Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Apple Auto-Disables Outdated Versions of Flash Player, Pushes Several Security Fixes in Mac OS X 10.7.4 and Safari UpdateFollowing a recent update to its iOS software that addressed several security issues with Apple’s mobile devices, the Cupertino tech titan pushed another significant software update today, this time for its flagship Mac OS X operating system and Safari Web browser.

Dell today announced that it has completed its acquisition of IT security vendor SonicWALL, adding several components to the company’s security software and services portfolio.In a deal that was announced on March 13 of this year, while the terms were not publicly disclosed, Dell reportedly paid $1.2 billion to acquired SonicWALL.

Adscend Media LLC, a marketing firm connected to several Clickjacking schemes (also known as Likejacking), has agreed to pay attorney fees and stop spamming Facebook. The agreement was announced on Monday by the Washington State Attorney General’s office.Washington State Attorney General Rob McKenna sued Adscend earlier this year, after a rash of scams on Facebook led to users being tricked into sharing personal information and signing up for subscription services.

David DeWalt Joins Mandiant as Chairman of the Board of Directors Mandiant, a firm focused on security threat detection and response solutions, has announced that former McAfee President and CEO, David DeWalt, has been named as chairman of Mandiant’s board of directors.

MySpace Settles With FTC After Failing to Live up to Privacy ExpectationsOn Tuesday, the Federal Trade Commission (FTC) announced that MySpace has agreed to settle charges that the social networking portal misrepresented its privacy claims to users.

Online Address Book Service Plaxo Switching to oAuth After Being used to Access Google AccountsPlaxo, a popular online address book service, has disabled its API and suspended some services after attackers used them as a proxy to target an unknown number of Google accounts.

BlackBerry maker Research In Motion today announced that the U.S Department of Defense has given department-wide approval for the use of BlackBerry 7 smartphones on its networks. The struggling smartphone maker said that by working with U.S. Army and Defense Information Systems Agency (DISA) sponsors and partners, BlackBerry 7 smartphones have undergone successful testing through Army labs leading to a subsequent listing on DISA's Unified Communications Approved Product List (UCAPL).

Fixing DNSSEC Errors - What Can You Do When DNSSEC Goes Bad?Despite the fact that the Internet is an increasingly critical component of the world’s communications infrastructure, its “phone book” -- the Domain Name System (DNS) -- is often considered fundamentally insecure.

In a letter to Senator John McCain, originally obtained by the Washington Post for a report published last Friday, General Keith Alexander, the director of the NSA and current commander of the U.S. Cyber Command, says that the U.S. should implement policy that would require hardened network defenses.

The Blackhole exploit kit has moved its ransom-based payloads forward from child porn and terrorism to copyright violations. The new theme from the crime kit is professionally developed and is mostly targeting users in Europe.The changeup from Blackhole was discovered by researchers at abuse.ch, the Swiss security blog. Briefly, the Blackhole exploit kit was launched in 2010 by developers in Russia. The kit targets various vulnerabilities, from Windows only, to Adobe’s Flash and PDF formats, and Java.

On Tuesday, the PHP Group plans to release new versions of PHP in order to address the problems with a previous patch, which was intended to close a security problem. As SecurityWeek reported on Friday, the first patch released by PHP was easily bypassed.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.