Friday, June 19, 2009

Around Then Horn vol.1,123

Microsoft announces free antivirus, limited public beta

By emil.protalinski@arstechnica.com (Emil Protalinski) on Microsoft Security Essentials

Microsoft today officially announced Microsoft Security Essentials (MSE), its free, real-time consumer antimalware solution for fighting viruses, spyware, rootkits, and trojans. Currently being tested by Microsoft employees and a select few testers, MSE is Microsoft's latest offering intended to help users fight the threats that plague Windows PCs.

Microsoft notes that the threat ecosystem has expanded to include rogue security software, auto-run malware, fake or pirated software and content, as well as banking malware, and the company is aiming to help the users who are not well protected. A beta of MSE will be available in English and Brazilian Portuguese for public download at microsoft.com/security_essentials on June 23, 2009 for the first 75,000 users. This is a target number, but Microsoft is willing to increase it if necessary.

Click here to read the rest of this article

That e-mail attachment is not a Twitter invite

By Elinor Mills

Twitter invites have a URL in the e-mail and not an attachment like this worm attack does, Symantec says.

Symantec is warning about a mass-mailing worm that comes in an attachment pretending to be a Twitter invite.

"The observed messages appear as if they have been sent from ...

Microsoft's free anti-malware beta to arrive next week

By Elinor Mills

Updated at 2:40 p.m. PDT with comment on what happens if a user already has antivirus software installed and at 1:45 p.m. with AVG comment.

Microsoft will launch a public beta of its anti-malware service, Microsoft Security Essentials, on Tuesday as it phases out its Live ...

Apple: iPhone OS 3.0 plugs 46 security bugs

By David Martin

Apple has issued an advisory regarding security enhancements included in the iPhone OS 3.0 release Wednesday.

Here is a synopsis of the 46 iPhone security vulnerabilities addressed by the latest operating-system update for the iPhone and iPod Touch. As may be expected, many of these security patches ...

Originally posted at iPhone Atlas

Oracle Users Struggle With Patch Management

Oracle users still slow to deploy security patches despite new tools

Microsoft To Launch Free Antivirus Product Next Week

Public beta of the much-anticipated "Morro" tool debuts June 23, replacing OneCare Live for consumers

Hactivist DDoS Attacks In Iran Trigger Worries Of Wider Internet Crackdown

Experts warn that distributed denial-of-service (DDoS) attacks could backfire

New Injection Attack Compromises More Than 40,000 Websites

New injection attack may have compromised more than 40,000 Websites, researchers say

Mass Injectors Still Burying the Needle

In Vulnerability Research

The use of mass injection redirection campaigns like the Gumblar is only just getting started, researchers contend.

Cybersecurity training: The battle over mandates

A debate rages over a Senate proposal to require certification or licensing for all cybersecurity professionals who work on government information systems.

How DOD's certification program works

DOD published a manual describing various job categories, including technical and management positions, and the different certifications that meet the training requirement. Here are a few examples.

The new cybersecurity licensing proposal

Here's how a Senate proposal to require certification or even licensing for cybersecurity professionals would work.

Cloud computing: Is it secure enough?

Government officials should start now to understand the security implications and begin taking steps to protect their organizations as they adopt the cloud computing model.

Navy aggressive in protecting networks from enemies

As commander of the Naval Network Warfare Command, Vice Adm. H. Denby Starling leads a 14,000-strong cyber force deployed worldwide to protect Navy information networks.

Deepwater watch: Coast Guard Acquisition Directorate gets new leader

The Coast Guard Acquisition Directorate has a new rear admiral in charge — Ronald Rábago.

Cybersecurity: Legislation, new security controls on same track

New catalog of information and security controls co-developed by NIST, the Pentagon and the intelligence community, along with information security legislation gaining traction in Congress, are expected to significantly improve federal cybersecurity standards.

Google's Anti-Malvertising.com Fights Off Bad Ads

The site was created because Google has a significant interest in making sure that ad blocking doesn't become a standard security practice.

Microsoft Security Essentials Beta Coming Tuesday

Previously code-named "Morro," the free software will replace Windows Live OneCare, which included both security and utility services for $49.95 per year.

Microsoft Security Essentials Beta Coming Tuesday

Previously code-named "Morro," the free software will replace Windows Live OneCare, which included both security and utility services for $49.95 per year.

Apple iPhone, iPod Security Flaws Get 45 Patches

Software patches were bundled with Apple's iPhone 3.0 operating system released Wednesday.

iPhone Gets Enterprise IT Boost From Startup Apperian

Apple's lack of interest in being a major player in enterprise IT has opened the door for Apperian to work with large corporations to develop applications for the iPhone.

MasterCard beefs up security requirements

In a move that is unlikely to sit well with many merchants, MasterCard has quietly changed a key security requirement for all businesses handling between 1 million and 6 million card transactions annually.

Fight against China's Web filtering software grows

A U.S. company that says its code was copied by a Chinese Internet filtering program has ordered more PC makers not to distribute the Chinese software.

Apple delivers prodigious patch batch for iPhone

Apple on Wednesday patched 46 security vulnerabilities, half of them in the Safari browser and its WebKit rendering engine, for the iPhone and iPod Touch as it released iPhone OS 3.0.

Worm-bearing Twitter spam on the loose

Twitter spam bearing a worm virus is on the loose today trying to lure Twitter users into opening a malicious file attachment containing malware that could take over Windows-based machines, Symantec is warning.

Microsoft to deliver free antimalware next Tuesday

Microsoft will release a public beta of its free antimalware software, now called Microsoft Security Essentials, formerly "Morro," next Tuesday for Windows XP, Vista and Windows 7.

Spammers cashing in on Twitter, Iran, new iPhone

Spammers are never far from a hot story, it seems, and in the past day they've been flooding Twitter with phoney messages about Iran and the latest iPhone 3.0 operating system.

India bans import of mobile phones without identity codes

The Indian government has banned the import of mobile phones without an IMEI (International Mobile Equipment Identity) number, and has ordered operators to block calls from phones without an IMEI from next month..

GhostNet cyber espionage probe still has loose ends

Nearly three months after a report detailed an extensive, worldwide cyber espionage operation, many countries that were hacked may not have been formally notified yet.

Barclays online and ATM crash after disc array fault

A disc array fault left thousands of Barclays customers unable to access their bank accounts online or withdraw money from cash machines in the south of England for three hours yesterday.

EU progressing on information infrastructure policy

The European Union is refining a set of guidelines that would strengthen its ability to respond to computer security crises as well as ensure Internet infrastructure in member countries is more resilient.

Google agrees to delete unblurred German Street View data

Google has agreed to delete some of the original, unblurred photographs captured by its German Street View service, ceding to demands by Hamburg's Data Protection Office.

Cyberdefense center will lead in education

The Cooperative Cyber Defense Center of Excellence (CCDCOE) opened in May 2008 in Tallinn, Estonia, to assist NATO with technical, legal and policy issues associated with dealing with cyberwarfare incidents. The 20-person center includes civilian analyst Kenneth Geers, who works for the U.S. Navy's Naval Criminal Investigative Services. Geers, who has been with the center for about a year and a half, spoke about CCDCOE's mission on the opening day of the organization's first-ever Conference on Cyber Warfare on Wednesday.

Blogger: Windows 7 UAC feature still vulnerable

The Microsoft blogger who first called attention to a security vulnerability in Windows 7's User Account Control (UAC) feature claims it still exists and that Microsoft won't fix it, even as the company nears final code completion on the OS.

Buy an Infected PC for 5 cents

It doesn't take much to get started in Internet crime these days. Find the right site, hand over $50, and you can start wreaking havoc with 1,000 already-infected PCs.

Canadian bill forces personal data from ISPs sans warrant
Requires police intercept hardware

Canada is considering legislation allowing the country's police and national security agency to readily access the online communications and the personal information of ISP subscribers.…

January's Windows 7 hole still open
Sort it out, Redmond

A security hole in Windows 7, highlighted by a blogger back in January, is still wide open and Microsoft is showing very little interest in closing it.…

Incident Handlers Guide to SQL Injection Worms

Category: Incident Handling

Paper Added: June 18, 2009

Building an Automated Behavioral Malware Analysis Environment using Open Source Software

Category: Tools

Paper Added: June 18, 2009

Apache HTTP DoS tool released, (Thu, Jun 18th)

Yesterday an interesting HTTP DoS tool has been released. The tool performs a Denial of Service atta ...(more)...

Security researchers develop browser-based darknet

By Robert Westervelt

Called Veiled, the darknet only requires participants to use an HTML 5-based browser to connect and share data anonymously.

Database monitoring, encryption vital in tight economy, Forrester says

By Erin Kelly

A new report from Forrester Research Inc. examines eight database and server data security technologies and recommends small steps that can make a big difference.

Virtual appliances boost flexibility, improve security

By Eric Ogren

Companies see the benefits of placing network-oriented security on a faster processor.

Botnet platform helps cybercriminals bid for zombie PCs

By Robert Westervelt

Infected PCs are sold again and again on a new platform that enables cybercriminals to buy and sell victim's machines.

FRISK Fprot Generic Bypass Using TAR Files

Clam AntiVIrus Generic Bypass Using RAR CAB or ZIP Files

CA Service Desk Tomcat Cross Site Scripting Vulnerability

Apple Java CColorUIResource Pointer Derference Code Execution Vulnerability

User interaction is required to exploit this vulnerability in that the target must visit a malicious page.

CA ARCserve Backup Message Engine Denial of Service Vulnerabilities

Microsoft Preps Security Essentials Beta

Microsoft announces that the beta version of Microsoft Security Essentials, code-named Morro, will be available for download starting June 23. The free product represents Microsoft's latest swing at the consumer security market, which is dominated by vendors such as Symantec and McAfee.
- Say hello to Microsoft Security Essentials. Microsoft plans to let the newborn brother of its Windows Live OneCare product come out to play next week. Starting June 23, Microsoft will make a beta version of Security Essentials code-named Morro available for download. The offering is slated for...

Why Enterprises Shouldn't Limit Web Traffic

NEWS ANALYSIS: The business world is deathly afraid of allowing workers to access any site on the Web. A new attack called Nine-Ball, which targets legitimate sites and then redirects users to malicious sites, is just the last security issue that keeps IT administrators up at night. But in the long run, blocking employee access to Websites might be a mistake.
- It's become commonplace in the business world to limit employee Web traffic. At many firms, regardless of their industry or size, IT managers are being asked to block access to some sites and in some cases, limit the amount of time users spend on the Web. By doing so, they can limit the impact m...

iPhone 3.0 Includes 46 Security Updates

In New Patches

Apple on Wednesday released the much anticipated 3.0 update for the iPhone, bundling at least 46 security fixes into a new version of the iPhone operating system that includes essential functionality such as cut-and-paste and Spotlight search. Included in the 3.0 bundle are security patches for vulnerabilities in a broad range of iPhone components, including Safari and Mail. The mail flaw, for example, could allow a malicious app or attacker to place a phone call without user interaction. A host of other security holes fixed by this update could allow a remote attacker or Web site to run malicious code on the device or cause it to crash. The update is available only through iTunes. My colleague Rob Pegoraro has a more in-depth post about the new features built into this update, but he was having trouble grabbing the update yesterday. Apple says that the automatic update process may take

Microsoft to provide free anti-virus software (AFP)

In technology

AFP - Microsoft has announced it will soon release free anti-virus software so people on tight budgets won't skimp on protecting their computers from hackers.

Microsoft readies free PC security software (AP)

In technology

AP - Microsoft Corp. said Thursday it plans to release a beta test of its free computer security program next week and is on track to launch a finished product in the fall.

Spammers Cashing in on Twitter, Iran, New IPhone (PC World)

In technology

PC World - Spammers are never far from a hot story, it seems, and in the past day they've been flooding Twitter with phoney messages about Iran and the latest iPhone 3.0 operating system.

Microsoft readies free PC security software (AP)

In technology

AP - Microsoft Corp. plans to release a test version of its free computer security program Tuesday.

Microsoft takes on Symantec, McAfee in security (Reuters)

In technology

Reuters - Software giant Microsoft Corp is launching a free PC security service next week in what could be the biggest challenge to date for anti-virus companies with billions of dollars in annual revenue.

Canada proposes new powers to police Internet (AFP)

In technology

AFP - The Canadian government on Thursday unveiled new legislation to allow police to intercept data sent over the Internet and access web subscriber information in order to fight cybercrimes.

EU Progressing on Information Infrastructure Policy (PC World)

In technology

PC World - The European Union is refining a set of guidelines that would strengthen its ability to respond to computer security crises as well as ensure Internet infrastructure in member countries is more resilient.

The Möbius Defense, the end of Defense in Depth

Our new partner in the Netherlands, Lab106 (aka Outpost24), invited me out to present some our research at the Amsterdam Black Hats event.

I focused the main presentation on Anti-Guerrilla Warfare tactics, why defense in depth doesn't work, and the new Möbius Defense along with…

Google News Alert for: "cyber security" | cybersecurity | information security | computer security

Smart Grid Security Frenzy: Cyber War Games, Worms and Spies, Oh My!
Reuters - USA
According to executives at computer security firm IOActive: Studies show that overall project costs are 60 times higher when gaps in information security ...
See all stories on this topic

 

Designated immigration agents authorized to participate in drug ...
Los Angeles Times - CA,USA
By Josh Meyer Reporting from Washington -- In an effort to plug a hole in US-Mexico drug enforcement, the US departments of Justice and Homeland Security ...
See all stories on this topic

The Associated Press

Somali security minister killed in explosion
The Associated Press
Information Minister Farhan Ali Mohamud announced the death of National Security Minister Omar Hashi Aden but declined to give any other details. ...
See all stories on this topic

 

Cybersecurity To Push For Standard For Info Security Products
Bernama - Kuala Lumpur,Malaysia
KUALA LUMPUR, June 19 (Bernama) -- CyberSecurity Malaysia, the country's vanguard of cyber security, is pushing for the Common Criteria for information ...
See all stories on this topic

 

EU Progressing on Information Infrastructure Policy
PC World - USA
The European Union is refining a set of guidelines that would strengthen its ability to respond to computer security crises as well as ensure Internet ...
See all stories on this topic

 

China Disables Some Google Functions
New York Times - United States
But on Friday, J. Alex Halderman, a computer science professor at the University of Michigan, said that a patched version of Green Dam had a security ...
See all stories on this topic

 

Will PCI Ever Make the Grade?
TechNewsWorld - Sherman Oaks,CA,USA
Even the companies that had the payment industry's top rating for computer security, a seal of approval known as "PCI compliance," have fallen victim to ...
See all stories on this topic

CNET News

Apple: iphone OS 3.0 plugs 46 security bugs
CNET News - San Francisco,CA,USA
by David Martin Apple has issued an advisory regarding security enhancements included in the iphone OS 3.0 release Wednesday. Here is a synopsis of the 46 ...
See all stories on this topic

Google Blogs Alert for: "cyber security" | cybersecurity | information security | computer security

 

Smart Grid Security Frenzy: Cyber War Games, Worms and Spies, Oh My!
By Katie Fehrenbacher
(NERC) said it has made progress on some “milestones” (more like incremental steps) for smart grid security. NERC says its Board of Trustees has approved the first revisions of its eight cyber security standards, and is working on a second ... According to executives at computer security firm IOActive: Studies show that overall project costs are 60 times higher when gaps in information security controls are addressed late in the development cycle, as opposed to projects ...
Earth2Tech - http://earth2tech.com/

 

Sonos 130 Music System: Review
By home security
It is beautiful, loud and completely wireless! Is this bundle from Sonos the ultimate system for streaming music throughout the home? Megawhat investigates.
Home Security Systems | Home... - http://www.homesecuritysystemstips.com/

 

Social Security Reform - Government Improvement Series
By MoneyNing
Without factual information, how can we plan for retirement? And if we have to assume we won't get any Social Security benefits in our planning, what's the point of having that extra check? Forget the bailouts. Work on Social Security. ...
Personal Finance Blog by Money Ning - http://moneyning.com/

 

Norway's government caught spying on itself | IceNews - Daily News
By A. Rienstra
The Security Service's role is to monitor all data security within the Defence Forces, as well as the information that comes out of the Prime Minister's office to ensure that no sensitive information gets into the wrong hands. ...
IceNews - Daily News - http://www.icenews.is/

 

Microsoft Security Essentials Premiering June 23rd ~ Revelations ...
By the oracle
Noted in ComputerWorld today, the beta of Microsoft Security Essentials will be made available on June 23. The details are being fleshed out now that the wraps are off the project. Security Essentials will completely replace the ... calls “ Dynamic Signature Service,” a back-and-forth communications link between a Security Essentials-equipped PC and Microsoft's servers. Mary-Jo Foley, long time Microsoft watcher on ZDNet, has some more information to add to the story - ...
Revelations From An Unwashed Brain - http://www.lockergnome.com/theoracle/

No comments:

Post a Comment

My Blog List