Application Security
News
- +
Facebook users targeted in massive spam run 19/03/2010 06:50:00
The messages try to get users to dowload a malicious attachmentFacebook's 400 million users have been targeted by a spam run that could infect their computers with malicious software designed to steals passwords and other data, according to security researchers at McAfee. - +
Law enforcement push for stricter domain name rules 18/03/2010 05:04:00
The changes would make it more difficult for criminals to register under false details for domain namesLaw enforcement officials in the U.K. and U.S. are pushing the Internet Corporation for Assigned Names and Numbers to put in place measures that would help reduce abuse of the domain name system. - +
60% of virtual servers less secure than physical machines, Gartner says 16/03/2010 07:47:00
New analyst group research looks at security issues around virtualizationSixty percent of virtual servers are less secure than the physical servers they replace, the analyst firm Gartner said in new research Monday. - +
Trusteer rolls out malware forensic tool for banks 16/03/2010 06:04:00
The software can detect malware on customer's computers and send it away for analysisSecurity vendor Trusteer's latest product will allow banks to remotely investigate their customers' computers if it is suspected the PC has been hacked. - +
Hackers love to exploit PDF bugs, says researcher 11/03/2010 08:25:00
Last month's Adobe Reader vulnerability now under attack, says F-Secure and MicrosoftHackers adore Adobe Reader, and have pushed it into first place as the software most often exploited in targeted attacks, a Finnish security company said today. - +
Hackers exploit latest IE zero-day with drive-by attacks 11/03/2010 06:26:00
Researchers expect attacks to explode once exploit code goes publicHackers are exploiting the just-disclosed unpatched bug in Internet Explorer (IE) to launch drive-by attacks from malicious Web sites, security researchers said today. - +
Source code management a weak spot in Aurora attacks 05/03/2010 05:56:00
McAfee says that hackers were after the source code management systemsCompanies should take extra steps to secure their source code from the type of targeted attacks that hit Google, Adobe, Intel and others over the past few months. - +
New zero-day involves IE, puts Windows XP users at risk 01/03/2010 14:10:00
Microsoft investigates unpatched flaw that affects users running IE7 and IE8Microsoft on Sunday confirmed it's investigating an unpatched bug in VBScript that hackers could exploit to plant malware on Windows XP machines running Internet Explorer (IE). - +
UK registry to implement DNS security protocol 01/03/2010 03:34:00
The system, DNSSEC, prevents hackers from redirecting people from legitimate domains to fraudulent onesNominet, the U.K.'s domain name registry, will begin implementing a security protocol on Monday designed to protect the DNS (Domain Name System). - +
Adobe working to fix security bug in Download Manager 22/02/2010 05:40:00
Software could give an attacker a way to install an unwanted programAdobe Systems is working to fix a glitch in software it uses to speed up downloads of its products that could give hackers a way to push malicious programs onto a victim's PC. - +
Adobe to rush out another critical Reader patch 15/02/2010 07:35:00
A Flash Player flaw, patched Thursday, affects Reader and Acrobat as wellJust weeks after patching a critical flaw, Adobe Systems is rushing out another patch for its Reader and Acrobat software. The company also patched a critical issue in Flash Player Thursday. - +
Australian parliament Web site attacked 11/02/2010 05:32:00
Denial-of-service attack comes after warning from AnonymousThe Australian Parliament's Web site was hit by an apparent denial-of-service attack Wednesday, two days after the hacking group Anonymous threatened attacks over the government's plan to filter Web content. - +
CA brings SOA security to open source JBoss 09/02/2010 10:08:00
More commercial options for widely-used app serverCA has announced its SiteMinder and SOA Security Manager products are now available for the open source JBoss middleware platform. - +
Gmail of foreign journalists in China hijacked 19/01/2010 06:36:00
Google says cyberattacks have also recently targeted the Gmail accounts of Chinese human rights activistsThe Gmail accounts of foreign reporters in at least two news bureaus in Beijing have been hijacked, a journalists' group in China said Monday. - +
Report: India claims it was also hacked by Chinese 19/01/2010 06:49:00
The attacks came the same day U.S. companies were also hacked, said the country's security advisorThe office of India's National Security Advisor, M.K. Narayanan, and other government offices in India were targeted by hackers believed to be from China, according to a report.
Features
- +
Windows 7 Tips: Best Security Features 04/02/2010 04:52:00
IT can specify which applications can run on employees' desktopsFor both enterprises and consumers, one of the big draws of Windows 7 has been its tighter security features. - +
Cloud Security: Ten Questions to Ask Before You Jump In 28/01/2010 07:08:00
The reality is security responsibility will be sharedThe hype around cloud computing would make you think mass adoption will happen tomorrow. But recent studies by a number of sources have shown that security is the biggest barrier to cloud adoption. The reality is cloud computing is simply another step in technology evolution following the path of mainframe, client server and Web applications, all of which had -- and still have -- their own security issues. - +
Why traditional security doesn't work for SOA 19/01/2010 07:38:00
SOA's strengths turn out to be highly exploitable entry points for attackersMany organizations are embracing SOA as a way to increase application flexibility, make integration more manageable, lower development costs, and better align technology systems to business processes. The appeal of SOA is that it divides an organization's IT infrastructure into services, each of which implements a business process consumable by users and services. - +
Plumbers' Co-operative filters out spam deluge 26/11/2009 11:09:00
Gateway appliance chosen over hosted solutionWith spam hampering staff productivity and increasing helpdesk calls, Sydney-based plumbing suppliers company Plumbers' Supplies Co-operative Ltd has replaced an open source e-mail security solution with an network gateway appliance. - +
Facebook Tips: Staying Safe While Using Games and Apps 13/11/2009 10:34:00
Click a link on Facebook and your computer might be infectedIf you're one of the 63.7 million people playing the popular Farmville game on Facebook, you've probably noticed a change in how you earn points. FarmVille's parent company, Zynga, agreed last week to remove deceiving mobile subscriptions and "scammy" offers that lure players to register for services in exchange for game currency, which helps players to advance in the game. - +
Researchers advise cyber self defense in the cloud 12/10/2009 21:16:00
Web services and access from anywhere, any time make the cloud a risky place.Security researchers are warning that Web-based applications are increasing the risk of identity theft or losing personal data more than ever before. - +
Careless downloading makes BlackBerry users spy targets 08/10/2009 01:15:00
A security researcher said downloading foreign applications to a BlackBerry leaves you vulnerable to spiesIPhone lovers and other smartphone users should take heed: A security researcher showed ways to spy on a BlackBerry user during a presentation Wednesday, including listening to phone conversations, stealing contact lists, reading text messages, taking and viewing photos and figuring out the handset's location via GPS. - +
Windows attack code out, but not being used 07/10/2009 07:21:00
Metasploit module is considered unreliable by security expertsIt has been a week since hackers released software that could be used to attack a flaw in Windows Vista and Server 2008, but Microsoft and security companies say that criminals haven't done much with the attack. - +
Cloud security: time to smoke another one? 01/09/2009 04:19:00
CSOonline embarks on a series about cloud computing risks and how to minimize them. Here's how you, the reader, can be part of the solution.Chris Hoff, one of the most respected voices on the topic of virtualization and cloud security, once told me in an interview that people should shut up about securing the cloud because, in his opinion, there's no such thing as cloud security. - +
CIO and CSO should take a follow the money approach to security: IBM X-Force 27/08/2009 10:15:00
IBM X-Force report finds Web sites and Web applications were major vulnerability for enterprises in 2008CIOs and CSOs could do well to consider the monetisation cost and overall profitability of security risks when considering how to safe guard their organisations, according to the findings of a new report from IBM’s Internet Security Systems X-Force research and development team. - +
Five lessons from Microsoft on cloud security 26/08/2009 05:00:00
The software titan reviewed its security approach to cloud computing and developed new strategies. Here's what one Microsoft cloud expert says he's learned.While Google, Amazon and Salesforce have gotten the most attention as cloud service providers, Microsoft-with its 300 products and services delivered from its data centers-has a large cloud bank all its own. - +
Cloud hype peaks, but IT concerns increase 27/08/2009 06:51:00
How big is the cloud marketing challenge? CIO.com's newest survey of IT professionals on cloud computing shows fears regarding security, data management, TCO, compliance and vendor lock-in have only spiked since one year ago.Apparently the everpresent cloud computing marketing messages aren't working quite well enough: Tech buyers still have major concerns regarding cloud-based benefits and security issues, many of which have not eased during the past year. - +
Is your PC bot-infested? here's how to tell 25/08/2009 02:32:00
Bots have recently invaded cell phones, tooAs fireworks boomed on the Fourth of July, thousands of compromised computers attacked U.S. government Web sites. A botnet of more than 200,000 computers, infected with a strain of 2004's MyDoom virus, attempted to deny legitimate access to sites such as those of the Federal Trade Commission and the White House. The assault was a bold reminder that botnets continue to be a massive problem. - +
Survey: Facebook, Twitter banned by most employers 20/08/2009 03:33:00
Research from ScanSafe says 76 percent of companies restrict access to popular Web 2.0 sites because of security and productivity concernsEmployers are increasingly putting the brakes on employee use of social networking sites on the job, according to a new survey. The research, released Wednesday by ScanSafe, a provider of SaaS Web security, said its data shows more employers are blocking sites such as Facebook and Twitter. The results run counter to a story published by CSO in March 2009 that cites research which found most employers do allow access to Web 2.0 in the office. - +
SOA security: good enough and getting better 20/08/2009 05:35:00
Forrester Research SOA expert Randy Heffner discusses how to establish an iterative design process for evolving your SOA security architecture that considers your current and future security requirements.Security is not a reason to stay away from SOA. Although full SOA security maturity is yet to come, 30 percent of organizations now use SOA for external integration with customers and partners. For standard Web services using SOAP, WS-Security has achieved critical mass as a foundational standard. On the other hand, advanced SOA security - involving federation among partners, nonrepudiation, and propagation of user identities across multiple layers of service implementations - is in its early days.
Case Studies
- +
Uni fortifies Western Front with IDS 22/02/2008 20:11:00
Nurtured NAC keeps malware outThe University of Western Sydney (UWS) has today gone live with a managed Intrusion Detection System (IDS) for its 5000 users.
Interviews
- +
Bogus security promises and how to detect them 14/03/2008 10:13:00
Data leakage, smartphone malware, hotspot threats are discussed by security analyst Nick SelbyWhat is true enterprise security and how do you get it? Bogus promises by vendors are all too common. In this interview, outspoken security analyst Nick Selby humorously tackles the truth about data leakage products, smartphone protection, hotspot threats and the word "solution." Nick Selby leads The 451 Group's Enterprise Security Practice. Selby also serves as The 451 Group's Director of Research Operations and is on the faculty of the Institute for Applied Network Security.
Opinions
- +
The Myth of Cloud Computing 04/12/2008 08:25:00
Why the rapid spread of virtual technology is becoming a security riskWhy the rapid spread of virtual technology is becoming a security risk. - +
Cutting Through the Spin of Recent Vulnerability Disclosures 13/10/2008 11:53:00
The FUD surrounding the ClickJacking and TCP/IP vulnerabilities has the world seemingly frozen in fear. But once you cut through the spin, the vulnerabilities aren't all that they were made out to be.There are a few highly publicised vulnerabilities at the moment which haven't completely been disclosed and which, it is claimed, could threaten the whole Internet as-we-know-it. Only, when the vulnerabilities are finally disclosed, it seems that the whole incident has been somewhat Chicken Little. - +
Are we about to witness a real OS X virus? 24/07/2008 14:27:59
Intego might have stumbled across an OS X specific virus being offered for auction that targets a previously unknown ZIP archive vulnerability.Mac antivirus maker, Intego, have published an interesting alert about a potential OS X virus that an enterprising individual is trying to sell through auction. With absolutely no technical information to go on, the antivirus maker is treating the announcement with caution. - +
Hacking tools: A new version of BackTrack helps ethical hackers 30/06/2008 10:57:21
BackTrack is the quickest way to get access to hundreds of (legal) hacking toolsVersion 3.0 of BackTrack has been released. BackTrack is a Linux-based distribution dedicated to penetration testing or hacking (depending on how you look at it). It contains more than 300 of the world's most popular open source or freely distributable hacking tools. - +
A resurgent Denial of Service threat emerges 11/06/2008 19:12:24
Something new might be emerging from the underground.A less known part of the recent ARP attack against H D Moore's MetaSploit site was an attempted Denial of Service attack that coincided with the successful ARP attack. - +
Zero-second exploits 06/05/2008 12:04:48
The number of days between a vendor patch being released and the malware exploit being announced has shrunkMicrosoft SQL server hasn't had a public vulnerability announcement since 2004. The SQL Slammer worm struck in 2005, but the hole the worm exploited had been patched six months before. The holes that MS-Blaster and Code Red worm attacked had been patched, too. But back just a few years ago, no one really cared about patching really. We just didn't patch. - +
Attackers are thinking outside the box 17/04/2008 11:19:36
How to predict what the next attack will look likeIn the adversarial environment of information security, new types of attacks emerge constantly. Just recently, a very highly targeted phishing attack against CEOs used the pretext of a federal grand jury subpoena to lure executives to a site hosting malware. Let's face it: Most of the innovation in this industry is on the other side, the "dark" side. We are unfortunately forced to keep reacting to new ingenious attacks every few years. - +
What spooks Microsoft's chief security advisor 27/03/2008 11:12:24
Application exploits, virtualization security are big concernsMicrosoft's US general manager/chief security advisor for its National Security Team thinks like a true security professional: In every bit of good news, Bret Arsenault wonders what bad news could be lurking behind it. - +
Code name: Secure software 13/03/2006 14:34:47
Code writers now occupy the front line in the battleground of software security as the defense shifts from perimeter protection to prevention function that's built in during the application development phase.
Additional Resources
CSO Online Member Login
Devious Ransom Trojan Takes Your Data Hostage 2010-01-27 14:08:00+11
Symantec Simplifies Information Management for Enterprise Organisations with NetBackup 7 2010-01-27 11:52:00+11
Symantec to Deliver Deduplication Everywhere to Mid-Sized Businesses with Backup Exec 2010 2010-01-27 11:43:00+11
Cisco, NetApp and VMware Collaborate to Deliver New Capabilities for the Dynamic Data Centre 2010-01-27 10:48:00+11
Websense Enhances Web Security Gateway Coverage for Facebook - Announces Integrated Defensio Social Web Threat Detection 2010-01-22 14:53:00+11
Whitepaper
Making the move to Ethernet | A DECISION GUIDE
While enterprises today need higher bandwidth, there is increasing demand for solutions that can provide scalability, performance, simplicity and control at lower costs. Get the best of both worlds - read about Ethernet adoption today.
Sponsored Links


