Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

DARPA Seeks Stronger Authentication Beyond Passwords by Making Computers Adapt to HumansThe U.S. Defense Advanced Research Projects Agency (DARPA) is asking for help designing a new approach to authentication.

Estonian Cybercrime Group Infected More Than 4M Computers with DNS Changing Malware The FBI and international authorities have disrupted a massive cybercrime scheme that infected more than four million computers with malware, and generated an estimated $14 million for a group of cybercriminals over a period of several years.

Bank of America Merrill Lynch announced this week that it would be offering Chip and PIN technology (also known as EMV) in corporate cards for U.S. international travelers.A Bank of America spokesperson told SecurityWeek that the credit cards would be offered to any its large corporate/commercial credit card customers who travel outside the U.S. on business. The program is not available for debit cards.

Shares of Imperva (NYSE:IMPV) jumped nearly 40 percent today as the data security firm made its debut as a public company, opening at $23 a share and topping $25 during trading.

Kindsight, an Alcatel-Lucent backed company that works with ISPs to analyze the behavior from their customer’s computers, has launched a new portal that details current network-based threats and vulnerabilities.Kindsight, after detecting issues on a given user’s system, will often provide support to the ISP’s customer when needed. They partner with several ISPs, and the data collected from their day-to-day analysis of threats and vulnerabilities, means they have a treasure trove of information to share.

Baltimore-based data protection vendor, SafeNet, has released, what the company says, is the industry’s first Key Management Interoperability Protocol (KMIP) standards-based EKM solution using a pre-configured hardware appliance.“As the use of encryption grows and various solutions are deployed, key management becomes exponentially critical and complex,” said Vic Wheatman, vice president, Gartner Research. “Mismanagement of keys can expose an organization to unnecessary risk.”

Fraud Rings Manufactured U.S. Permanent Resident Cards, Social Security Cards, Mexican Consular Identification cards, and Driver’s Licenses.More than 300 law enforcement officers from federal and local agencies executed dozens of arrest and search warrants in connection with multiple fraudulent document rings operating in Los Angeles and several other cities.

Microsoft and Adobe Systems each released patches today to address critical security vulnerabilities in their products. For Patch Tuesday, Microsoft issued four security bulletins to plug a total of four vulnerabilities. Just one of those bulletins is rated ‘critical’ – a bug in Microsoft Windows that can be exploited by an attacker to remotely execute code.

Cenzic and NT OBJECTives, both firms that focus on application security solutions, today announced that they have settled an ongoing legal battle that has been rolling for most of this year.

A new report coming from the Anti-Phishing Working Group (APWG) reveals that phishing attacks against Chinese banking and e-commerce Web sites soared by 44 percent in the first half of 2011. According to the report, 70 percent of all maliciously registered domain names in the world were established by Chinese cybercriminals for use against Chinese brands and enterprises.

Apple security guru Charlie Miller said he has uncovered a bug in Apple iOS that allows an attacker to circumvent Apple’s code signing approach.According to Miller, who is principal research consultant with Accuvant Labs and a veteran of the Apple bug-finding world, the vulnerability could spell trouble for iOS users if exploited.

Millions of people in Brazil have potentially been exposed to malware as a result of a nationwide DNS attack. Additionally, several organizations in Brazil are reporting that network devices are also under attack. After being compromised remotely, scores of routers and modems had their DNS settings altered to redirect traffic. Police have arrested a 27-year-old ISP employee who is suspected to have taken part in the attacks.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.