Top IT Security Bloggers
-
When you fly nearly every week, you can get pretty bored on a plane. When I am sick of working, playing games, or watching movies, my latest distraction is checking out laptop screens. Sometimes I'm curious what movie you are watching but other times I am interested in what type of confidential company information you are displaying for the world to see.
-
Hard to criticize Anonymous for targeting Westboro Baptist Church
CSO OnlineSaying this won't earn me any popularity points. It may even be hypocritical given my criticism of Anonymous in the past. But my feelings are colored by the filth that is the Westboro Baptist Church. -
After Sandy Hook, how do we make schools more secure?
CSO OnlineThe tragedy in Newtown, Connecticut leaves us asking how to make school buildings harder to penetrate. But every sound idea has its limits. -
Windows passwords: "Dead in Six Hours" - paper from Oslo password hacking conference
Sophos - Naked SecurityThe total number of Windows passwords you can construct using eight keyboard characters is vast: one followed by 16 zeros, or near enough.
Gone in six hours.
Plus you get to heat your house at the same time.
-
Observations on the Evolution of Cyber Tactics in 2013
TrendLabs - Malware Blog“There is one thing stronger than all the armies in the world, and that is an idea whose time has come.” – Victor Hugo The world has reached a point of inflection in cybercrime. As cyberspace abounds with cyber privateers, and many nations of the world become havens for these modern-day pirates, it appears that [...]Post from: Trendlabs Security Intelligence Blog - by Trend Micro
Observations on the Evolution of Cyber Tactics in 2013 -
Monday review - the hot 18 stories of the week
Sophos - Naked SecurityHere you go.
All the stories we wrote in the past seven days, in case you missed anything (or just want to read them again).
-
Tapjacking: An Untapped Threat in Android
TrendLabs - Malware BlogUsing social engineering tricks, a developer can create an app that tricks users into tapping a specifically-crafted app popup window (called toast view), making it a gateway for varied threats.This attack, dubbed tapjacking, takes advantage of a specific vulnerability in Android user interaction (UI) component. This technique is not very complicated but has serious security [...]Post from: Trendlabs Security Intelligence Blog - by Trend Micro
Tapjacking: An Untapped Threat in Android -
Security Intelligence Can Help Enterprises Improve Risk Management and Incident Detection/Response
Network World - Networking Nuggets and Security SnippetsAccording to ESG Research, 65% use external threat intelligence (i.e. open source or commercial threat information) as part of their overall security analytics activities. This is yet another factor driving the intersection of big data and security analytics.
Of those enterprises that consume commercial threat intelligence, 29% say that it is “highly effective” in helping their organization address...
- 1
Bank trojan targets users of Bitcoin exchange Mt Gox
- 2
Australian Information Security Association issues blunt warning as National Cyber Security Awareness Week begins
- 3
Review: Mobile Device Management
- 4
The week in security: Aussie banks targeted as mobiles drive privacy fears
- 5
Security a key factor in LogMeIn’s Internet of Things platform
- FTOS Web Applications DeveloperNSW
- FTTest EngineerVIC
- FTR&D EngineerSA
- FTSenior Python DeveloperNSW
- FTSenior Python Web Applications DeveloperNSW
- FTQuality ManagerSA
- FTSenior Python DeveloperNSW
- FTJob Title: Mac Systems/ Enterprise Systems EngineerNZ
- FT.NET - Sitecore Developer - Melbourne - PermNSW
- FTLead Software EngineerSA
- FTTest Analyst (MS Environment) .netNSW
- FTFlash / ActionScript Developer - ContractNSW
- FTTest Analyst (MS Environment) .netNSW
Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).
- Have an incident response plan.
- Pre-define your incident response team
- Define your approach: watch and learn or contain and recover.
- Pre-distribute call cards.
- Forensic and incident response data capture.
- Get your users on-side.
- Know how to report crimes and engage law enforcement.
- Practice makes perfect.
Warning: Tips for secure mobile holiday shopping
I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.













