Archive for the ‘Security’ Category

iPhone vulnerability leaves your data wide open, even when using a PIN

If you feel like going through the process of typing in your PIN every time you unlock your iPhone is worth it thanks to the unconquerable security it implies, you might want to read this report from Bernd Marienfeldt about the chosen one’s security model. Yes, a PIN will keep casual users from picking up [...]

Car hackers can kill brakes, engine, and more

University researchers have taken a close look at the computer systems used to run today’s cars and discovered new ways to hack into them, sometimes with frightening results. In a paper set to be presented at a security conference in Oakland, California, next week, the security researchers say that by connecting to a standard diagnostic [...]

Report: Google Hackers Stole Source Code of Global Password System

The hackers who breached Google’s network last year were able to nab the source code for the company’s global password system, according to The New York Times. The single sign-on password system, which Google referred to internally as “Gaia,” allows users to log into a constellation of services the company offers — Gmail, search, business [...]

Rethinking security

Ask any IT manager, business leader or regulator and they will tell you that IT security is important – that much goes without saying. As the chart below shows, for many professionals the role of security in IT is now seen to be a fundamental part of delivering day to day IT service to users, [...]

Symantec spends $370 mln on encryption companies

BOSTON, April 29 (Reuters) – Symantec Corp (SYMC.O), the world’s biggest maker of computer security software, has agreed to pay $370 million to buy two makers of technology that businesses use to scramble sensitive corporate data. The security giant said on Thursday that it would pay $300 million for privately held PGP Corp and $70 [...]

Fireshark plugin decodes the malicious Web

A computer security researcher has released a plugin for Firefox that provides a wealth of data on Web sites that may have been compromised with malicious code. The plugin, called Fireshark, was released on Wednesday at the Black Hat conference. The open-source free tool is designed to address the shortcomings in other programs used to [...]

Researchers to Demonstrate Database Man-in-the-Middle Attacks at Black Hat

Two researchers from Trustwave will demonstrate how to use man-in-the-middle attacks against Oracle databases to steal user credentials and take over sessions at Black Hat Europe next week. Two researchers from Trustwave will demonstrate how a man-in-the-middle attack on Oracle databases can be leveraged to swipe user credentials and hijack sessions at the upcoming Black [...]

Study calls for more C-level involvement in cybersecurity

Organizations with top executives who aren’t involved in cybersecurity decisions face a serious problem — a major hit to their bottom lines, according to a report released Wednesday. “Many organizations see cybersecurity as solely an IT problem,” said Karen Hughes, director of homeland security standards programs at the American National Standards Institute (ANSI), one of [...]

Free app makes paid web scanners dead in the water

Google’s upgraded version of its automated Web application scanner, SkipFish, has received glowing reviews from local security experts. The free tool designed by Google software engineer Michal Zalewski, and launched late last week, scans for web application vulnerabilities. Penetration testing firm HackLabs director Chris Gatford said the tool is “blazingly fast” and accurate. The revamped [...]

Apple delivers record monster security update

Apple today patched 92 vulnerabilities, a third of them critical, in a record update to its Leopard and Snow Leopard operating systems. Security Update 2010-002 plugged 92 holes in the client and server editions of Mac OS X 10.5 and Mac OS X 10.6, breaking a record that has stood since March 2008 . The [...]