Data breaches exploit configuration errors, not software vulnerabilities

Posted by admin | Posted in Data Security, Hacking, Intrusion detection and prevention, Malware, News, Patch management, Security Central | Posted on 29-07-2010

Hackers appear to be increasingly counting on configuration problems and programming errors rather than software vulnerabilities in order to steal information from computer systems, according to a new study from Verizon.

The quiet threat: Cyber spies are already in your systems

Posted by Galen Gruman | Posted in Cyber Security, Data Security, Intrusion detection and prevention, Leak prevention, News, Phishing/pharming, Risk Management, Security Central, Security event/information management | Posted on 26-07-2010

Is your company’s data under surveillance by foreign spybots looking for any competitive advantages or weaknesses they can exploit? This might sound farfetched, but such electronic espionage is real. It’s an insidious security threat that’s a lot more common than you probably realize.

As an IT or security executive, determining whether your organization is under attack via this seemingly undetectable threat — and putting in place adequate technology and procedural safeguards — should be a high priority. The stakes are too high to ignore the problem.

The quiet threat: Cyber spies are already in your systems

Posted by Galen Gruman | Posted in Data Security, News, Security Central | Posted on 26-07-2010

Is your company’s data under surveillance by foreign spybots looking for any competitive advantages or weaknesses they can exploit? This might sound farfetched, but such electronic espionage is real. It’s an insidious security threat that’s a lot more common than you probably realize.

As an IT or security executive, determining whether your organization is under attack via this seemingly undetectable threat — and putting in place adequate technology and procedural safeguards — should be a high priority. The stakes are too high to ignore the problem.

Second variant of Stuxnet worm strikes

Posted by admin | Posted in Data Security, Endpoint security, Hacking, Malware, News, Security Central | Posted on 20-07-2010

Researchers at Eset have discovered a second variant of the Stuxnet worm that uses a recently disclosed Windows vulnerability to attack Siemens industrial machines .

The second variant, which Eset calls “jmidebs.sys,” can spread via USB drives, exploiting an unpatched flaw in Windows involving a malicious shortcut file with the “.lnk” extension.

IBM boosts IPS platform with Web application security, data-loss prevention

Posted by admin | Posted in Data Security, IBM, Intrusion detection and prevention, News, Security Central | Posted on 16-07-2010

IBM announced it has added capabilities for Web application protection and data-loss prevention (DLP) to the basic technology platform for its intrusion-system prevention (IPS) product line.

4 reasons why execs are the easiest social engineering targets

Posted by admin | Posted in Data Security, Hacking, Leadership, News, Phishing/pharming, Security Central | Posted on 14-07-2010

Security managers are often concerned about employees who use Facebook at work and fall for the 419 “I’m trapped in London and need money” scam. Others might still have some in their organization who are convinced it is the Prince of Nigeria who wants to share his fortune. And with spear phishing, a targeted email attack in which messages are created to look like they come from an employer, bank or other trusted source, now a common criminal technique, the need for effective awareness programs for employees has become paramount.

Oracle releases critical patches for database security

Posted by admin | Posted in Data Management, Data Security, Database Management Systems, News, Oracle, Patch management, Security Central | Posted on 14-07-2010

Oracle released a set of 59 patches on Monday to fix security vulnerabilities across its entire range of database, application, and middleware products.

The patches include fixes for three critical flaws affecting virtually every supported version of the company’s Database Server technology.

Security rule No. 1: Assume you’re hacked

Posted by Roger A. Grimes | Posted in Data Security, Hacking, News, Security Central | Posted on 13-07-2010

A recent Forbes magazine article advised readers to assume that their companies have been hacked. Some readers have asked me to weigh in, and here’s my assessment: The article is slightly hyperbolic, but all in all, it’s a pretty accurate assessment. Most companies are actively hacked, and their sensitive data is being stolen and leaked to outsiders.

Websense offers free enterprise DLP suite

Posted by admin | Posted in Data Security, News, Security Central, data loss prevention (DLP) | Posted on 08-07-2010

Websense Thursday is announcing that it’s making its data-loss prevention (DLP) suite free for 30 days under a “DLP for Download” program.

The roughly 600MB download available at the Websense.com site is the full enterprise Websense Data Security Suite. The download can be installed in a VMware-based environment and is intended to provide a quick way to evaluate the effectiveness of the software for stopping unauthorized transmission of data.

iPhone 4 business users get remote data wiping

Posted by admin | Posted in Data Security, Iphone, Mobile device management, Mobilize, News, Patch management, Security Central | Posted on 30-06-2010

Businesses worried about keeping tabs on the latest Apple iPhone will soon be able to remotely interact with the devices in the event of theft, loss or mishap, Absolute Software has announced.

Using an update due in the next quarter, Absolute Software will enable Apple iPhones running iOS 4 to be remotely managed like any other portable computer using the company’s Absolute Manage system, the company said.

From the labs: IT’s future today

Posted by Jason Snyder | Posted in Applications, Data Explosion, Data Security, Encryption, Hardware, Memory, Networking, News, Processors, Security Central, wireless networking | Posted on 21-06-2010

For all its promise of revolution, the computing industry often lags behind expectations. After all, your netbook is really just a laptop, only smaller and cheaper. The chip that powers your PC today has a direct lineage back to the Pentiums of yesterday. Your latest hard drive might hold 2TB, but it’s still just a hard drive. Where’s the real innovation?

In the labs, of course.

iPad hack not so harmless

Posted by InfoWorld Tech Watch | Posted in AT&T, Data Security, Hacking, Ipad, Leak prevention, Mobilize, News, Security Central | Posted on 17-06-2010

iPad hack not so harmless

The hack of iPad user info on the AT&T site may be much worse than an embarassment, according to a security researcher who specializes in mobile devices.

AT&T reportedly bungles handling of private data, again

Posted by admin | Posted in AT&T, Data Security, Iphone, Mobilize, News, Privacy, Security Central, Smartphones | Posted on 16-06-2010

This hasn’t been AT&T‘s month. First, security researchers found a loophole in the company’s Website that could be used to reveal email addresses for tens of thousands of Apple iPad customers.

Controversial Windows XP vulnerability now being exploited

Posted by admin | Posted in Data Security, Hacking, News, Security Central | Posted on 15-06-2010

The Windows XP exploit that was published by a Google engineer last week is now being exploited in the wild, according to researchers at Sophos Labs.

The vulnerability, which could allow remote code execution if a user views a specially crafted Web page using a Web browser, or clicks a specially crafted link in an e-mail message, was published by Tavis Ormandy just five days after he alerted Microsoft to the problem.

Hacker group: Apple iPad ‘simply not a safe platform’

Posted by InfoWorld Tech Watch | Posted in AT&T, Apple, Data Security, End-user hardware, Ipad, Mobile Platforms, Mobile Security, Mobilize, News, Security Central | Posted on 14-06-2010

Hacker group: Apple iPad 'simply not a safe platform'

Apple’s reputation for security continues to take hits as hacker group Goatse Security today accused the company of failing to patch a flaw in Safari — known

AT&T apologizes, blames hackers for iPad email breach

Posted by admin | Posted in AT&T, Data Security, Hacking, Ipad, News, Other mobile devices, Security Central | Posted on 14-06-2010

AT&T issued an apology on Sunday for a hack that exposed thousands of iPad customers’ email addresses last week and vowed to work with law enforcement to prosecute those responsible.

The AT&T data leak is no big deal — really

Posted by Robert X. Cringely | Posted in AT&T, Adventures in IT, Data Security, Ipad, Mobile device management, Mobilize, News, Other mobile devices, Security Central, internet | Posted on 11-06-2010

Getting a chance to bash AT&T twice in two weeks is like getting to hit a pinata filled with $100 bills. Hand me the stick and stand back, boys.

Sloppy AT&T software led to theft of iPad email addresses

Posted by admin | Posted in AT&T, Data Security, Ipad, Mobile Platforms, News, Privacy, Security Central | Posted on 10-06-2010

The harvesting of over 100,000 iPad 3G owners’ email addresses was not a hack or a classic data breach, but a brute force attack of a minor feature AT&T offered to Apple customers, experts said Wednesday.

According to New York-based Praetorian Security Group, which obtained a copy of the PHP script used to scrape email addresses from AT&T’s servers, the attack succeeded because the mobile carrier used poorly designed software.

How to secure business info: Keep employees off the Internet

Posted by InfoWorld Tech Watch | Posted in Data Security, News, Security Central, Tech industry analysis | Posted on 08-06-2010

How to secure business info: Keep employees off the Internet

There they go again: Trying to scare business and IT executives into buying yet more security tools.

Mobile phone security dos and don’ts

Posted by admin | Posted in Anti Virus, Blackberry, Data Security, Google Android, Iphone, Mobilize, News, Security Central, Smartphones | Posted on 08-06-2010

It used to be a luxury to own a smartphone. Now everyone seems to have one, and can’t seem to do their jobs without it.