Google Releases Chrome 16.0.912.77

/
US-Cert has just distributed a notification about the release of Chrome 16.0.912.77 for Linux, Mac, Windows, and Chrome Frame to address multiple vulnerabilities. The vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

Email scam could clear out your bank account

/
The FBI even put out a warning to let people know what to watch out for. This recent scam doesn't surprise me at all. It only takes these scanners to get .05% of people on email for it to be worth their time. And think how much easier it is today. I mean, I hardly ever go into a bank anymore. With online banking I can do almost everything, from checking my balance, transferring funds to paying my bills. And with hot new apps from banks like Chase, PNC and USAA I can even scan my checks with my phone and deposit them straight into my account.

Vulnerability Summary for the Week of January 16, 2012

/
This bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) the week of January 16, 2012. It is available here:

Congress withdraws SOPA and PIPA

/
Lawmakers on Friday indefinitely postponed anti-piracy legislation that pits Hollywood against Silicon Valley, two days after major Internet companies staged an online protest by blacking out parts of prominent websites. Senate Democratic leader Harry Reid postponed a showdown vote in his chamber on the Protect Intellectual Property Act, or PIPA for short, that had been scheduled for January 24.

Carberp Malware is Back in a New Form to Target Facebook users

/
"Carberp replaces any Facebook page the user navigates to with a fake page notifying the victim that his/her Facebook account is 'temporarily locked,'" says Trusteer CTO Amit Klein in his blog. "The page asks the user for their first name, last name, email, date of birth, password and a Ukash 20 euro [approximately $25 US] voucher number to 'confirm verification' of their identity and unlock the account.

Upcoming SANS 2012 (Orlando) Information Security Training Event

/
SANS 2012 (March 23-30, 2012) is fast approaching! More than 35 courses are offered, all taught by our top-rated instructors who are the best at ensuring you learn the material and can apply it immediately when you return to your office. Choose from audit, IT legal, security management, software and web app developer, forensics, computer security training, and more.

This is a post with post format of type Link

/
http://www.kriesi.at Lorem ipsum dolor sit amet, consectetuer…

Security Risk of Shortened URLs and How to Expand Them

/
Shortened URLs are a fixture in the social networking world. They are the cryptic URLs you normally see on your Twitter feed as well as on Facebook.

Effective password testing using Metasploit

/
Software vulnerabilities receive most of the limelight in network security, but weak, shared, and mismanaged passwords are often the biggest threat to most organizations.

Oracle Critical Patch Update (CPU) for Tues Jan 17th 2012

/
FYI for those running Oracle products such as OracleDB, Glassfish, MySQL, Solaris, etc. The following links will provide additional information to assist you. Oracle Critical Patch Update (CPU) Pre-Release Announcement - January 2012