Tuesday, March 3, 2009

Around The Horn vol.1,54

Alerts

-- Aurora Report says no new alerts today.

Security News

5:44 PM (4 hours ago)

New Gmail Flaw Lets Attacker Control 'Change Password' Function

from CGISecurity - Website and Application Security News by Robert A.

"A researcher today released a proof-of-concept for a vulnerability he discovered in Google Gmail that lets an attacker change a Gmail user's password, wage a denial-of-service attack on the account, or even access other Gmail users' email. The cross-site request forgery (CSRF) flaw -- which researcher Vicente Aguilera Diaz from Madrid-based...

5:44 PM (4 hours ago)

Opera 9.64 Security Updates and Enhancements

from CGISecurity - Website and Application Security News by Robert A.

From Opera's changelog Fixed an issue where specially crafted JPEG images ccould be used to execute arbitrary code, as reported by Tavis Ormandy of the Google Security Team; see our advisory Fixed an issue where plug-ins could be used to allow cross domain scripting, as reported by Adam Barth; details will...

7:51 PM (2 hours ago)

Obama releases Dubya's secret anti-terror memos

from The Register - Security

Warrantless wiretapping? Check

The Obama administration has released nine secret legal opinions penned by Bush Administration lawyers, revealing the scope of executive power the White House sought in fighting domestic terrorism.…

4:51 PM (5 hours ago)

US spy agency gains support for cyber security role

from The Register - Security

DHS not up to task, Congress told

The United States' top intelligence official argued last week that the National Security Agency should become the nation's cyber defender, adding his voice to the growing murmur of support for the agency's future role in cyberspace.…

2:51 PM (7 hours ago)

Hack-off contestant dubs Apple Safari 'easy pickins'

from The Register - Security

Pwn2Own's low-hanging fruit

Apple's Safari browser is likely to be compromised multiple times at an annual hacking contest being held later this month because it's "easy pickins as usual," a researcher specializing in Apple security says.…

12:47 PM (9 hours ago)

Oz runs Romero-themed zombie awareness week

from The Register - Security

Throw another braaaain on the barbie

Australia is running a national zombie awareness week in a bid to educate users about how to stop hackers from taking over control of their PCs.…

10:28 AM (11 hours ago)

Barclays heralds new wave of wallet-waving

from The Register - Security

Contactless tech going in cards - data-gathering to follow

Barclays Bank is to embed contactless technology into every debit card issued from this day forward, allowing punters to pay for coffee with a wave of the wallet - providing they can find somewhere that accepts the new technology.…

9:28 AM (12 hours ago)

Securing the corporation

from The Register - Security

The Alpha and Omega of risk management

In the past couple of articles we have considered why security is important and what are the threats faced, both internal and external. Most, if not all organisations will be doing something about IT security, so it isn’t going to be awfully useful to launch into a treatise on how everybody should be implementing IT security. It is perhaps worth revisiting some of the key elements of ‘security done right’, however, so we can consider what’s getting in the way.…

9:28 AM (12 hours ago)

Facebook sues 'Spamford' Wallace over spam scam

from The Register - Security

Bring in the usual suspects

Facebook has launched a lawsuit against infamous junk mail merchant Sanford "Spamford" Wallace.…

12:40 PM (9 hours ago)

Computer Security Handbook Fifth Edition is ready

from Network World on Security by M. E. Kabay

After three years of labor, the Fifth Edition of the Computer Security Handbook (CSH5) is ready! Senior Editor Sy Bosworth and new Editor Eric Whyne and I are proud to see the two-volume work for sale at last.

12:40 PM (9 hours ago)

Koobface worm to users: Be my Facebook friend

from Network World on Security by Gregg Keizer

A worm that hit Facebook last December has resurfaced, a security researcher said today, and is now hijacking user accounts -- not only for that social networking service, but also for MySpace, Friendster, LiveJournal and others.

12:40 PM (9 hours ago)

Banks, credit unions begin to sue Heartland over data breach

from Network World on Security by Jaikumar Vijayan

In an indication of the legal troubles companies can find themselves in over data breaches these days, several banks and credit unions have begun suing Heartland Payment Systems over its recently disclosed data breach.

12:40 PM (9 hours ago)

Realtors sold on software that ferrets out illicit password sharing

from Network World on Security by Ellen Messmer

Stopping illicit password use is a tough problem to solve but Ray Moore, member of the board at the Mountain Central Association of Realtors, says a little technology combined with a lot of diplomacy has made the difference in stopping unauthorized use of the association's MLS database.

12:40 PM (9 hours ago)

Russian password-cracking software discounted

from Network World on Security by Jeremy Kirk

Russian security vendor Elcomsoft is offering a 20 percent discount for law enforcement and government agencies for some of its password-cracking software.

12:40 PM (9 hours ago)

IBM looks to secure Internet banking with USB stick

from Network World on Security by Jeremy Kirk

IBM's Zurich research laboratory has developed a USB stick that the company says can ensure safe banking transactions even if a PC is riddled with malware.

12:40 PM (9 hours ago)

Cisco debuts e-mail security services

from Network World on Security by Tim Greene

Cisco is wheeling out three flavors of e-mail security services, the first of a series of hosted security services the company plans to announce.

12:40 PM (9 hours ago)

Aussie govt considers quantum leap in secure comms

from Network World on Security by Darren Pauli

Australian governments may soon have the world's most secure data communication system if trials of a locally-developed quantum cryptography technology are successful.

4:17 PM (5 hours ago)

Opera browser security updates, (Tue, Mar 3rd)

from SANS Internet Storm Center, InfoCON: green

Opera has released version 9.64 on various platforms to address security bugs ...(more)...

12:44 PM (9 hours ago)

Iranian cybercriminal shares Marine One specs on Gnutella

from Ars Technica by julian.sanchez@arstechnica.com (Julian Sanchez)

A data security company in Pennsylvania this weekend confirmed that sensitive schematics for the Sikorsky VH-60N helicopter—better known by the call sign "Marine One" when used as personal transport for the President of the United States—had been leaked over the Gnutella peer-to-peer file sharing network, and appeared to be in the possession of a probable cybercriminal in Iran.

The documents—which included the complete avionics package for the VH-60N, describing its electronic systems in detail—were first discovered floating around P2P networks last fall by analysts at Tiversa, a company that specializes in detecting P2P data leaks. The documents are believed to have originated on the network of an unnamed defense contractor based in Bethesda, MD, where an employee had installed a file-sharing client configured to share the contents of the hard drive indiscriminately.

11:07 AM (11 hours ago)

Netbooks May Offer Hackers Private Data Gateway

from Wired Top Stories by By Kelvin Soh

TAIPEI (Reuters) - Netbook web surfers beware. That low-cost netbook you're using could be a high-speed gateway into your life, bank accounts, passwords and other personal data.

Netbooks have made headlines since their 2007 launch, making PCs accessible to millions of non-traditional users. But their cheap cost could also carry a steep price tag due to lax security that makes them easier prey for viruses and hackers.

10:12 AM (12 hours ago)

Too Early to Criticize Obama's Tech Policy?

from Wired Top Stories by Nicholas Thompson

Obama's technology policy has not been as transformative as a lot of Wired readers might have hoped — at least in the first month and a half. Some great things have happened, but the velocity is lower than expected. Obama is supposed to create a wiki white house. Is it too early to take him to task?

7:54 PM (2 hours ago)

Pop Superstar Sting Supports British Pentagon Hacker, Condemns U.S.

from Wired Top Stories by Kevin Poulsen

Former Police singer calls the U.S. prosecution of admitted British hacker Gary McKinnon "a travesty of human rights" and "disproportionate in the extreme." Next week, Boy George calls the prosecutor a karma chameleon.

2:50 PM (7 hours ago)

Critical Fix for the Opera browser, New Winamp Flaw

from PC World Latest Technology News

Grab today's update of the Opera browser to fix a major security flaw, and watch out for a hole in the Winamp media player.

11:28 AM (11 hours ago)

Facebook Hit by Five Security Problems in One Week

from PC World Latest Technology News

Facebook has been the victim of five different security problems in the past week, says Trend Micro.

Other News

11:28 AM (11 hours ago)

Socialtext Collaboration Platform Gains Microblogging

from PC World Latest Technology News

Socialtext will add Twitter-like functionality to its hosted enterprise collaboration platform.

No comments:

Post a Comment

My Blog List