General Security
End user security requires layers of tools and training as employees use more devices and apps

A posting from Dark Reading in there Endpoint security section: When Meritrust Credit Union wanted to improve its endpoint security to comply with financial regulations, information security officer Brian Meyer needed to go beyond antivirus. The commonly used endpoint security typically doesn't provide a way of tracking whether employees' devices -- the laptops, tablets and […]

Read more
General Security
LinkedIn flips the two-factor authentication switch

A posting from Naked Security on LinkedIn authentication:  Happy anniversary of getting the bejeezus hacked out of you, LinkedIn! Maybe the timing is just a coincidence, but the career-toned social networking site got savagely hacked on 5 June 2012. Cybercrooks stole about 6.5 million passwords, over 60% of which were cracked within the span of […]

Read more
Vulnerability
Not good enough, Oracle - promises to secure Java are too little, too late

An interesting article from Naked security: Oracle has promised to work harder to make Java more secure. Given the constant flood of high-profile, heavily-exploited vulnerabilities, are Oracle's new ideas going to be enough to save this piece of software from drowning in bad vibes? In a lengthy blog post last week, the head of Java […]

Read more
General Security
Social Engineering: Tips to Protecting Yourself

In the world of information security, ‘social engineering’ is a term that describes a non-technical way of hacking that relies on the hacker to collect information to bypass normal security controls. It is the art of manipulating users into performing actions or divulging confidential information.

Read more
General Security
GovSec - The SecurityOrb Show: Interview with Curtis KS Levinson about GovSec

GovSec - The SecurityOrb Show: Interview with Curtis KS Levinson about GovSec

Read more
Hack
APT Attacks Trace To India, Researcher Says

A posting from information week on APT Attacks : A multi-year advanced persistent threat (APT) campaign that targeted the government of Pakistan, as well as global businesses operating in mining, automotive, engineering, military and finance sectors, among others, appears to have been run from India. Organizations targeted for industrial espionage were located in numerous countries, including the United […]

Read more
Vulnerability Assessment
3 Lessons From Layered Defense's Missed Attacks

a posting from Dark Reading in there  Vulnerability Management section: Layering security measures typically protects systems better: Research) by three University of Michigan graduate students in 2008, for example, found that using multiple antivirus engines result in much better protection than using a single program. Yet, recent analysis by NSS Labs highlights that layering security devices rarely catches all […]

Read more
Vulnerability & Threat Report
Gathering More Security Data From Your Endpoints

A posting from Dark Reading in there  Endpoint Security section: Even though many of the most troublesome and advanced threats hitting enterprise networks originate from the endpoint, most organizations today aren't investing in the same kind of visibility and control over these devices as they spend on network-based controls. This disparity is leaving organizations with […]

Read more
General Security
Anatomy of a change - Google announces it will double its SSL key sizes

A posting from Naked Security on Google announces it will double its SSL key sizes: Google just announced that its HTTPS web pages will be ditching 1024-bit RSA keys in favour of 2048 bits. "Pah," I hear you say. "I have one or two questions about that - three questions, in fact." How is this newsworthy when many […]

Read more
Privacy
Phishers try flattery with Facebook Page owners

An interesting article in Naked Security on Phishers try flattery with Facebook Page owners: Beware, fanboys and fangirls: phishers are targeting Facebook Page owners with a bogus message supposedly sent from Facebook Security. According to Hoax-Slayer, the scam claims that Facebook is rolling out a new security feature to protect Page owners. This supposed new security feature is dubbed the "Fan […]

Read more