Don't Take Vulnerability Counts At Face Value
A posting from Dark Reading in there Vulnerability Management Section: In 2012, there were 5,291 vulnerabilities documented by security researchers and software firms. Wait, no, make that 8,137. No, 9,184. Well, it could even be 8,168 or 5,281. In reality, the exact number of vulnerabilities reported in different databases each year varies widely--by as much […]
Bad SSH Key Management Leaves Databases At Risk
A posting from Dark reading in there Database Security Section: A "gaping hole" in the way enterprises govern the use of one of IT's least sexy but most used access control and encryption protocols is leaving many sensitive database servers and other network devices at serious risk. Secure Shell (SSH)--a Swiss army knife in the arsenal of […]
Microsoft announces five Bulletins for Patch Tuesday, including Office for Mac
A posting from Naked Security: Midsummer Patch Tuesday (or midwinter, depending on your latitude) takes place on Tuesday 11 June 2013. As you probably already know, Microsoft publishes an official Advance Notification each month to give you early warning of what's coming. These early notifications generally don't give any details, summarising only the basics, such as: The […]
Not good enough, Oracle - promises to secure Java are too little, too late
An interesting article from Naked security: Oracle has promised to work harder to make Java more secure. Given the constant flood of high-profile, heavily-exploited vulnerabilities, are Oracle's new ideas going to be enough to save this piece of software from drowning in bad vibes? In a lengthy blog post last week, the head of Java […]
Controlling The Risks Of Vulnerable Application Libraries
A posting from Dark Reading in there Application Security section: During the past decade, developers have increasingly leaned on third-party components, such as open-source libraries, to dramatically lighten the load during coding. These components can help reduce time spent adding basic or universal features and functions so that developers can focus their work on the innovative […]
Web Application Testing Using Real-World Attacks
A posting from Dark Reading in there Vulnerability Management section: Vulnerability management and scanning systems typically combine a number of techniques to assess the risk faced by a business's information technology, from scanning files and evaluating the current patch level to launching attacks and testing for practical vulnerabilities. While assessing patch level tends to be the most reliable […]
Is Application Sandboxing The Next Endpoint Security Must-Have?
A posting from Dark Reading in there Endpoint Security section : With the onslaught of zero-day attacks continuing to increase the barrage of unanswered threats against endpoints, there's a growing contingent of security advocates championing the addition of a virtualized container layer in the endpoint security mix. Analyst predictions are rosy for the virtual containerization […]
Indian government investigates firms at center of global cyber heist
A posting from NBCNEWS in there technology section about Indian's government investigates firms at center of global cyber heist: MUMBAI/BANGALORE, May 12 (Reuters) - The Indian government's cyber watchdog is investigating how security at two companies that are part of the country's vast IT services industry was breached in a global ATM heist that saw $45 million stolen […]
US cyberwar strategy stokes fear of blowback
A posting from NBC NEWS in there technology section: WASHINGTON (Reuters) - Even as the U.S. government confronts rival powers over widespread Internet espionage, it has become the biggest buyer in a burgeoning gray market where hackers and security firms sell tools for breaking into computers. The strategy is spurring concern in the technology industry and intelligence community […]