Friday, August 11, 2006

Microsoft braces for worm attack / Symantec slams locked Windows kernel

Windows defense handcuffs good guys
Microsoft's PatchGuard is frustrating security companies, because the feature prevents them from fully protecting the system. - CNET News.com
Related of interest:
Symantec slams Vista's locked kernel - NewsFactor

Microsoft security - no more second chances?
Perspective on the U.S. Department of Homeland Security's warning about the risk from a patched flaw in Windows. - CNET News.com

With exploits out, Microsoft braces for worm attack
Microsoft is bracing itself for the worst after exploit code for the MS06-040 update has been released. - eWEEK
Related of interest:
Experts ratchet up Windows worm warnings - InformationWeek
To patch or not to patch? - Internetnews.com
Windows worm warnings no joke - InternetWeek.com
Microsoft Patch Tuesday exploit surfaces - NewsFactor

Officials probe Lieberman site crash
Authorities will now investigate, why U.S. senator Joe Lieberman's website went offline to establish if it was hit by a denial-of-service attack. - AP/MSNBC

Phishers flick switch, dupe Yahoo users with Flickr
A new phishing scam targeting Yahoo users uses the company's Flickr service as bait. - TechWeb

Ruby on Rails derailed by URL glitch
Users of Ruby on Rails are being urged to update after a security flaw has been discovered. - The Register

Thursday, August 10, 2006

Exploits for feared Windows flaw / Vista's core vulnerable / HSBC downplays online risk

HSBC to 'review' online security
The HSBC bank will now take its online security under review after security researchers may have found a loophole. - BBC News
Related of interest:
HSBC denies online accounts vulnerability - Computer Weekly
How serious is HSBC's online banking flaw? - Silicon.com

Utah man charged with intercepting employer email
A former employee faces up to 15 years in prison for accessing the emails of his former employer. - CIO Magazine

Microsoft patch prompts DHS warning
The U.S. Department of Homeland Security has issued a warning to urge users to install the latest patches from Microsoft, as the first exploits surface. - CIO Magazine
Related of interest:
Worm fears raised after release of Windows malware - InfoWorld

Rails users urged to fix flaw immediately
A serious flaw in Ruby on Rails means that users should update their software as soon as possible. - CNET News.com

Symantec picks away at Vista's core
Security firm Symantec has released a new report on its investigation of Windows Vista, where it has found more vulnerabilities. - CNET News.com
Related of interest:
Symantec spots Vista weaknesses - Computerworld
Vista's fortified kernel could trouble third-party apps - eWEEK
Symantec report IDs holes in Vista kernel security - eWEEK

Users still not wiping data from unwanted PCs
One fifth of second hand PCs still contains personal data, british study finds. - Computer Weekly
Related of interest:
Critical data found on second-hand hard drives - SC Magazine UK/US

Apple issues two security fixes for Mac Pro
Apple has released two security related fixes for its brand new Mac Pro desktop workstations, revealed earlier this week. - eWEEK

IRS employees abusing email privileges
The Inspector General of the U.S. Internal Revenue Service found abuse of the departments email systems on more than half of inspected PCs. - Federal Computer Week

VA to analyze breached data
The U.S. Department of Veterans Affairs has hired a contractor to determine if the data on the laptop stolen in May has been accessed. - Government Computer News
Related of interest:
Top Dem blasts latest VA data loss - Internetnews.com
Gov't promises veterans credit protection - AP/MSNBC

Deadline for agencies to secure remote data comes - and goes
The deadline has now passed for U.S. government agencies to encrypt all remote data, but many still lack policies to make use of the encryption. - InformationWeek

Researcher: Hacker sophistication outpacing forensics
Security expert Kevin Mandia believes that hacker tools are becoming more sophisticated faster that forensic tools can keep up. - InformationWeek

Google to keep storing search requests
Google intends to keep storing users' search request in spite of the recent incident, where AOL accidently made their search data public. - AP/MSNBC
Related of interest:
Will AOL goof trigger new U.S. law? - NewsFactor
Google: Gov'ts are the biggest risk to breach data - Reuters/Sydney Morning Herald

All-in-one security devices face challenges
Network security devices that integrates multiple defenses are taking a big chunk of the network bandwidth. - Network World Fusion

Lieberman's hack was no such thing
The shutdown of U.S. senator Joe Lieberman's website may have been caused by his hosting plan exeeding its limit rather than an attack. - The Inquirer

Hunting metamorphic viruses

Defcon attendees took a look at how to catch metamorphic viruses. - The Inquirer

Wednesday, August 09, 2006

Microsoft issues 9 criticals / Users urged to patch / Blackberry trojan spy

One in 10 'victim of ID crimes'
According to a survey about one in ten believe they have fallen victim to some form of identity theft. - BBC News

Hijacked handheld turns data spy
A security expert has created a game with a hidden trojan to demonstrate how the Blackberry device can be used to attack a corporate network. - BBC News
Related of interest:
Security pest found on BlackBerry - CNET News.com
Blackberry exploit code poses threat to corporates - Computer Weekly
Trojan malware takes a bit out of Blackberry - Computerworld
Purported Blackberry hack overstated, RIM says - CRN/TechWeb

Homeland Security: Fix your Windows
The U.S. Department of Homeland Security has issued a warning, urging users to install Microsoft's update MS06-040 as soon as possible. - CNET News.com

Another hefty patch month for Microsoft
Microsoft has released 12 updates this month for Windows and Office, 9 of which are considered 'critical'. - CNET News.com
Related of interest:
Microsoft releases 12 security patches, nine critical - Computerworld
Microsoft fixes a dozen security flaws - eWEEK
Microsoft fixes 23 flaws, including bug with MSBlast potential - InformationWeek
Microsoft patches newest 'dirty dozen' - Internetnews.com
Microsoft fixes PowerPoint, Windows flaws - Network World Fusion
IT pros burn the midnight oil - SC Magazine UK/US
Security firms urge Microsoft users to patch up - Vnunet.com

New phishing trojan disguises illicit activity
A new trojan hides its communication in the ICMP traffic to avoid detection. - Computer Weekly

Can you rely on Microsoft's Network Access Protection?
Microsoft will with Windows Vista ship the company's Network Access Protection technology that it touts as a great security enhancement. - Computerworld

Could your keyboard spy on you?
Researchers have designed a new form of hardware keylogger, dubbed 'JitterBug', that can send back information using covert network channels. - Computerworld

IG: Weak spots still hamper DHS info security
The U.S. Department of Homeland Security still has significant information security weaknesses, according to the Inspector General. - Government Computer News

Hacking the dead cow
The notorious hacker group Cult of the Dead Cow has released its own search engine for analysing malware. - Internetnews.com

Lieberman camp accuses opponents of hacking campaign site
U.S. senator Joe Lieberman's campaign manager accuses the opponents of hacking the senator's campaign website. - SC Magazine UK/US

Psst! Secret JFK documents for sale
A new advance fee scam has emerged, as an email from a person, who claims to be a dying KGB agent who knows the truth about the assassination of John F. Kennedy. - Sydney Morning Herald

Security at your fingertips
The security and convenience advantages of biometric security could mean that it will replace creditcards and keys soon, company hopes. - Sydney Morning Herald

E-crims slipping through the net
Flaws in Australian police's protocols means that many IT related crimes are not reported. - Sydney Morning Herald

Microsoft defends IE7's RSS security
Microsoft defends the built-in RSS feed reader in Internet Explorer 7 by saying that the browser has a number of security features to protect from bad feeds. - TechWeb

Transportation Department laptop stolen

The U.S. Department of Transportation has lost a laptop that holds personal information on about 133,000 Florida residents. - Washington Post

Tuesday, August 08, 2006

VA lose data on 38,000 / Consumers lose to spyware / Trojan hijacks ICMP

Another PC with veterans' information is missing
The U.S. Department of Veterans Affairs have lost another PC containing data on 36,000 military veterans. - CIO Magazine
Related of interest:
VA: Data for 38,000 veterans missing - AP/CNN.com
Another VA computer missing - Computerworld
Antoher VA computer goes missing - eWEEK
VA releases details of missing computer - Federal Computer Week
Computer stolen from VA subcontractor, Unisys - Government Computer News

AOL says privacy breach was a mistake
Internet service provider AOL apologizes for the accidental release of search data concerning about 650,000 users. - AP/CNN.com
Related of interest:
AOL removes search data - The New York Times

Researchers warn of serious Blackberry vulnerability
Organizations with Blackberry communications servers installed behind their gateway could be at risk, when exploit code is released later this month. - eWEEK

Security risk: Weekend

Security firm Kaspersky Lab found that it was impossible to reach investigators and credit card firms to report fraud on a weekend. - Heise online

Survey: Consumers lose to online schemes
A study by Consumer Reports finds that American consumers lost $8 billion to spyware, phishing, and viruses last year. - Los Angeles Times
Related of interest:
Viruses, spyware cost users $7,8bn - Washington Post

Lieberman campaign site, email hacked
U.S. senator Joe Lieberman has found his website defaced by hackers on the same day as the senator campaigns for reelection. - MSNBC

Trojan data-stealer hijacks ICMP traffic
A new trojan attempts to hide by sending information using ICMP back to its controllers. - Network World Fusion
Related of interest:
Phishing trojan plays ping-ping with captured data - The Register

Database security 'IT's biggest problem'
Breaches of database security is happening because of a large number of attacks that are just not noticed, security expert warns. - SC Magazine UK/US

Consumers say securty affects brand trust
Surveys seem to confirm that security can affect corporate brands. - SC Magazine UK/US

Brits beef up internet security
A British study shows that almost 90 percent of Brits are protecting their computer with antivirus, anti-spyware, and firewalls. - Silicon.com

High bidders with low motives
Organized crime is buying up exploits for security vulnerabilities and are willing to pay more than security companies offer, experts fear. - Sydney Morning Herald

IM attacks on the rise
Security firm warns that is has reported a steep increase in the use of instant messaging as an attack vector. - TechWeb

'Jitterbug' spies threaten IT security
Physical wiretapping of input from peripheral devices such as keyboards is easy to install and hard to detect. - Vnunet.com

JFK assassination spam scam exposed

In a new 419 advance fee scam, the sender poses as a dying KGB agent offering the truth about the assassination of U.S. president John F. Kennedy. - Vnunet.com

Monday, August 07, 2006

VA suffers new breach, arrests made / AOL search data out / E-passports hacked

Google warns on 'unsafe' websites
Google's search engine will now display a warning to users if they click on a search result that links to a potentially harmful website. - BBC News
Related of interest:
New Google warnings protect Internet users - NewsFactor

AOL releases data on web searches
U.S. internet service provider AOL appears to have released data about three months of users' searches, raising privacy concerns. - CIO Magazine
Related of interest:
AOL apologizes for release of user search data - CNET News.com
AOL exposes search data on 658,000 people - TechWeb

Teens arrested in VA laptop theft
Two 19-year olds have been arrested in relation to the theft of the laptop containing information about 25 million U.S. veterans. - CNET News.com
Related of interest:
Another theft leaves VA data exposed - Federal Computer Week
Arrests in VA laptop case please congressman - Federal Computer Week
Maryland police arrest pair in theft of VA laptop - Computerworld
Two men charged with theft of VA laptop - eWEEK
VA suffers another data breach - Government Computer News
Teens charged in VA laptop theft - Internetnews.com
2 teens arrested in theft of VA laptop - AP/MSNBC
2 Md. men arrested in theft of VA laptop - Washington Post

Researchers: E-passports pose security risk
A demonstration at the Black Hat security conference proved that it is easy to copy the information found on new e-passports with RFID chips. - CNET News.com
Related of interest:
Digital passports can be cloned - Computer Weekly
Security hole seen in passport e-data - AP/Los Angeles Times
Hackers clone radio-chip passports - NewScientist
Hi-tech passports prove hackable - AFP/Sydney Morning Herald

U.K. security guru lays into database vendors
A U.K. security researcher released details about 20 vulnerabilities in IBM's Informix databases at the Black Hat conference. - Computerworld

FBI: Cybercriminals taking cues from Mafia
FBI investigators told the Defcon audience how cybercriminals are adopting the same organizational structures as organized crime. - InfoWorld

Hackers meet to exploit computer flaws
Hackers compete to find security flaws in software at this year's Defcon conference in Las Vegas. - AP/MSNBC

Microsoft works to minimize risk with Vista
With new security features in Windows Vista over previous versions of Windows, Microsoft aims to improve security. - NewsFactor

Nigerian email scam-master arrested
Nigerian police have arrested a man suspected to be the ringleader of a large email scam. - SC Magazine UK/US

Global cyber-crime treaty gets Senate nod
The U.S. Senate has ratified the European Council's international anti-cybercrime treaty. - Silicon.com