Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

As 2011 draws to a close, I’ve decided to take a step back and review the past year. Let’s take the lessons learned about software piracy and see how they can be applied in 2012.

Constant demand for advanced malware, paired with a co-opetition model, this ecosystem directly impacts how quickly and efficiently new threats can spread.As malware gets progressively more complex, it’s important to understand how the major players in the malware industry fit together and how these relationships affect the ways that malware is developed, distributed and ultimately used in attacks.

Around this time last year you may have read my SecurityWeek article, The Optimist's Cybercrime Predictions for 2011. Now that the year is drawing to an end, I thought it would be an interesting opportunity to look back to my 2011 predictions and see how each of them panned out.

While the move is far from a total change of stance, it looks as if the Pentagon has started to open its heart and mind to something other than BlackBerry. According to the latest Security Technical Implementation Guide (STIG) overview, the Defense Department is open to the idea of devices running Android 2.2, but so far only one device has made the cut.

McAfee has come forward with its list of 2012 threat predictions, part of a longstanding tradition in the InfoSec community, which outline what it sees as the largest obstacles to personal and organizational security in the coming year.

The National Cyber Security Alliance (NCSA) and McAfee have produced a report examining the growing false sense of security displayed by mobile users, and how it could impact the nation overall.The research found that 70-percent of smartphone owners say they feel their device is safe from various types of cybercrime. Further, the same percentage said that they have never installed any form of security protection on their mobile device, and that they feel their device is safe from data theft...

Siemens has announced plans to patch a number of critical vulnerabilities in its SCADA software after a researcher accused the company of trying to brush the issue under the rug.In response to claims by security researcher Billy Rios that the company was dismissing reports of vulnerabilities, Siemens issued a statement noting that the company planned to patch a number of issues found by Rios and fellow researcher Terry McCorke next month.

In late November, news surfaced that researchers from Columbia University had discovered vulnerabilities in upgradeable firmware in HP laser printers that could be compromised and modified by an attacker, enabling them to do anything from overheating the printer, to compromising a network, with some saying that the devices could even be set up in flames.

Strategic Forecasting Inc. (Stratfor), a Texas-based intelligence firm that delivers paid briefings on a wide range of topics, suffered a pre-Christmas breach at the hands of those supporting the current incarnation of the AntiSec movement. The fallout has been devastating thus far, but according to comments from those familiar with the breach, this is only the beginning.

Instead of passively waiting for an intruder to trigger a trap you set, consider adding a truly proactive component to your SIEM strategy.Aren't IDS and Log Collectors great? Not so long ago, the problem that most security professionals had was a lack of information. Not any more! Now, many of us have more information than you can throw SQL queries at.

Next year you'll be able to do all your holiday shopping without ever opening a physical wallet—or so Google hopes. The previously announced Google Wallet is comfortably into beta. Google is betting that by 2014 half of all smart phones will ship with compatible NFC chips installed. They hope that Google Wallet will be on most if not all of them.

Cyber-Ark Software, a provider of enterprise security solutions that help companies secure and manage accounts, sessions, critical applications and data, this week announced that it has signed an agreement for a $40 million investment round led by Goldman Sachs and Jerusalem Venture Partners (JVP).

2012 IT Security Predictions: What Will the Threat Landscape Look Like in the New Year?Very soon, 2011 will come to a close. It has been quite a year for hackers and security companies alike.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.