Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest News

It’s always the insider. Well, maybe not always, but it sometimes seems that’s what we are hearing. I was reading articles on some recent cases and any of them seem to have a common theme: “XXX Case Exposes Insider Risks” and “Employee Error Leads to XXX Hack” are just a couple recent headlines. The press also published info about a recent breach which was caused when an employee clicked on an attachment that they pulled from the junk email folder.

The Washington Post has notified users of its job board that a recent a cyber attack has resulted in a data breach that compromised up to 1.27 million job seeker accounts.The Washington Post said that the attack occurred in two brief episodes, once on June 27 and once on June 28, resulting in the attacker(s) getting hold of roughly 1.27 million user IDs and e-mail addresses. Passwords or other personal information were not compromised, the publisher said.

It’s July. An odd time to be talking about Super Bowl security, right? Actually, it’s never too early to focus on information security and risk management, and Super Bowl security is certainly no exception. Super Bowl officials take two full years to plan and implement their strategy. IT security pros everywhere would be well advised to learn from them and take action long before crunch time.

Sophos has completed its acquisition of network security vendor Astaro, a deal that will enable Sophos to deliver endpoint protection combined with Unified Threat Management solutions.The acquisition, which was announced on May 6, 2011, will enable Sophos to:

Oracle Virtual Desktop Client App for iPad Brings Highly Secure and Mobile Access to Virtual Desktops and Enterprise Applications Oracle today announced the availability of Oracle Virtual Desktop Client App for iPad that enables secure access to virtual desktops managed by Oracle's Sun Ray Software and Oracle Virtual Desktop Infrastructure.

In a talk at last year’s EuroSecWest conference, researcher Andrei Costin presented several vulnerabilities he found within commercial printers.

Last month, the FBI announced that violent crime rates had fallen dramatically in 2010 despite a tough economy. The Wall Street Journal explained this seemingly counterintuitive situation away with a list of factors. But none of those factors seem to have caused a drop in cyber-crime, as the Verizon Data Breach Investigations Report (DBIR) showed. All this poses a question – can we apply any of these factors to reduce the rate of cyber-crime?

Adrian Ghighina, 33, of Bucharest, Romania, was sentenced to 48 months in prison last week by U.S. District Judge Matthew F. Kennelly in Chicago after he pleaded guilty in February 2011 to one count each of wire fraud and conspiracy.

Domain name registrar and Web hosting provider GoDaddy, announced it has agreed to receive a strategic investment from private equity firms KKR, Silver Lake and Technology Crossover Ventures.The terms of the transaction were not disclosed, but the Wall Street Journal reported people familiar with the deal saying it could be worth approximately $2.25 billion. Its likely that founder Bob Parsons has cashed out a large chunk of his shares in the company, and kept a minority stake.

With all the daily reports on how companies are experiencing security breaches in their networks, it would appear hackers are taking over. Since January of this year, those in the security business believe that hacking big companies is now in the norm. NASDAQ, HP, Sony and governments agencies, as examples, are not weathering hacker intrusions any better.

Unlike my daughter’s second grade piano review, sincerity in the world of secure web application development means very little. Development of secure Web applications and the effort to maintain their security is hard work, requiring a holistic approach and a long-term perspective that web application is essential. Security is not achieved by simply demanding it of your staff; you need the correct staff to demand it of, continuous manual and automated vulnerability testing, and code reviews by security experts.

Cybercriminals Favoring Targeted Attacks over Mass SpamIn a continuing trend, new research released by Cisco today further confirms that cybercriminals have made a fundamental shift in strategy, abandoning traditional mass spam attacks in favor of personalized attacks with a greater financial impact on targeted organizations.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.

Cloud Security

Cloud Security

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.