Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Oracle recently patched a flaw in the TNS Listener service as part of their update release in April. As it turns out, the TNS Poisoning patch didn’t apply to current versions of Oracle, leaving existing customers on their own. The TNS Poison bug has quite the history, researcher Joxean Koret reported the issue in 2008, but the flaw itself has likely existed since Oracle 8i.

Microsoft has patched a recently disclosed password reset vulnerability in Hotmail, which exposed a user base of some 360 million people to having their accounts compromised. Unfortunately, says Vulnerability Laboratory, the firm that discovered the flaw initially, the patch might not have arrived soon enough.

PRAGUE, CZECH REPUBLIC – Counter eCrime Operations Summit - The results of a recent study released by the Anti-Phishing Working Group (APWG) at its Counter-eCrime Operations Summit (CeCOS VI) taking place this week in Prague, showed that PayPal has lost its spot as the most phished brand globally.

CORE Security Technologies, a Boston, Massachusetts-based provider of security testing solutions, this week announced a significant update to its CORE Insight Enterprise security intelligence solution.According to the company, its latest offering helps security professionals identify critical exposures to their infrastructure and link them real-world business risks.

Why Consistency of Security Effectiveness and Performance is Key When Choosing Security TechnologiesHow do you separate marketing hype from reality? One approach is with third-party tests of IT security solutions—an efficient, neutral way to validate vendor claims of solution effectiveness and performance. But it isn’t enough to just look at a point-in-time result. What really counts is consistency year after year. Here’s why.

Google today said it would make another change to its search engine algorithm in an effort to cut back on web sites showing up in search results that may be there because of the wrong reasons.

A recent study coming from Sophos showed that 1 in 5 Macs have malware on them, leading to headlines proclaiming that 20% of Macs are infected. This misleading claim misses a key point in Sophos’ study, which is that the 20% represented Windows-based malware infections. If anything, Sophos’ results seem to suggest that Macs are the new Typhoid Mary of the Internet.

Firm Estimates Total share of Russian Cybercrime Market Doubles to Nearly $2.3 BillionGroup-IB, a Russian cybercrime investigations and forensics company with offices in New York and Moscow, recently released a report that examines the Russian cybercrime market and its existence in 2011. The 28-page report looks at the risks, trends, and financial performance of the criminal element, and includes forecasts for the coming year.

Researchers at Kaspersky Lab have confirmed that a new variant of malware targeting Macs is a directed attack. Called SabPub, the Trojan allows the attackers full control over the system, and unlike Flashback - the other Mac malware dominating the headlines - this one seems to have a distinct reason for living.

Security researchers are reporting the emergence of another variant of the Flashback Trojan targeting Mac machines. According to Intego, the new variant continues to use a patched Java vulnerability to infect users. No password is required for it to install, and it places files in the victim’s home folder at the following concerns:• ~/Library/LaunchAgents/com.java.update.plist• ~/.jupdate

Network security vendor Fortinet today introduced a series of dedicated appliances designed to help organizations defend against DDoS attacks.Designed for enterprises, hosting providers, and cloud service providers, the new FortiDDoS family of appliances takes advantage of custom ASICs (custom chips designed for a particular use) that the company says are capable of mitigating DDoS attacks while maintaining latency less than 26 microseconds.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.