Vulnerability
Metasploit Module Released For IE Zero-Day Flaw Used In Labor Attack

A posting from Dark reading:  A targeted attack discovered last week serving up malware from the U.S. Department of Labor's (DOL) website employed a previously unknown vulnerability in Internet Explorer 8 that Microsoft says it will fix either with an emergency patch or via its monthly patch process. And as is tradition, Metasploit also has […]

Read more
Vulnerability
5 Ways For SMBs To Boost Security But Not Costs

A posting from Dark reading: For many businesses, improving their security seems like the proverbial money pit: but it doesn't have to be that way. While the time crunch of attending to the demands of the daily business has typically created an accumulation of security problems for many businesses, information technology professionals at SMBs can improve […]

Read more
Hack
Sweet Password Security Strategy: Honeywords

A posting from Information Week in there security section: Businesses should seed their password databases with fake passwords and then monitor all login attempts for use of those credentials to detect if hackers have stolen stored user information. That's the thinking behind the "honeywords" concept first proposed this month in "Honeywords: Making Password-Cracking Detectable," a paper written by Ari Juels, chief scientist […]

Read more
Vulnerability
US nabs suspected programmer of bank Trojan that drained millions of dollars

A posting from NBC News in there Technology section:  ATLANTA (AP) - An Algerian man accused of helping to develop and market a computer program that drained millions of dollars from bank accounts around the world pleaded not guilty Friday to nearly two dozen charges. A 23-count indictment charges Hamza Bendelladj, 24, with wire fraud, bank fraud, computer […]

Read more
Vulnerability
Websites Harbor Fewer Flaws, But Most Have At Least One Serious Vulnerability

A posting from Dark Reading: Websites now contain fewer numbers of serious security vulnerabilities, but the majority of websites still have at least one serious flaw that can lead to a major compromise. Some 86 percent of websites have at least one serious bug that could be used in an attack, while the total number […]

Read more
Vulnerability
Spamhaus DDoS Suspect Arrested

A posting from Information week in there Security section: Police in the Netherlands Friday announced the arrest of a 35-year-old Dutchman on charges of having launched "unprecedented heavy attacks on the non-profit organization Spamhaus." The suspect, identified only as "S.K." by Dutch police, has been named in multiple news reports as Sven Kamphuis, the leader of Amsterdam-based […]

Read more
Vulnerability
Twitter Two-Factor Authentication: Too Little, Too Late?

A posting from Information week in there security section:  Can you feel the two-factor fever? Following in the footsteps of Microsoft this month, Apple in March, and Facebook and Google before them,Twitter is now testing a two-factor authentication system to make it more difficult for attackers to hijack people's accounts. That's welcome news in the wake of […]

Read more
Vulnerability
How Lockheed Martin Phishes Its Own

An posting From Dark Reading about How Lockheed Martin Phishes Its Own: On several occasions over the past couple of years, employees at Lockheed Martin have flagged suspicious emails that turned out to be previously unknown targeted attack campaigns aimed at the defense contractor. This additional pair of eyes in security is one of the bonuses of […]

Read more
Malware
Mac malware found in malformed Word documents - is China to blame?

An posting  from  Naked security about Mac malware found in malformed Word documents - is China to blame:  Our friends at F-Secure have blogged today about a boobytrapped Word document, that appears to be designed to infect computer systems running Mac OS X. The malicious Word file, examined by the experts in SophosLabs, claims to be about the […]

Read more
Vulnerability
Security Vendors In The Aftermath Of Targeted Attacks

An posting from Dark reading about Security Vendors In The Aftermath Of Targeted Attacks: It has been months now since any word of a security company getting hacked has surfaced, but security vendors are still getting targeted on a daily basis by attackers ultimately after their customers -- or their intellectual property. "It certainly has not […]

Read more