Click here

Security Best Practices: Archive: October 2010 

Sourcefire Targets Next-Generation Firewalls

Sourcefire expands IPS capabilities and takes aim at next-generation firewall market for 2011.

Will PCI-DSS 2.0 Security Standard Advance the Cloud?

Major security standard for payment and merchant systems is being updated. What's new? And what's still missing?

Adobe Warns of Another 'Critical' PDF Vulnerability

Adobe Systems says this latest security flaw is being exploited by hackers to take over control of computers running its popular PDF viewing application.

Social Networking Security Hot Topic at Interop NY

Interop NY 2010 attendees observed trends in network security ranging from cloud computing to green data centers, but the hottest topic was social networking--from policy development and controls to vulnerability management and compliance.

FTC Closes Google Street View Investigation

Agency opts not to fine the search giant for inadvertently collecting sensitive Internet information, though investigations continue overseas.

Mozilla Patches Firefox for Nobel Flaw

Mozilla rushes out critical security patch as next generation Firefox 4 browser is delayed into 2011.

Breach Exposes 280,000 Medicaid Patients' Data

A pair of health insurers in Pennsylvania said they lost a portable flash drive containing the names, addresses and some SSNs of hundreds of thousands of Medicaid patients.

Simple Steps to Securing Email with S/MIME

S/MIME support is already built into most desktop email clients, including Outlook, Apple Mail, and Thunderbird. Learn how to use it to encrypt your personal or business email messages.

How Google Locates and Identifies Malware

At SecTOR, Google security researcher details how the search giant identifies malware and why the company doesn't remove all malware pages from its search index.

Targeted Malware Attacks Surge in Retail Sector

Symantec report finds a huge spike in the number of low-volume email scams targeting employees at retail companies in October.

Should Obama Have an Internet 'Kill Switch'?

Survey says most Americans are willing to give the President the ability to cut off Internet access for national security reasons. The Unisys-sponsored survey also details holes in most consumer's security practices.

IT Security Salaries on the Rise

The "2011 IT Salary Guide" demonstrates that System Security Admin salaries are trending upward.

Uncle Sam Needs You in Cybersecurity

Want job security and a chance to serve your country? Get a job in cybersecurity. Experts say the dearth of qualified policy-makers and IT staff is putting the nation at risk.

Google Revamps Privacy Practices Following Wi-Fi Snag

Search giant unveils a set of internal controls in response to mistaken collection of Wi-Fi data through its Street View project, offers new revelations of how much data was collected.

5 Best Password Management Software Packages

Password managers can preserve your computer and data security, as well as your sanity. But how do you know which is best? We walk you through your options and recommend five of the best.

Facebook Takes Spammers to Court

The social networking site filed suit against two people and one company that it says are responsible for deceptive spam campaigns generated from multiple fake profiles.

Mozilla Firefox and Google Chrome Updated for Security Flaws

Firefox 3.6.11 fixes nine issues while Chrome 7 delivers ten fixes as security takes center stage for browser vendors.

Mississippi National Guard Admits Accidental Data Breach

Nearly 3,000 members of the Mississippi National Guard brigade will be checking their credit reports for years after a data management miscue exposed their personal information.

10 Riskiest Places to Give Out Your Social Security Number

Security software vendor McAfee found that social security numbers stolen from colleges and universities are most likely to be used for identity theft.

9 Best Defenses Against Social Engineering Attacks

No matter how tight your network security or well-considered your security policy, the human element at your business remains vulnerable to hackers. But there are steps you can take to tighten your security against social engineering attacks.

Metasploit Goes Pro for Security Testing

Open source vulnerability testing framework delivers 3.5 release for the community and a new Pro version for commercial enterprises.

Top Ten Ways to Avoid an Evil Twin Attack

Business travelers are particularly susceptible to evil twin attacks--hacker-created wireless access points that use real network names (SSIDs) to bait users into connecting to them.

More Students Vulnerable to Identity Theft

More than 106,000 students attending or applying to the University of North Florida this week learned that an overseas hacker infiltrated a server containing social security numbers and other PII.

New Virtualized Network Security Appliances from Fortinet

The network security provider introduces virtual versions of its FortiGate, FortiManager, FortiAnalyzer and FortiMail appliances, promising better visibility and security within cloud environments.

DHS, DoD Join Forces in Cybersecurity Push

Military and civilian departments to pool resources to combat cyberthreats, sharing personnel and intelligence to formalize and expand current partnership.

Botnets Biggest Cybercrime Threat: Microsoft Report

Microsoft and others are making headway against cybercrime, but have a long way to go, especially against botnets, according to a new report.

Facebook Offering One-Time Passwords in Security Play

Social networking giant offering security features that aim to give its more than 500 million users secure access to their accounts from public computers.

DHS Staging Cybersecurity Awareness Campaign

In recognition of national cybersecurity month, the Department of Homeland Security has launched the "Stop. Think. Connect." campaign in an effort to promote safe computing habits.

Oracle Plugs Java for Drive-by Downloads with October CPU

Massive update covers long list of Oracle software including an update for 29 new security vulnerabilities in Java.

Microsoft Patches Nearly 50 Security Holes

In what is certainly one of the largest patch releases in Microsoft's history, the company released some 49 bug fixes on Tuesday.

Group Seeks Greater Online Security for Kids

New survey from Common Sense Media finds vast majority of parents express concerns about online child safety and cyberbullying in the Facebook age, fueling campaign for tighter laws.

Four Key IT Security Trends for 2011

What the 2010 security acquisition spree by major players, including Symantec, HP, IBM, CA and VeriSign, could mean to IT security professionals.

McAfee Plots New Data Security Strategy

Mobile devices, virtualization and embedded security apps in a wide range of consumer devices will define the security software maker's future following its merger with Intel.

15 Reasons to Use Enterprise WLAN Security

There are myriad reasons why your business’s Wi-Fi network should be protected by enterprise-grade WLAN security. Here are 15 of the best.

Paessler Unveils PRTG Network Monitor 8

The latest version of Paessler's network monitoring suite features fail-over clustering and Linux support, as well as a simplified licensing structure.

Microsoft Promises Busy Patch Tuesday Next Week

Apparently there will be no let up in the need to patch security flaws in Microsoft's products as the company readies another big batch of bug fixes for October.

Your Own Staff May Be Your Company's Biggest Security Risk

No matter how diligent you are in hardware, policy-making, or hiring, your security is only as strong as the weakest link. Columnist Christopher Null examines the realities of insider fraud.

Review: MXI Stealth ZONE

Security features are robust in this fast, efficient "secure USB desktop" from MXI, which uses an encrypted flash drive with speedy BlueFly processor to boot a PC-adapted, IT-customized Microsoft Windows Embedded Standard image.

Zeus Phishing Campaign Targets iTunes Customers

A new malware scam making its way across the Internet uses a bogus iTunes receipt to try to lure victims to sites that infect their PCs and mobile devices with the Zeus Trojan.

Symantec's New Mobile Security, Management Strategy

Aiming to extend its offerings from the PC to the mobile sphere, Symantec has announced a new mobile security and management strategy that encompasses solutions for enterprises, consumers and communication service providers.

Cisco Accelerates Security Portfolio

New high-end security appliance and remote access security improvement debut as Cisco expands its Borderless Networking vision.

New Service to Protect Networks from Botnets

Nominum, a provider of intelligent DNS solutions, has created a real-time feed of bot-related malicious domains that network owners can leverage to block the propagation of botnets and other malware.

Netezza Rolls Out Real-Time Security Appliance

New Mantra Vault analyzes data across enterprise databases to identity potential threats to real-time transactions.

Adobe Promises Quick Fix for Reader Flaw

Company tells customers to expect a patch for a 'critical' hole in Adobe Reader and Acrobat apps by next week.