Vulnerability
What Every CFO Should Know About Security Breache

A posting from dark reading about What Every CFO Should Know About Security Breache:  TYSONS CORNER, VA. -- CEOs and CIOs have gotten religion about cybersecurity, but what about those who hold the purse strings? Experts say they need a hard lesson, too. In a panel called "What Every CFO Must Know About Cyber Threats and […]

Read more
Vulnerability
Developing Data Classification For Stronger Database Security

An posting  from Dark Reading about Developing Data Classification For Stronger Database Security: Data discovery may be an important early step in developing a sound database security program, but in the end it's just the first step. Ultimately data security controls have to be driven by the different sorts of risk faced by the various types of […]

Read more
Vulnerability
Oracle preps 128 security patches; Java gets 42

An posting from Cnet in there security and privacy section :  Oracle will release today 128 fixes for security vulnerabilities that affect "hundreds" of its products.The software giant and Java maker said in a pre-release announcement today that four of the patches include fixes for Oracle's flagship database product, which can be exploited remotely without the need for […]

Read more
Vulnerability
Researcher rewarded over $30,000 for nailing three Chrome OS security flaws

An posting from Naked Security about Researcher rewarded over $30,000 for nailing three Chrome OS security flaws:  Google has patched four flaws - three of them high-risk - in its Chrome operating system and has paid out $31,336 to the researcher who spotted three of them. The flaws are all found in the O3D plug-in: a Google-crafted plugin […]

Read more
Vulnerability
Anatomy of an exploit - Linksys router remote password change hole

An interesting posting from Naked Security: A security researcher from San Jose in California has published a how-to guide detailing a number of vulnerabilities in various Linksys routers. Phil Purviance, who goes by the handle of SUPER.EVR (EVR stands for Exploitation Vulnerability Research), reported the holes privately on 05 March 2013:   And Purviance certainly lived up […]

Read more
Vulnerability
Public safety personnel targeted by DoS attacks flooding phone lines

An article from SCMagzine about Public safety personnel targeted by DoS attacks flooding phone lines: Telephone lines for public safety and emergency communication workers have been inundated with bogus calls, an attack characterized by the U.S. Department of Homeland Security and FBI as telephony denial-of-service (TDoS), which is being used to extort money from victims. Last […]

Read more
Vulnerability
Firefox's Version 20 Patches 11 Serious Flaws

An posting from TechNews on FireFox Patches : Firefox was not exactly full of vulnerabilities previously, but now users of Mozilla's customizable Web browser can rest even easier. In its 20th version, Firefox patches 11 potentially catastrophic security flaws while introducing a few privacy and convenience features for the average user. While Mozilla still pinpoints […]

Read more
Vulnerability
NSA Director: Information-Sharing Critical To U.S. Cybersecurity

An posting from Dark Reading about cyber security: Information-sharing and visibility into the threat landscape are vital for the public and private sectors to defend cyberspace, National Security Agency Director Gen. Keith B. Alexander told an audience at The Georgia Tech Cyber Security Symposium yesterday. The key to this is crafting legislation that protects privacy […]

Read more
Vulnerability
Too Scared To Scan

An article from Dark Reading in there Security section: When it comes to detecting vulnerabilities in mission-critical applications, security professionals often find themselves in a bind. These are usually the applications that the enterprise can least afford to suffer a hack. But at the same time, they are also the applications whose owners are most […]

Read more
Vulnerability
Critical Flaw Threatens Millions of BIND Servers

An posting in Threat post on a flaws that my blind severs: There is a critical vulnerability in several current versions of the BIND nameserver software that could allow an attacker to knock vulnerable DNS servers offline or compromise other applications running on those machines. The bug is present in several versions of the ubiquitous […]

Read more