Hack
AP Twitter Hack: Lessons Learned

An posting from Information Week security in there security section: Would you trust an email that says: "Please read the following article, it's very important: www.washinqtonpost.com/blogs/worldviews/wp/2013/04/23/"? So went a phishing email reportedly sent to multiple employees at the Associated Press, less than an hour before the company's Twitter feed was taken over and used to issue multiple tweets, […]

Read more
Vulnerability
How Lockheed Martin Phishes Its Own

An posting From Dark Reading about How Lockheed Martin Phishes Its Own: On several occasions over the past couple of years, employees at Lockheed Martin have flagged suspicious emails that turned out to be previously unknown targeted attack campaigns aimed at the defense contractor. This additional pair of eyes in security is one of the bonuses of […]

Read more
Hack
XSS Vulnerability in Cisco sub domain found by 14 Years Old security researcher

A Cross Site Scripting Vulnerability found in Cisco sub domain newsroom.cisco.com by a 14 Year Youngest security researcher Ali Hasan Gauri, today he reported us about his Latest vulnerability he found in Cisco sub domain.

Read more
General Security
Nessus® 5.2 Vulnerability Scanner is Now Available

Tenable is pleased to announce the availability of the Nessus® 5.2 vulnerability scanner. This release provides expanded platform support and integration, enhanced analysis and reporting capabilities, and improved usability. Nessus 5.2 is available now to Nessus ProfessionalFeed®, Nessus Perimeter Service™, and Nessus HomeFeed® users at no additional cost.

Read more
Malware
Mac malware found in malformed Word documents - is China to blame?

An posting  from  Naked security about Mac malware found in malformed Word documents - is China to blame:  Our friends at F-Secure have blogged today about a boobytrapped Word document, that appears to be designed to infect computer systems running Mac OS X. The malicious Word file, examined by the experts in SophosLabs, claims to be about the […]

Read more
Vulnerability Assessment
How To Stop Making Excuses For Poor Application Security Testing

An posting from Dark reading about How To Stop Making Excuses For Poor Application Security Testing: just as the old carpenter axiom warns to measure twice and cut once, the effort of putting in effective security testing practices earlier in the application development process saves many more headaches later in the application lifecycle. "We want to […]

Read more
Vulnerability
Security Vendors In The Aftermath Of Targeted Attacks

An posting from Dark reading about Security Vendors In The Aftermath Of Targeted Attacks: It has been months now since any word of a security company getting hacked has surfaced, but security vendors are still getting targeted on a daily basis by attackers ultimately after their customers -- or their intellectual property. "It certainly has not […]

Read more
General Security
Google joins FIDO's crusade to replace passwords

An posting From Cnet in there Security and privacy sections about Google joins FIDO's crusade to replace passwords: In the face of rampant weak password selection, group aims to replace passwords for identity authentication when logging into Web sites and online accounts. A group of tech companies looking to replace passwords for online identity authentication gained a powerful ally Tuesday in […]

Read more
Mobile Security
Viber flaw bypasses lock screen to give full access to Androids

An article from Naked  Security about Viber flaw bypasses lock screen to give full access to Androids: Lacking the lightning-fast reflexes needed toget past the Samsung Galaxy Note 2's lock screen? Hampered by pesky morality that forces you to forego the placing of bogus emergency calls so as to hack iPhone passcodes? Not that you should want to do any of […]

Read more