Stories by Gregg Keizer

Oracle renumbers Java patch updates, confuses users even more

By Gregg Keizer | 16 May, 2013 10:06

Oracle has changed the numbering of its Java security updates, prompting one expert to say, "As if Java updates weren't confusing already."

Apple keeps patching Java on OS X Snow Leopard after proposed drop-dead date

By Gregg Keizer | 17 April, 2013 14:28

Apple on Tuesday patched Java for the aged OS X Snow Leopard and tweaked Safari to give users more control over what websites they let run the vulnerability plagued Oracle software.

Microsoft takes new 'Scroogled' shot at Google

By Gregg Keizer | 09 April, 2013 20:29

Microsoft today launched a third wave of 'Scroogled,' its attack ad-based campaign aimed at Google, this time highlighting what it said were privacy flaws in the latter's Android app store.

XP migration easy pickings over, say experts

By Gregg Keizer | 09 April, 2013 10:59

The easy upgrades to Windows XP have already been done, migration experts said, predicting that a large number of enterprises will still be running the aged OS a year from now.

Ad industry threatens Firefox users with more ads if Mozilla moves on tracking plans

By Gregg Keizer | 25 March, 2013 10:28

The online ad industry has attacked Mozilla over its decision to block third-party cookies in a future release of Firefox, calling the move "dangerous and highly disturbing," and claiming that it will result in more ads shown to users.

Security experts applaud Apple's new two-factor authentication

By Gregg Keizer | 23 March, 2013 15:58

Apple this week followed the lead of rivals like Facebook, Google and Microsoft, offering two-step authentication to help customers secure their Apple IDs against hacking.

Apple sneaks Safari update into Snow Leopard

By Gregg Keizer | 19 March, 2013 21:39

Apple last week silently updated the aged Safari 5 browser for Snow Leopard to version 5.1.8, more evidence that the company intends to support the 2009 operating system for an unusually long time.

Google pays $40K to 'Pinkie Pie' for partial hack of Chrome OS

By Gregg Keizer | 18 March, 2013 18:41

Google today said it had paid a researcher $40,000 for a partial exploit of Chrome OS at its Pwnium 3 hacking contest two weeks ago.

Apple not ready to kill OS X Snow Leopard yet

By Gregg Keizer | 15 March, 2013 17:47

Apple yesterday gave its strongest signal yet that it will continue to support OS X Snow Leopard with patches for the foreseeable future rather than retire the still-active operating system.

Apple updates Mountain Lion, patches Safari

By Gregg Keizer | 15 March, 2013 13:21

Apple has updated OS X Mountain Lion for the first time in six months, patching 14 security vulnerabilities and addressing a host of other issues.

Security pros pan and praise Microsoft's plans on updating Modern apps in Windows 8, RT

By Gregg Keizer | 14 March, 2013 14:29

Microsoft will issue security fixes for its Windows Store apps on the fly, not just on the familiar monthly Patch Tuesday, the company said this week.

Adobe patches Flash, but doesn't get around to Pwn2Own bug

By Gregg Keizer | 12 March, 2013 20:29

Adobe today patched Flash Player, the fifth time this year it's updated the vulnerability-plagued software.

Pwn2Own hacking contest winds down after paying a record $480K

By Gregg Keizer | 08 March, 2013 16:23

A day after researchers hacked Chrome and Firefox at the Pwn2Own contest, Google and Mozilla patched their browsers Thursday.

Scroogled dents Google's reputation, claims Microsoft

By Gregg Keizer | 07 March, 2013 23:15

Microsoft's anti-Google "Scroogled" campaign is a battle for hearts and minds as much as for search and email market share, and Microsoft claims the effort is making a difference.

Researchers rake in $280K at Pwn2Own hacking contest

By Gregg Keizer | 07 March, 2013 11:55

Research teams Wednesday cracked Microsoft's Internet Explorer 10 (IE10), Google's Chrome and Mozilla's Firefox at the Pwn2Own hacking contest, pulling in more than $250,000 in prizes.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Dynamic Threat Intelligence

The FireEye Dynamic Threat Intelligence cloud interconnects FireEye appliances deployed within customer networks, technology partner networks, and service providers around the world.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.