Cybersecurity Receives Emphasis in State of the Union Address

/
An interesting article by Mickey McCarter of Homeland Security…

ShmooCon Begins with LobbyCon

/
ShmooCon officially kicks off today Friday January 27, 2012, but yesterday was LobbyCon at the Hilton Hotel at 1919 Connecticut Ave, NW in Washington, DC. The Lobby became a mini conference where conversations, newly forged relationships and ideas were shared in every corner of the hallways by attendees of ShmooCon and those who simply show up to be part of the action without paying to participate and fellowship. Someone stated, LobbyCons are were we come up with ideas, the deals are made, the projects are talked about and the real learning is done. After an hour LobbyConning, I would have to agree.

Counter Terror Expo US Forms Advisory Board to Expand Community Reach and Involvement

/
The Counter Terror Expo US , being held May 16-17, 2012 at the Walter E. Washington Convention Center , has formed an advisory board of industry experts from leading organizations to help guide and shape the educational programming and conference content. The advisory board includes individuals from government, academia, law enforcement, media, and the private sector with knowledge ranging from cyber security to border and critical infrastructure protection.

New Variant of Zeus Malware Titled “GameOver” Sent via Phishing Scam

/
The FBI has issued a warning about the latest identify theft/bank swindling malware, called “Gameover”. The “Gameover” scam is initiated through a phishing scheme that sends fictitious e-mails to a bunch of users from the National Automated Clearing House Association (NACHA), the Federal Reserve Bank, or the Federal Deposit Insurance Corporation (FDIC). After opening the email and selecting the hyperlink, the user is forwarded to a phony website that automatically installs the Trojan without their knowledge or assistance, then eventual access to the victim’s bank account becomes accessible to the scammer.

Google Releases Chrome 16.0.912.77

/
US-Cert has just distributed a notification about the release of Chrome 16.0.912.77 for Linux, Mac, Windows, and Chrome Frame to address multiple vulnerabilities. The vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

Email scam could clear out your bank account

/
The FBI even put out a warning to let people know what to watch out for. This recent scam doesn't surprise me at all. It only takes these scanners to get .05% of people on email for it to be worth their time. And think how much easier it is today. I mean, I hardly ever go into a bank anymore. With online banking I can do almost everything, from checking my balance, transferring funds to paying my bills. And with hot new apps from banks like Chase, PNC and USAA I can even scan my checks with my phone and deposit them straight into my account.

Vulnerability Summary for the Week of January 16, 2012

/
This bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) the week of January 16, 2012. It is available here:

Congress withdraws SOPA and PIPA

/
Lawmakers on Friday indefinitely postponed anti-piracy legislation that pits Hollywood against Silicon Valley, two days after major Internet companies staged an online protest by blacking out parts of prominent websites. Senate Democratic leader Harry Reid postponed a showdown vote in his chamber on the Protect Intellectual Property Act, or PIPA for short, that had been scheduled for January 24.

Carberp Malware is Back in a New Form to Target Facebook users

/
"Carberp replaces any Facebook page the user navigates to with a fake page notifying the victim that his/her Facebook account is 'temporarily locked,'" says Trusteer CTO Amit Klein in his blog. "The page asks the user for their first name, last name, email, date of birth, password and a Ukash 20 euro [approximately $25 US] voucher number to 'confirm verification' of their identity and unlock the account.

Upcoming SANS 2012 (Orlando) Information Security Training Event

/
SANS 2012 (March 23-30, 2012) is fast approaching! More than 35 courses are offered, all taught by our top-rated instructors who are the best at ensuring you learn the material and can apply it immediately when you return to your office. Choose from audit, IT legal, security management, software and web app developer, forensics, computer security training, and more.