8 Blocked a Billion Malware Downloads

Microsoft's technology for blocking malware and phishing attacks appears to be paying off for users, as the company claims a cool billion potential attacks blocked.

Phishers Put Old-School Twist on Online Scams

The Anti Phishing Working Group is now lending its expertise to the IRS to help root out online and offline phishing scams that use a combination of e-mails and faxes to steal identities.

Mozilla Rushes Out Another Firefox Security Update

With the release of Firefox 3.6.8, Mozilla is fixing only one security flaw omitted from last week's release, while work progresses on Firefox 4.

Microsoft Tweaks Its Bug Disclosure Process

As bug sleuths find and disclose more security holes in Microsoft products, giving the company little or no advance warning, the software titan tries to lower the tensions between all parties in order to better protect users.

Cloud Security Concerns Hold Back Adoption

Mimecast reports that 62 percent of IT departments say there's always a risk in storing data on servers outside the business.

Apple Has the Most Security Vulnerabilities: Report

Secunia's report doesn't measure the severity of security flaws, but it says some interesting things about how the focus of malware attacks has shifted.

Tripwire Enhances Compliance With Remediation Manager

The new Tripwire Enterprise 8.0 release is designed to automate the process of bringing IT systems into both regulatory compliance and a company's internal mandates.

Cisco: U.S. Leads in Spam; IT Policies Not Being Followed

Cisco's midyear security report paints a bleak picture of non-compliance by IT users for enterprise policies.

Cloud Storage Security

A Nasuni white paper examines the key security risks inherent in cloud storage solutions, as well as the ways those risks can be mitigated.

Oracle Targets Security With New Identity Management Suite

The database giant says the new release of Oracle Identity Management 11g "radically simplifies" application security.

Shortened URLs Are the Latest Spam Scourge

Symantec's MessageLabs report finds that the shortened hyperlinks that are a virtual necessity on Twitter are one of the fastest-growing sources of spam and malware.

Security Certifications a Good Career Investment

If Information Systems Security is your game, earning a few top certifications can also earn you top dollar.

Mozilla Patches Firefox for 14 Vulnerabilities

Ahead of Black Hat, Firefox 3.6.7 addresses a slew of flaws -- one of which had been fixed weeks ago by Google Chrome.

Spam in Q2 2010

A Google report states that virus and spam volumes both increased in the second quarter of 2010.

Microsoft Beta Tests Two Updated Security Tools

Forefront Endpoint Protection offers new features for enterprise admins while the free Security Essentials gets an overhaul.

How Cloud Security is Like Y2K

A Deloitte venture capitalist believes cloud computing will force companies that have deferred investment to become more efficient by buying new systems, among other things.

Dell Kace Debuts Secure Firefox Browser

The Dell Kace Secure Browser takes a different approach to isolating and managing browser instances to improve enterprise security.

Protecting Students' Privacy

A Sophos white paper offers advice to schools on how to protect student data.

Microsoft Blindsided by Another Zero-Day Attack

New zero-day attacks on all Windows OS's spring from removable file storage vulnerability, says Microsoft.

Spammers Love the UK

In Sophos' latest Dirty Dozen spam report the UK has jumped to fourth place, up from ninth place earlier this year.

Defending the Power Grid is Defending the Nation

We a look at the new book, "Cyber War: The Next Threat to National Security and What to Do About It." Is the best defense against cyber attacks to disconnect the power grid from the Internet?

Zscaler Brings Email Security to the Cloud

The security software vendor's latest cloud security product screens all inbound and outbound email messages sent from any PC or mobile device.

Simplifying Compliance

An M86 Security white paper offers advice on implementing an effective data loss prevention policy.

DNSSEC Now Deployed in Root DNS

A major historical milestone will see the Net's core infrastructure get a new security feature. A look at why it matters and what else the Internet's operators are doing to keep the Net safe.

Leading Security Threats for Q2 2010

According to Commtouch's latest report, spam comprised an average of 82 percent of all email traffic in the second quarter of 2010.

U.S. Tops in Spam Relaying; UK Gains Ground

Security software vendor Sophos' latest "Dirty Dozen" list of top spam-relaying countries paints a familiar picture with usual suspects such as the U.S. and India atop the chart.

Hybrid Web Security

An M86 Security white paper examines the benefits of combining cloud and on-premises security solutions.

Hackers Using eBay Ruse in Malware Attack

Security researchers have discovered a new malware campaign that uses a bogus email request for payment from eBay to infect users' computers.

Fortinet Debuts 1 Gbps Firewall in New Security Appliances

The network security provider delivers new levels of performance in an entry-level appliance aimed at distributed enterprises, SOHOs and small businesses, and service providers delivering managed services in CPE deployments.

A Rise in Software Security Flaws

A Secunia report finds that the software industry is continuing to produce software with a surprising number of vulnerabilities.

Top Ten Security Reasons to Upgrade to Windows 7

Windows 7 Enterprise delivers enough security improvements to justify the cost and hassle of migration. We outline ten of the best security benefits.

AMR Breach Puts 79,000 Employees at Risk

American Airlines' parent company says the personal data of some 79,000 current, former and retired employees was compromised after a hard drive was stolen from its Fort Worth, Texas headquarters.

Security Regulations in the European Union

A Sophos white paper looks at the key directives and legislation affecting the member states of the European Union.

Snooping and Data Security

A Cyber-Ark Software survey finds that 41 percent of respondents have used administrative passwords to snoop on sensitive or confidential information.

Hackers Break Into University of Maine Servers

University of Maine officials say hackers managed to pry their way into a pair of file servers storing the social security numbers and other personal data of 4,500+ students.

Obama's Cyber Chief Touts 'Resilient' Security Strategy

Tasked with coordinating and improving cybersecurity operations across the agencies and private sector, Howard Schmidt has a big job, and he's not looking for a silver bullet.

Feds Look to Clear Hurdles in Private-Sector Cybersecurity

Public-private partnerships may be the lynchpin of federal cybersecurity, but experts warn that many stumbling blocks remain.

Understanding Blended Security Threats

An M86 Security white paper examines some of the newer methods being employed to break through corporate defenses.

Patch Tuesday to Fix Three 'Critical' Microsoft Holes

July’s patch release may not be as demanding as June, but in fixing three critical holes, it’s an important one for administrators to deploy ASAP.

Assessing Advanced Security Threats

More than 83 percent of IT and IT security leaders say their organizations were recently targeted by advanced threats.

Hackers Strike Back Against Microsoft

A group of hackers says it will begin releasing proof-of-concept exploit code for Microsoft vulnerabilities in retaliation for the software giant's recent criticism of third-party security researchers.

7 Things Hackers Hope You Don't Know

Protect your business or home Wi-Fi network by thinking like a hacker. Find your greatest WLAN weaknesses and then guard against them.

Microsoft Warns on Windows Developer Tool Vulnerability

Microsoft puts users and developers on notice that the Windows Foundation Classes have a security flaw -- making some apps vulnerable to attackers.

7 Bad Computing Habits You Should Break

We’ve identified seven common computing habits that have security implications. We’ll tell you how and why you should break them.

Top 10 Web Security Threats

A MessageLabs white paper offers advice on how to mitigate 10 key security risks.

Spam and Malware

A recent AppRiver report finds that more than one in 10 spam emails contained a virus during the past six months.

Understanding Targeted Trojan Attacks

A MessageLabs white paper looks at the methodology behind targeted Trojan attacks.

iPhone Security Apps Buying Guide

While Apple has integrated some basic security measures into the settings of the iPhone itself, several third-party apps can add key security functionality to the device.

Teenagers and Security

While 95 percent of teenagers are confident in their ability to stay safe online, 27 percent have accidentally infected their home computer with malware.

'Twilight: Eclipse' Malware Leverages 'Poisoned' Search Results

Fans of the 'Twilight' vampire saga could be in for a nasty surprise while searching the Web for movie information.

Gartner Security Summit News Round-Up

Annual IT security gathering urges attendees to adopt more pragmatic, risk-centric, business-focused approaches.