AP Twitter Hack: Lessons Learned
An posting from Information Week security in there security section: Would you trust an email that says: "Please read the following article, it's very important: www.washinqtonpost.com/blogs/worldviews/wp/2013/04/23/"? So went a phishing email reportedly sent to multiple employees at the Associated Press, less than an hour before the company's Twitter feed was taken over and used to issue multiple tweets, […]
How Lockheed Martin Phishes Its Own
An posting From Dark Reading about How Lockheed Martin Phishes Its Own: On several occasions over the past couple of years, employees at Lockheed Martin have flagged suspicious emails that turned out to be previously unknown targeted attack campaigns aimed at the defense contractor. This additional pair of eyes in security is one of the bonuses of […]
XSS Vulnerability in Cisco sub domain found by 14 Years Old security researcher
A Cross Site Scripting Vulnerability found in Cisco sub domain newsroom.cisco.com by a 14 Year Youngest security researcher Ali Hasan Gauri, today he reported us about his Latest vulnerability he found in Cisco sub domain.
Nessus® 5.2 Vulnerability Scanner is Now Available
Tenable is pleased to announce the availability of the Nessus® 5.2 vulnerability scanner. This release provides expanded platform support and integration, enhanced analysis and reporting capabilities, and improved usability. Nessus 5.2 is available now to Nessus ProfessionalFeed®, Nessus Perimeter Service™, and Nessus HomeFeed® users at no additional cost.
Mac malware found in malformed Word documents - is China to blame?
An posting from Naked security about Mac malware found in malformed Word documents - is China to blame: Our friends at F-Secure have blogged today about a boobytrapped Word document, that appears to be designed to infect computer systems running Mac OS X. The malicious Word file, examined by the experts in SophosLabs, claims to be about the […]
How To Stop Making Excuses For Poor Application Security Testing
An posting from Dark reading about How To Stop Making Excuses For Poor Application Security Testing: just as the old carpenter axiom warns to measure twice and cut once, the effort of putting in effective security testing practices earlier in the application development process saves many more headaches later in the application lifecycle. "We want to […]
Security Vendors In The Aftermath Of Targeted Attacks
An posting from Dark reading about Security Vendors In The Aftermath Of Targeted Attacks: It has been months now since any word of a security company getting hacked has surfaced, but security vendors are still getting targeted on a daily basis by attackers ultimately after their customers -- or their intellectual property. "It certainly has not […]
Google joins FIDO's crusade to replace passwords
An posting From Cnet in there Security and privacy sections about Google joins FIDO's crusade to replace passwords: In the face of rampant weak password selection, group aims to replace passwords for identity authentication when logging into Web sites and online accounts. A group of tech companies looking to replace passwords for online identity authentication gained a powerful ally Tuesday in […]
Viber flaw bypasses lock screen to give full access to Androids
An article from Naked Security about Viber flaw bypasses lock screen to give full access to Androids: Lacking the lightning-fast reflexes needed toget past the Samsung Galaxy Note 2's lock screen? Hampered by pesky morality that forces you to forego the placing of bogus emergency calls so as to hack iPhone passcodes? Not that you should want to do any of […]
AP Twitter account hacked, posts false White House scare
An posting from NBC News in there Technology section : Following a hack attack, the Associated Press' verified Twitter account posted "an erroneous tweet" claiming that two explosions occurred in the White House and that President Barack Obama is injured. Moments later, the @AP Twitter account — with nearly 2 million followers — was suspended. Immediately […]