Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Romanian Nationals Charged with Participating in Multimillion Dollar Scheme to Hack into and Steal Credit Card Data from U.S. MerchantsThe Department of Justice announced today that four Romanian nationals have been charged for their alleged participation in a multimillion dollar scheme to hack into and steal payment card data from merchants’ point of sale (POS) systems in the U.S.

Security researchers have uncovered more details about the recent Adobe Reader and Acrobat exploit that is being used in attacks targeting U.S. defense firms. According to Symantec, the attackers are leveraging a zero-day flaw in 9.x versions of Reader to infect Windows computers with the Sykipot Trojan, which opens up a backdoor on compromised systems.

ENSIA Identifies 16 Areas Where CERTS Fail on Proactive Detection of Network Security Incidents In a report detailing the findings of a study on proactive detection of network security incidents, the European Network and information Security Agency (ENISA) has identified 16 areas where Computer Emergency Response Teams (CERTs) are being hindered by process gaps that are impacting their job performance and overall effectiveness.

Yahoo! today said that it has been awarded a $610 million default judgment, handed down by a federal judge in New York, against spammers responsible for a fake Yahoo! lottery email scheme. In the scheme, spammers sent emails to users, trying to trick them into believing they had won a lottery prize from Yahoo!.Court documents show that Yahoo! estimated the defendants had sent at least 11,660,790 hoax emails from December 2006 through May 2009.

ENISA and OWASP Issue Smartphone Secure Development GuidelinesThe European Network and information Security Agency (ENISA) and OWASP have published a report for secure development guidelines on mobile devices. Written for smartphone application developers, the report lists ten critical areas to consider when creating the next Angry Birds, or the ultra-portable office solution.

OpenDNS has released a tool along with its source code, that enables encrypted DNS traffic, much in the same way SSL enables encrypted HTTP traffic.According to OpenDNS, and any researcher or vendor who has ever worked in the field, some of the underlying foundations of the DNS protocol are inherently weak, especially what they call the “last mile” - or the part of the internet connection between the client and the ISP. To address this, OpenDNS released a preview of...

What Happens When Data is Separated from the Systems and Applications that the Data Owners control?Cloud computing, virtualization, mobile devices, and social networking are consistently listed in the top concerns for CISOs in 2011. And rightly so: the primary line of defense for our information assets had been the Internet perimeter and conclaves. As a consequence, our main security strategies have focused on the network and hosts rather than the data.

Federal Government Releases "Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program"The Office of Science and Technology Policy (OSTP) released a report detailing the roadmap of priorities for government agencies that sponsor research and development in cyber-security.

Open source giant Red Hat, today announced the availability of Red Hat Enterprise Linux 6.2, the latest version of its enterprise operating system that brings significant improvements in resource management, high availability, and new features aimed at storage and file system performance and identity management.

Software-as-a-Service (SaaS) security solutions vendor Qualys, today announced updates to its QualysGuard Web Application Scanning suite, including the ability to integrate with Selenium, the open source tool that lets users to record their browser actions and save them as scripts that can then be replayed at a later time.

Security pioneer RSA, The Security Division of EMC, is celebrating today as it announces the 500,000th online attack shut down on behalf its customers. In its seventh year of offering online anti-fraud services, the company estimates that its RSA FraudAction service has prevented US$7.5 billion in potential losses due to fraud, mainly through its anti-phishing and anti-Trojan services.

Domain names are used a trillion times every day. They're part of the plumbing of the Internet and, like regular plumbing, you don't need to worry too much about how it works…it just does. Until it doesn't. The world of domain names is complex, governed by multiple layers of technological and contractual relationships. Sometimes it can be confusing. Here are five facts about domains names that you may not be aware of, but could affect your business.If you Forget to...

Security firms Symantec and PhoneFactor separately unveiled solutions today to help organizations deal with the challenges posed by the influx of mobile devices in the workplace. For Symantec, the solutions took the form of the new Symantec Mobile Security Assessment Suite, a set of services aimed at providing enterprises strategic recommendations for securing mobile devices and applications.

Facebook Attack Attempts to Infect PCs with the Dorkbot Worm Through the Social Network’s Chat System. A new Facebook worm has its eyes on Windows PCs.This time, the idea is to infect users with the Dorkbot worm. Often spread via instant messaging, removable drives and compromised Websites, the Dorkbot worm opens a backdoor and allows remote access to an infected computer.

U.S. military sources told Fox News on Monday that Iran may be in possession of a drone whose stealth technology is the same as the drone used to monitor the compound during the raid that killed Usama bin Laden. According to Fox News, Military sources confirmed that the Iranians have the RQ-170 drone.

Defense contractor Raytheon has acquired Madison, Alabama based Pikewerks, a privately held cyber security company that serves the federal government, research organizations, and critical industry partners.The acquisition will extend Raytheon's capabilities to help its customers defend against cybersecurity threats, mainly for its intelligence community, Department of Defense and commercial organization customers.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.