Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Kaspersky Lab has released what it declared as the most significant “business related” products it has released in four years. Officially launched on Thursday, Kaspersky Endpoint Security 8 for Windows and Kaspersky Security Center include new multi-layer anti-malware protection, powered by Kaspersky’s intelligence network.

Three unencrypted backup tapes containing sensitive personal data have been reported missing by Nemours, a children's health care services provider.The tapes in question were reported missing from a facility in Wilmington, Delaware on September 8, 2011. The company believes they have been removed around August 10, 2011 during a renovation project.

Baltimore-based data protection vendor SafeNet, said on Friday that it has received baseline approval from the US Government for its new MDeX system.MDeX, or Multi-Domain eXchange, was designed to address cross domain data sharing between government organizations. Earning a Unified Cross Domain Management Office (UCDMO) Cross Domain Inventory, Version 4.0 baseline, means that SafeNet is now free to offer MDeX to departments such as Homeland Security, and other intelligence agencies.

The recent and ongoing Occupying Wall Street rally is an interesting and refreshing exercise in US democracy at its best. Starting out with just 200 protesters in mid-September, the New York City rally has grown to thousands of activists, with similar protests in 30 cities including Chicago, Boston and Denver. Initially scoffed at as being "leaderless" and "directionless", the Occupying Wall Street rally appears to be moving towards focusing on defining such lofty demands as ending the death penalty, ending...

After a relatively quiet Patch Tuesday in September, Microsoft is releasing fixes for 23 separate vulnerabilities in its security update next week.The patches will be spread across eight bulletins – two rated ‘Critical’, six designated ‘Important’ – and will touch Internet Explorer, Microsoft Windows, Microsoft Forefront Unified Access Gateway (UAG), Microsoft Host Integration Server, the .NET Framework and Silverlight.

Developers Leave Debug Tool Open for The World to Use, Including AttackersDevelopers from American Express have made somewhat of a big mistake recently, leaving an administration panel for Web site debugging wide open for anyone to access, providing a potential tool and avenue for attackers to target AMEX customers. (Update: Amex appears to finally have closed access to the admin panel within the past hour, as of 11:15AM EST on Oct 6.)

Before there was concern over VM stall, there was that of VM sprawl.VM sprawl had organizations worrying that so many virtual machines would be spun up (thanks to the ease of deploying them) that not only would management become an issue, but so, too, would performance, security, and IT staffing.

Update: NetQin Mobile reached out to SecurityWeek to let us know that they had previously identified the same malware under the name AnserverBot on September 19th. Dr. XuXian Jiang, Chief Scientist at NetQin’s US Security Research Center, offers a detailed report on how the malware works. - Editor

According to a recent report from the Government Accountability Office, despite efforts to implement stronger cybersecurity controls, several federal agencies remain in a weakened state. Since 2006, security incident reports have risen over 650-percent.

New Release Helps Protect Sensitive Data, Brings Centralized Management of Enterprise Wide Database Security MeasuresOn Monday at Oracle Open World, Oracle’s giant customer conference taking place this week in San Francisco, Oracle unveiled new and improved database security features in Oracle Enterprise Manager 12c.

McAfee today announced that it has agreed to acquire NitroSecurity, a privately held provider of high-performance security information and event management (SIEM) solutions.The company’s founders and roots come from the U.S. Department of Energy’s Idaho National Laboratory, giving it extensive experience with critical infrastructures in the energy sector, creating a sweet spot for the Portsmouth, NH-based company in a sector that has come into the spotlight following Stuxnet and a general rise in concern over critical infrastructure security.

SIEM vendors are all jumping on the Security Intelligence tag line, but what does it really mean? The bad guys are getting more sophisticated and the quality and breadth of intelligence is crucial to early identification and thwarting attacks. Can SIEM bring the analog of human intelligence (aka, espionage) to cyber threats and the security visibility of business intelligence to the executive boardroom?Defining the threat landscape:

VASCO Data Security, parent of recently “hacked out of business” Certificate Authority (CA), DigiNotar, has shared additional information on the expected losses surrounding the recent cyber attack that forced the company into bankruptcy.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.