Application Security — News
The new IAM: nailing shut the door on the Trojan horse
Cloud, mobility and bring-your-own-device (BYOD) computing are providing so many new potential ingress points to your network that it’s getting near impossible to keep up. The solution, as David Braue finds, lies in reconsidering your exposure, revisiting your IAM strategy – and picking your battles carefully.
Trend Micro's new paradigm: old (but good) advice in a new bottle
Information security vendors are telling customers to think in a new way. At the core of their advice is the idea — the admission, if you like — that no matter how good the defences they sell, sooner or later the bad guys will get through.
Oracle updates Java 7 after Apple’s browser plugin block
Oracle on Friday released its February critical patch update for Java 7 two weeks ahead of schedule and days after Apple blocked it for the second time in a month.
Whonix: An OS for the era of Anonymous and Wikileaks
Anonymity is an increasingly scarce commodity. Google's latest Transparency Report revealed government requests for data about users of its online services are increasing. It's not hard to find examples of threats to privacy — either intentional or unintentional.
SANS: Closeted IPv6 causing “angst” amongst security pros
Almost two years after ‘IPv6 day’ in 2011, security professionals cannot confidently manage security threats posed by the replacement to IPv4, according to the SANS Institute's Internet Storm Centre.
Review: Mobile Security
With mobile devices now ubiquitous in the workplace, you need to have some level of protection in place. Ashton Mills investigates.
Disable ‘UPnP’ on networked devices now, say researchers
Security researchers are warning businesses and consumers to immediately disable Universal Plug and Play (UPnP) functions on thousands of networked device products after revealing common flaws that can be easily exploited by a remote attacker.
Australia lags in online security awareness
An online survey of IT managers polled more than 2000 companies, each with 500 or more employees, in several countries—Australia, Canada, the United States, Germany, UK, France, Brazil, and India. 225 firms were surveyed in Australia.
Google Apps customers get ‘private’ app channel on Play
Google has opened a private channel in its Google Play app store for Google Apps business customers to distribute Android apps to their employees.
Google yanks fake iLife, iWork apps from Android’s Play
A spoofed version of Garage Band, the free OS X software that costs $4.99 as an iOS app, made a brief appearance on Google Play for $4.98 this week along with Apple's productivity suite, iWork.
Anonymous threatens Zynga games leaks for layoffs
Zynga, the embattled games company behind Facebook hit FarmVille, could have a number of its games leaked and made available for free if it does not scuttle an offshoring plan.
Six IT support scams’ funds frozen: hitting Aussies since ‘09
A US District Court Judge has frozen the funds of six fake-virus phone operations that have been targeting consumers from English speaking nations, including Australia, for years.
Adobe hacked, malware signed as Adobe
Adobe says “advanced persistent” hackers broke into its software development servers and compromised its code signing certificate procedures to pass off Windows malware as trusted Adobe products.
Tinfoil aims to cut out web application security humans
Tinfoil, a security company that launched its public beta on Wednesday, hopes to weed out web application vulnerabilities -- and the security consultants that fix them -- by helping smaller companies do it themselves.
CSO: the art of catching the board's ear
The success of a CSO and the enterprise’s security strategy depends on awareness at the C-level of not just the threats, but their implications, making communications and building alliances outside IT the key to a CSO’s success. The battle to secure data has become a more vicious and dynamic beast today, according to Mike Rothman, CEO of analyst firm Securosis, who says attackers, including actors who may have “very deep pockets” that tilt the balance of power in their favour. Add these to the chaos of hacktivists, well-organised cybercriminals, social media and Cloud computing, and the challenges that CSOs face in protecting corporate data become clear.
Now League of Legends hit by hackers
Riot Games, the developer of League of Legends, is warning all its 32 million users to change their passwords after hackers breached its western European, Nordic and eastern European database.
AusCERT 2012 Day 1 : Is security growing up at last?
The first is that the delegates don’t seem to have seen it this way. Nobody seemed to doze off early this afternoon after even the third session with a predominantly legal focus (Nick Abrahams of Norton Rose following Bill Caelli following Robert Clark).
After outcry, Adobe says it will patch CS5
Adobe is partially reversing a decision not to patch flaws in Illustrator and Photoshop 5 and earlier following outcry from customers.
15 bad apps sneak past Google’s ‘bouncer’
Despite Google’s best efforts to prevent malware entering its official market, Google Play, it let 15 data-stealing apps slip by, according to security vendor, McAfee.
Mozilla gives CAs a chance to come clean about certificate policy violations
Mozilla has asked all certificate authorities (CAs) to revoke subordinate CA certificates currently used for corporate SSL traffic management, offering an amnesty to any CAs that had breached Mozilla's conditions for having their root certificates ship with its products.
- 1
The new IAM: nailing shut the door on the Trojan horse
- 2
Despite $1.46b furphy, 2013-14 Budget offers slim pickings for cyber security
- 3
VMWare wants software defined data centres for better security
- 4
iiNet’s Web analytics delivers real-time security bonus
- 5
Security a key factor in LogMeIn’s Internet of Things platform
-
Splunk Named a Leader in Gartner Magic Quadrant for SIEM
-
Dell Sets Sights on Cisco, Announces Game-Changing NSA Series That Introduces Powerful Next-Gen Firewall Advances for Mid-sized Businesses and Distributed Enterprises
-
Silver Peak saves Riverbed customers up to 86 per cent with software upgrade program
-
Ovum analysis ranks Orange Business Services ahead of APAC competition for service capability and strategy
-
2013 Brightcove Innovation Award Winners Announced at PLAY 2013 Global Customer Conference
- FTSnr Web Developer PHP/Magento/API integration into E-commerce sites. $100k+SuperNSW
- FTTest Analyst (MS Environment) .netNSW
- FTOS Web Applications DeveloperNSW
- FTWeb Developer- Drupal and PHP. Exciting new position- #2 in Dev team.$100k+SuperNSW
- FTSenior Python DeveloperNSW
- FTSenior Field Engineer - MSNSW
- FTSenior Python Web Applications DeveloperNSW
- FTSenior Projects EngineerNSW
- FTSenior E-Commerce PHP Developer- North Sydney- E-commerce Software $110kNSW
- FTTest Manager - IMMEDIATE STARTNSW
- FTSenior Python DeveloperNSW
- FT.NET - Sitecore Developer - Melbourne - PermNSW
- FTTest EngineerVIC
- FTTest Analyst (MS Environment) .netNSW
- FTR&D EngineerSA
- FTLead Software EngineerSA
- FTQuality ManagerSA
- FTTechnical Account Manager - MSP + CloudVIC
Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).
- Have an incident response plan.
- Pre-define your incident response team
- Define your approach: watch and learn or contain and recover.
- Pre-distribute call cards.
- Forensic and incident response data capture.
- Get your users on-side.
- Know how to report crimes and engage law enforcement.
- Practice makes perfect.
Warning: Tips for secure mobile holiday shopping
I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.










