Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Reports Show Significant Drops in Spam Levels Since Rustock Botnet Takedown - But Will Rustock Be Back?The Rustock Botnet was sending as many as 13.82 Billion spam emails each day before being taken down early this month by an effort headed by Microsoft in cooperation with authorities and the legal system.According to Symantec’s March 2011 MessageLabs Intelligence Report, the Rustock botnet had been responsible for an average of 28.5% of global spam sent from all botnets in March.

eBay announced today that it has agreed to acquire ecommerce and marketing services provider GSI Commerce for $2.4 billion in cash. It’s not a “done deal” yet, however, as under the terms of the merger agreement, GSI Commerce may solicit acquisition proposals from third parties for a 40-day “go-shop” period continuing through May 6, 2011.

NEI, a Canton, Massachusetts provider of solutions for software technology developers and OEMs, today announced that it has been awarded a US Patent for a technology that creates a new type of "digital fingerprint" that accurately validates software updates for physical and virtual servers and cloud-based application platforms.Patent #7900056 filed as "digital data processing methods and apparatus for management of software installation and execution," enables secure and reliable software update distribution.

NETGEAR today introduced the NETGEAR ProSecure UTM150 – a Unified Threat Management (UTM) gateway targeting businesses with around 150 users. The new UTM150 was designed to deliver powerful security, reliability and performance in an affordable package for smaller businesses that typically lack "big IT" resources.

Cybercriminals in the underground economy are making serious money from stealing corporate intellectual property, which includes things such as source code, trade secrets, marketing plans, and research and development discoveries.According to the results of a study released today by McAfee and Science Applications International Corporation (SAIC), cybercriminals realize there is significant value in stealing corporate IP and the ability to that corporate information and trade secrets.

Updated with Statement from Oracle (03/28/11 1:48PM EST) Oracle issued the following statement to SecurityWeek on Monday afternoon: "Security is one of Oracle’s greatest priorities. It was recently reported that a number of sites on the MySQL.com domain may have been compromised. Oracle is currently investigating this incident to determine which systems and data may have been affected. We will continue to keep you updated."

The Android security model includes a sandbox-like environment that segregates applications and makes good use of shared memory. It also puts the user in control of the device, in part by making the user accept permissions for the installation of any widget.

One of the Best ways to Secure Messaging Infrastructure is to Leverage the Power of the Corporate Directory Information Technology in the current economy is about doing more with less—efficiency and optimization are the rule in IT projects for 2011 and driving technology trends like cloud computing and virtualization initiatives. Securing the IT infrastructure is a cost that does not contribute to a firm’s competitive advantage; however, optimization is about lowering the cost for securing the IT infrastructure.

Fraudulent SSL Certificate WarningUS-CERT, Microsoft, Mozilla and other organizations have issued warnings regarding fraudulent (fake) SSL certificates being issued.According to the Comodo Group, Inc., the certificate authority responsible for issuing the fraudulent certificates, a Comodo affiliate RA was compromised on March 15th 2011, resulting in the fraudulent issue of 9 SSL certificates to sites in seven domains.

According to recent scans of than 475 merchant networks, nearly two-thirds of merchant computer systems store unencrypted payment card data. These results come from SecurityMetrics, a provider of PCI Data Security Standard security solutions, and show that these merchants are in violation of the Payment Card Industry Data Security Standard (PCI DSS), leaving them liable to fines and other penalties.

This article is the second in a series describing the hottest commodities found in underground markets. In this column we continue to explore the trending “commodities” in underground markets and how to protect from your data being exchanged in these markets.

Mountain View, CA based Passware, Inc., a provider of password cracking and decryption technology, announced this morning that its software now can harness the power of Amazon Elastic Compute Cloud– a highly scalable cloud computing platform – for accelerated password cracking, without the need to buy expensive hardware.

McAfee announced this morning that it would acquire Sentrigo, a privately held provider of database security solutions.Sentrigo offerings include database security technologies including vulnerability management, database activity monitoring, database audit, and virtual patching.The acquisition would bring together technologies allowing McAfee customers to:

Hacker Posted Video of Himself Compromising a Hospital’s Computer System on YouTubeJesse William McGraw, a former contract security guard at the North Central Medical Plaza in Dallas, who admitted hacking into the hospital’s computer systems, was recently sentenced to 110 months in Federal prison.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.