Click here

Security Trends: Archive: June 2010 

Top Cybersecurity Threat Is Customers, Experts Say

Educating consumers presents issues, but with business, government, and individuals all working together, panelists were optimistic about our cyber security future.

Adobe Shores Up Security Holes in Reader, Acrobat

The updates fix more than a dozen known exploits, including a PDF vulnerability that hackers were using to usurp control of users' computers.

Facebook Extends Privacy Controls to Apps

Making good on its promise to Canadian privacy authorities, social networking giant Facebook said it has simplified the permission controls for users sharing data with third-parties.

Open Source is Inherently More Secure, Says Red Hat

At the Red Hat Summit in Boston last week, Josh Bressers, a senior security engineer at Red Hat, explained why open source really is the best model for building secure software.

McAfee Serves Up Cloud Security Suite

New cloud-based security service helps protect companies from malware without the need for any on-premise software or hardware.

HP Expands TippingPoint Security

First new releases debut after HP's 3Com acquisition, but full integration of the two companies' products is still a work in progress.

Cisco: Use of Unauthorized Devices a Growing IT Headache

A survey of IT professionals finds the growing use of iPhones and other personal mobile devices on corporate networks poses a security problem.

SSL Certificates In Use Today Aren't All Valid

New study examines 119 million domain names to discover some surprising results into how many are using SSL properly.

Sysadmins and Password Protection

An Osirium survey finds that companies are being exposed to 'unsustainable levels of operational risk.'

Database Gaffe Exposes Florida Student, Faculty Data

Thousands of students and dozens of faculty members had their names, social security numbers and other PII exposed for months before officials locked down an unsecured database.

Google Updates Chrome for Security and Adobe Flash

In the second update of the month, the newly released stable edition of Google's browser patches security vulnerabilities while throwing in Flash integration, to boot.

Social Media and Corporate Security

A Cyveillance white paper examines the security threats presented by social media.

Universities Respond to Obama's Request for More Cybersecurity Gurus

The Obama administration's leadership is motivating colleges and universities to step up and train an army of cyber warriors.

Security Concerns for 2010

An nCircle survey finds that IT professionals' leading concern for 2010 is meeting security compliance requirements.

Twitter Settles Security Complaint With FTC

Microblogging service Twitter agrees to settlement with Federal Trade Commission regarding high-profile security breaches that dogged the site in early 2009.

.Org Signed for DNSSEC

A major milestone as the first major top-level domain is now secured with DNSSEC. But the process of securing all .org domains isn't done -- yet.

Mozilla Firefox 3.6.4 Delivers Stability and Security

Out-of-Process plug-in support comes to open source Web browser, providing new crash protection for Linux and Windows users.

Five Ways to Reduce Security Risks

A Sophos white paper offers a suggested set of actions that will help reduce a company's vulnerability to online threats.

Three Things the Oil Spill Can Teach Us About Disaster Recovery

The BP oil spill is a cautionary tale for businesses that are functioning without proper business continuity and disaster recovery processes and procedures in place.

Survey: Small Businesses Prioritize Security

According to a Symantec survey, the majority of SMBs are now making data security their top IT priority, a big change from 15 months ago.

Cyber Security in the SMB Market

Small and mid-sized businesses are now spending an average of $51,000 a year on information protection.

Gartner Urges Smarter, Not Pricier, Security

Top analyst at research firm offers advice for IT managers trying to keep their systems secure in the face of constrained budgets and competing priorities.

Botnets Will Dominate Cyberattacks Through 2013: Gartner

While not sophisticated, botnets are a resilient method for launching attacks against government and business, says Gartner.

DARPA May Lose Cyber Wargames Playground

The Senate recently recommended a $143.4-million gutting of the Pentagon research agency's budget, including a $10-million cut to the National Cyber Range project.

ICANN Maps Out Internet Defense

The domain name system’s managing body pushes DNSSEC as the way forward to make the Internet a safer place for all.

10 Ways to Deter Hackers

A Bitrix white paper suggests 10 key steps to take to maximize security.

Ashcroft: Cybersecurity Takes a Village

Former attorney general argues for making security an institutional priority, outlines parallel between information security and 'war on terror.'

The Managed Security Market

A Frost & Sullivan report looks at the growth drivers for the North American MSSP market.

GlobalSCAPE Bets on Cloud for Managed File Transfer

San Antonio-based GlobalSCAPE has partnered with Rackspace Hosting to provide its Enhanced File Transfer Server as a subscription.

Microsoft and E-Fraud Group Aim to Stop ID Theft

New app helps to cut down on phishing, ID theft, and account compromises by letting investigators quickly report stolen credentials and credit card numbers.

Microsoft Sues Spammers Who Abused Its Spam Filters

In yet another move to take a bite out of cybercrime, Microsoft's Digital Crime Unit sues over one of the largest spam attacks ever.

DNSSEC Key Signing Designed to Make the Internet More Secure

A critical milestone in the history of Internet security happened this week at a "key signing" ceremony. Are we all now safer as a result?

A Buyer's Guide to Web Security Solutions

A Sophos white paper offers guidance on selecting an effective web security solution.

Microsoft: Privacy in the Cloud Is a Priority

Microsoft's chief privacy strategist tells CFP conference attendees that protecting and ensuring accountability for user information requires the participation of a wide group.

Can Federal Data Privacy Live On in the Cloud?

White House IT officials have been exuberantly talking about moving government IT to the cloud, and the process is already in motion, but federal privacy officers are speaking up.

Windows XP Zero-Day Exploit Spawns Attacks

So-called "limited" attacks have appeared since a security researcher revealed a hack that could put Windows XP users at risk of attack.

VeriSign Taps Growing SSL Certification Market

Soon to be part of Symantec, VeriSign's SSL security certification business is growing as the need for SSL continues.

Review: Kanguru Remote Management Console Cloud Edition

Perfect for SMBs, KRMC Cloud ($19.95 per drive per year) offers affordable thumb drive security with a public cloud service.

Online Fraud and Data Theft in the UK

CyberSource's sixth annual UK Online Fraud Report finds that British businesses lost an average of £400,000 to online fraud in 2009.

Lieberman Racing to Mark Up Cybersecurity Overhaul

Committee leadership races to bring major cybersecurity legislation that would expand White House and DHS authority over private sector to a markup.

Apple Updates Mac to OS X 10.6.4 for Security

Dozens of security fixes are made in the latest Snow Leopard update from Apple, and a few feature fixes, too.

Ensuring Data Security

An M86 Security white paper offers advice on implementing a successful data loss prevention strategy.

Censorship vs. Security, the Foreign Policy Debate

The State Department has been elevating the profile of Internet censorship as a diplomatic priority since Hillary Clinton took over, but free speech advocates are concerned.

Security Budgets on the Rise

A Deloitte survey of financial institutions finds that the majority of security budgets have increased.

OWASP Top Ten 2010 Web App Risks

Protect your business against this year's ten most worrisome Web application security risks.

Calif. Hospitals Hit With Stiff Data Security Fines

Five California hospitals were fined a total of $675,000 last week by the state's Department of Public Health for failing to prevent unauthorized access to patients' data.

FCC Issues Warning, FBI Investigates iPad Breach

Alarmed at the recent exposure of more than 100,000 iPad users' data, FCC issues a warning on cybersecurity. Meanwhile, AT&T seeks to reassure customers that all's well.

Trend Micro Buys Cloud Storage Provider Humyo

The security software vendor acquires a cloud-based storage company to provide online backup and data synchronization services for small businesses and individual consumers.

New World Cup Malware Features One-Two Combination

A new World Cup-themed malware campaign is incorporating a two-pronged strategy to target and infect large Brazilian finance, chemical and manufacturing firms.

Keeping Pace with Data Encryption Laws

At both the state and federal levels, a bevy of bills and laws are proposed or in effect, which require securing and even encrypting PII.

Microsoft Warns of Security Flaw in Windows XP

Windows XP may be nine years old but, as the most popular version of Windows, it leaves a lot of users in a precarious position when a serious security hole pops up.

Facebook Teams With PTA in Online Safety Push

World's leading social network partners with PTA to promote online safety, pledges $1 million to the cause.

Microsoft: Patch for Office XP Flaw 'Infeasible'

How does Microsoft plan to handle a validation flaw in Windows XP that's not covered by its monthly Patch Tuesday series of fixes? ‘Fix It,’ of course.

AT&T Gaffe Exposes 114,000 iPad E-Mail Accounts

The security hole that allowed at least one organization to access e-mail accounts belonging to iPad owners including Michael Bloomberg and Rahm Emanuel has been closed, AT&T says.

Cheating on a Security Audit

According to a recent survey, 10 percent of IT professionals have cheated to get an audit passed.

HP, Symantec Extend Security Pact to Safeguard PCs

Leading security software vendor and the world's largest computing company announced a multi-year deal that will keep Norton Internet Security on all HP PCs for free for 60 days.

Mitigating the Security Risks of Social Media

An ISACA white paper looks at the benefits and the security risks inherent in social media, and suggests several risk mitigation techniques.

Adobe Preps Crucial Flash Fix

Adobe Systems says it will issue an important patch for an exploit to its popular Flash Player later this week, and fixes for Reader and Acrobat by month's end.

Google Updates Chrome for Security, IE

Nine highly critical flaws get patched in Chrome as Google's Chrome Frame hits beta.

Microsoft Fixes Three 'Critical' Security Holes

With only three "critical" vulnerabilities to patch in June, you'd think that it was going to be an easy week for system administrators -- but you'd be wrong.

Buying Guide for Cloud-based E-mail

We outline the key considerations for companies looking to make informed, risk-sensitive, purchasing decisions when selecting a cloud-based e-mail solution.

Botnet Takes Control of Penn State Computer

A university computer holding the social security numbers and other critical data for 15,800 students was communicating with a botnet's command-and-control center for months.

Outbound Spam Prevention

A study by Osterman Research and Commtouch has found that 68 percent of service providers say outbound spam is costing them up to $100,000 a year.

HP Lands Air Force Cyber Defense Contract

HP will be providing infrastructure and applications integration for a Cyber Control System designed to provide strategic information and identify cyber threats for the USAF.

Microsoft Releases Patches for Silverlight

The software giant patches several bugs in Silverlight 4.0, the latest major release of the streaming media client.

Adobe Flash, PDF at Zero-Day Vulnerability Risk Again

Adobe warns of serious security flaws in flash and PDF that could be leaving millions of users open to attack.

Software Security Initiatives Using the Building Security In Maturity Model

Make strong software security initiatives a priority.

Google Opens Up on Its Security Practices

New security white paper details Google's security practices for its cloud-based apps.

Google Apps Security

A Google white paper examines the company's security policies and procedures.

World Cup Malware Ploy Targets Top Execs

Security-software vendors say hackers for months have been repeatedly targeting top-tier executives and government officials using the World Cup soccer tournament as a lure.

Defense Dept. Cyber Chief Warns of Mounting Threats

Speaking publicly for the first time since his installation in the top spot of the Defense Department's Cyber Command, Gen. Keith Alexander emphasizes the severity of the danger.

Cops, SIIA Bust Major Craigslist Piracy Duo

A pair of thieves who moved an enormous amount of counterfeit software applications through the online classified site have finally been busted.

Current Malware Threats

A Kaspersky Lab report examines the leading information security threats for the first quarter of 2010.

University of Louisville Patients' Data Exposed

A physician accidentally revealed the sensitive personal information of several hundred patients in the latest potential IT security breach to hit the medical field.

Security Concerns Cause Google to Quit Windows

According to a report in the Financial Times, Google began moving employees to other operating systems after its systems were hacked.

Three 'Critical' Microsoft Patches Coming

Microsoft has released its advance notice to IT administrators and this month's Patch Tuesday event may not be nearly as easy May's patch drops.

Cybercrime Security

An eEye Digital Security white paper examines current and emerging trends in cyber attacks and in methods of managing threats.

Hackers Make a Mess of Mop.com

Malware scamsters have weaseled their way into an unknown number of online gaming accounts on the popular Chinese entertainment site.

How to Securely Send E-mails and Transfer Files

These days, when it comes to the Internet, you can never be too careful. Learn how to more securely send and receive data via e-mail and FTP.

Assessing the Malware Threat

A Bit9 survey finds that only 32 percent of respondents feel confident that their businesses are protected from malware.

Facebook Contends With Latest 'Likejacking' Scam

The latest clickjacking scheme on Facebook managed to trick hundreds of thousands of users into "liking" and posting malicious links on their personal pages.

New OTP Solution Utilizes Mobile Phones

A cloud-based authentication specialist wants to make financial transactions more secure through the use of one-time password technology on mobile devices.

House Passes National Defense Authorization Act

An amendment included in the final version of the NDA act would install a permanent cybersecurity office in the White House and reshape government IT security compliance.

FBI Goes After 'Scareware' Scams

A new federal indictment exposes a common Internet scam--tricking users into thinking they've been infected with malware so they'll buy bogus security products from cybercriminals.

A Closer Look at the KOOBFACE Botnet

A Trend Micro white paper offers an in-depth examination of the highly successful botnet.