Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest News

Before there was concern over VM stall, there was that of VM sprawl.VM sprawl had organizations worrying that so many virtual machines would be spun up (thanks to the ease of deploying them) that not only would management become an issue, but so, too, would performance, security, and IT staffing.

Update: NetQin Mobile reached out to SecurityWeek to let us know that they had previously identified the same malware under the name AnserverBot on September 19th. Dr. XuXian Jiang, Chief Scientist at NetQin’s US Security Research Center, offers a detailed report on how the malware works. - Editor

According to a recent report from the Government Accountability Office, despite efforts to implement stronger cybersecurity controls, several federal agencies remain in a weakened state. Since 2006, security incident reports have risen over 650-percent.

New Release Helps Protect Sensitive Data, Brings Centralized Management of Enterprise Wide Database Security MeasuresOn Monday at Oracle Open World, Oracle’s giant customer conference taking place this week in San Francisco, Oracle unveiled new and improved database security features in Oracle Enterprise Manager 12c.

McAfee today announced that it has agreed to acquire NitroSecurity, a privately held provider of high-performance security information and event management (SIEM) solutions.The company’s founders and roots come from the U.S. Department of Energy’s Idaho National Laboratory, giving it extensive experience with critical infrastructures in the energy sector, creating a sweet spot for the Portsmouth, NH-based company in a sector that has come into the spotlight following Stuxnet and a general rise in concern over critical infrastructure security.

SIEM vendors are all jumping on the Security Intelligence tag line, but what does it really mean? The bad guys are getting more sophisticated and the quality and breadth of intelligence is crucial to early identification and thwarting attacks. Can SIEM bring the analog of human intelligence (aka, espionage) to cyber threats and the security visibility of business intelligence to the executive boardroom?Defining the threat landscape:

VASCO Data Security, parent of recently “hacked out of business” Certificate Authority (CA), DigiNotar, has shared additional information on the expected losses surrounding the recent cyber attack that forced the company into bankruptcy.

Organization Warns that Poor Governance over Geolocation can be DisastrousIn a recently released white paper, the ISACA has offered a general overview of the issues surrounding corporate and consumer privacy when it comes to mobile geolocation services. In addition, the organization has offered a simple mnemonic to consumers and employees to address privacy and safety concerns - aptly named ROUTE.

Danish security firm CSIS recently released the results of a three-month long study, backing a common line of thought in the security world. That is, third-party applications can lead to serious risk, especially when combined with a lack of patching.According to CSIS, five products are responsible for 99-percent of all malware infections. Many of the targeted applications are vulnerable due to a lack of patching, leaving the user and the network exposed.

Social media can be a useful tool for businesses, bringing substantial benefits to marketing and communications with customers and employees, when used properly. But as any IT security department knows, social networks such as Facebook, Twitter and LinkedIn pose a significant threat to users across the board as they blindly click links which often lead to spam, clickjacking attacks, or other malicious sites that could result in malware infection.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.

Cloud Security

Cloud Security

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.