Search

Search results below

Saturday, June 28, 2008

Beijing.Exe Storm Outbreak

A new spam outbreak attributed to the Storm Botnet has been hitting the Internet since Jun 18, 2008. The message warns of earthquakes hitting well known sites around the world causing significant destruction and loss of life and is being distributed from IP addresses hosted around the world. This site claims a quake measured in at 9.0 on the Richter scale has caused casualties and threatens the preparations for the upcoming Olympics hosted in China. The page contains links to a supposed video that actually downloads the Storm worm

Click below to read:
http://www.trustedsource.org/blog/125/BeijingExe-Storm-Outbreak

Former White House Advisor: Hackers Didn't Cause 2003 Blackout

Cyber security consultant Paul Kurtz threw some cold water this week on a report that Chinese hackers caused the massive 2003 northeastern U.S. blackout. He worked for the White House at the time of the outage.

Click below to read:

http://blog.wired.com/27bstroke6/2008/06/former-white-ho.html

Wards didn't tell consumers about credit card hack

An old name in retail was hit by a modern scourge - a hack of its customers' credit card numbers - but didn't inform the consumers, revealing how data breaches might be heavily undercounted even with new notification laws.

At least 51,000 records were exposed in the breach at the parent company of Montgomery Ward. The venerable Wards chain that began in 1872 went out of business in 2001, but in 2004 a catalog company, Direct Marketing Services Inc., bought the brand name out of bankruptcy. It now runs a Wards.com Web site along with six other sites, including three with Sears brands it has acquired: SearsHomeCenter.com, SearsShowplace.com and SearsRoomforKids.com.

Click below to read more:

http://apnews.myway.com//article/20080627/D91II9U82.html

Researchers Reveal Security Holes in Internet Explorer

Two security issues, one in Internet Explorer 7 and the other in Internet Explorer 6, could leave users open to attack.

Click on link to read more:

http://www.eweek.com/c/a/Security/Researchers-Reveal-Security-Holes-in-Internet-Explorer/

Friday, June 27, 2008

Antispam group outlines defenses to block botnet spam

A major antispam organization is pushing a set of new best practices for ISPs (Internet service providers) to stop increasing volumes of spam from botnets.

Click the link to readhttp://www.networkworld.com/news/2008/062608-antispam-group-outlines-defenses-to.html?Inform=nl&nlhtsec=rn_062708&nladname=062708securityal:

Cisco, IBM, Intel, Juniper and Microsoft fight cyber terror together

Five major network hardware, software and services vendors are banding together to improve IT security by promoting faster responses to threats.

click on link below to read full story:
http://www.networkworld.com/news/2008/062707-icasi-cyber-terror.html?nlhtsec=ts_062708&nladname=062708securityal

Thursday, June 26, 2008

Virgin loses data on 3000 customers

Virgin Media has disclosed that an unencrypted CD containing personal details of around 3000 customers went missing on 29 May.

Click below to read more:
http://www.heise-online.co.uk/security/Virgin-loses-data-on-3000-customers--/news/110991

Woman accused of spying for China at Motorola

A Chinese spy was caught "red-handed," according to federal authorities, as she was about to board a plane at O'Hare bound for Beijing.

Click below to watch & read:
http://abclocal.go.com/wls/story?section=news/local&id=6228552

Stakeouts, Lucky Breaks Snare Six More in Citibank ATM Heist

Citibank officials monitoring their network for fraud on Thursday, May 8, noticed suspicious ATM transactions at 8:30 p.m., coming through the five cash machines in the vestibule of a Citibank branch at 65th Street and Madison Avenue in New York City's Upper East Side.

http://blog.wired.com/27bstroke6/2008/06/fbi-arrests-six.html

Researcher slams Adobe for 'epidemic' of JavaScript bugs

Adobe fixes critical flaw in Reader, Acrobat; exploits circulating

Click below to read more:
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9102878&source=rss_topic85

HSBC scripting flaws play into the hands of phishers

Several HSBC websites are subject to scripting flaws that create a possible mechanism for crooks to create more convincing phishing scams.

Click on the link below to read more:
http://www.theregister.co.uk/2008/06/25/hsbc_scripting_flaws/

Monday, June 23, 2008

Sun launches Identity Manager 8.0

Sun has released its Identity Management software version 8.0 today. It automates processes that have been done manually in the past, including administrative activities and everyday tasks such as password management that were delegated to administrators and users. As a result, a reduction of operational costs and personnel workload can reach 80%, improving the rate of return on your investment in identity management.

Addressing security and compliance is still the largest expenditure for organizations," said Mark Herring, vice president of marketing Software Infrastructure. "Customers like GE, eBay, and Equifax are partnering with us because they know they can count on Sun for their needs.” Sun’s Identity Management Identity currently manages the identities of more than 12,000 eBay employees and contractors.

Click here to read more and know more

Symatec End point Management platform

Symantec Corp today announced the release of the new Symantec Endpoint Management Suite to define the next generation of integrated, best-of-breed systems management, endpoint security, backup and recovery.

Symantec Endpoint Management Suite secures the endpoint by providing the leading technology in all three areas of system configuration: management, security and recovery. The suite includes Symantec Endpoint Protection 11.0, Altiris Client Management Suite 6 and Backup Exec System Recovery 8 Desktop Edition.

Laptop Security

Hi,

Found this article on SANS site for Laptop security. As described in the document a Handy-dandy device with lots of information (official / personal) more valuable than the laptop itself.

People have started moving away from traditional Desktops to laptops not only in official environment but in homes also. Recommend reading this article & take the measures for securing your laptops.

Click here to read

The Best Security Books to have in your library

While i was going through the SANS articles found this write up on the best security books where the GIAC students who got above 90 were invited to the advisory board. Some books that received multiple polls were:

1. Counter Hack Reloaded: A Step-by Step Guide to Computer Attacks and Effective Defenses (2nd Edition) - Edward Skoudis and Tom Liston
2. Security Metrics: Replacing Fear, Uncertainty, and Doubt - Andrew Jacquith
3. Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks - Michal Zalewski
4. Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks - Michal Zalewski

Happy reading