Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

Author: admini

Patching window is getting shorter

Posted on March 8, 2006December 30, 2021 by admini

A proof-of-concept is a first version of malicious code which hackers publish on the internet to show how certain vulnerabilities can be exploited. Worryingly, 12.5% of the threats had code included in disclosure.

In addition, 50% of vulnerabilities had either an exploit and/or proof-of-concept code surface within one week.

http://www.it-observer.com/news/5828/patching_window_getting_shorter/

Read more

Second Phone Data Privacy Bill Approved

Posted on March 8, 2006December 30, 2021 by admini

“Living in the information age can be a boon to our prosperity and a bane to our privacy, but nothing says we have to take the bad along with the good,” House Commerce Committee Chairman Joe Barton (R-Texas) said.

Under the Telecommunications Act of 1996, telephone carriers are obligated to protect the Customer Proprietary Network Information (CPNI) of consumers, but last summer the privacy watchdog Electronic Privacy Information Center (EPIC) complained to the FCC that confidential phone records are readily available for sale on the Internet. The telephone carriers say their customer service representatives are being tricked out of the information through pretexting.

http://www.internetnews.com/bus-news/article.php/3590151

Read more

10 of the BEST for SECURITY

Posted on March 8, 2006December 30, 2021 by admini

In a world where the spectre of the so-called “zero day attack” (in which a security vulnerability is exploited “in the wild” before there is time to report it to the rest of the security community) looms ever larger, and when network linkages between entities are springing up like bacteria in a Petri dish, American Water sees network intrusion detection as one of its most valuable investments. “We have a full suite of defence in-depth architecture and now information security. Network intrusion detection forms the core of that,” Larson says.

So does around-the-clock coverage – the only approach that gives American Water the flexibility to respond to a zero day attack. Larson says as the time line – from vulnerability to disclosure, to widespread malicious software distribution – decreases, the importance of being flexible with your apparatus continues to grow. And that’s why he believes network intrusion detection is one of the “most valuable investments that we have in the estate”.

New network linkages are proliferating as companies outsource operational aspects of their businesses – from design and manufacture to logistics and customer service – to partners along their value chains.

US IT research firm Aberdeen Group points out that every one of those partnership, outsourced business arrangements and reverse business functions places yet more strain on an enterprise’s ability to verify and preserve the sanctity of the underlying networks and computing infrastructures employed to advance missions and business functions. “The ability to maintain auditable control and security for these networks and systems is becoming more difficult and more important as external auditors expand the purview of their testing and are increasingly using automated test tools to root out problems,” Aberdeen reports.

“It’s no small wonder that Aberdeen’s research shows that best practices for security in an environment involving less direct control means firms are having to dramatically improve procedures to verify the sanctity of the interconnected networks, systems, applications and underlying data throughout their value chains to operate their missions and business functions.” As enterprises continue to automate processes and extend beyond traditional boundaries, they need to ensure that a strong security awareness program is in place.

It is a challenge companies have known about for the past 25 years, which has been important for more than five years, and critical during the past three, notes Greg Wood, the man who was in charge of securing Microsoft’s electronic environments for more than three years, and now CTO for biometric security software company BioPassword. “The challenge is, how do you correct 25 years of history in a short period of time, and that’s the challenge that people have today. So you have networks that are built based on little security measures that have been built over 25 years and all of a sudden you have eight months or nine months or a year to fix them. And that’s why they pick the most important holes and fix them first to recognize that it will take many years and huge investment to catch up,” Wood says.

“Security vulnerabilities are like the Florida fire ant – you can’t kill them, all you can do is maintain your garden better than your neighbour so they choose to infest his yard instead of yours,” says Dr James Whittaker, chief security strategist and founder with Security Innovation. “Companies without clear and effective security strategies will draw the hackers to themselves and away from the companies doing a better job.”

Yet according to The Global State of Information Security 2005, a worldwide study by CIO magazine and PricewaterhouseCoopers (PwC), most organizations are just holding their ground, although the third annual edition of the survey reports incremental improvement in the tactical battle to react to and fight off security incidents.

CSO magazine (Australia) says the data shows a notable lack of focus on actions and strategies that could prevent these incidents in the first place, a “remarkable ambivalence” among respondents about compliance with government regulations, a clear lack of risk management discipline, and a continuing inability to create actionable security intelligence out of mountains of security data. Just 37 percent of respondents reported that they had an information security strategy – and only 24 percent of the rest say that creating one is in the plans for next year.

With increasingly serious, complex, targeted and damaging threats continuously emerging, that is not a good thing. “When you spend all that time fighting fires, you don’t even have time to come up with the new ways to build things so they don’t burn down,” says Mark Lobel, a security-focused partner with PwC. “Right now, there’s hardly a fire code.” Lobel compares the global state of information security to Chicago right before the great fire. “Some folks were well-protected and others weren’t,” he says, but when the ones that were not protected began to burn, the ones that were protected caught fire too.

Top to Bottom Best Practice Aberdeen says best practices for governing security span a wide range of activities, from board involvement to what happens daily within the enabling technologies that support an organization’s missions. In between, security is fundamentally about how people interact with information systems. More specifically, Aberdeen research shows that firms operating at best-in-class levels emphasize repeatable procedures, effective management of data and knowledge, an efficient and transparent organizational structure and strategy, and enabling automation technologies that assist with responses to business pressures. “Most share this sentiment expressed by one respondent,” Aberdeen says. “‘There is no such thing as a silver bullet or a single source for security, and there never will be.’ But most organizations automate when speed, business cycles or business seasonality force them. Many of the firms humbly admit their security programs still have a long way to go before reaching their full promise.” Aberdeen emphasizes that enterprises must maintain control and security of networks and systems. “Enterprises are struggling with trying to balance flexibility and agility with managing the risk that comes with unfettered access to information among employees, customers, business partners and suppliers.”

CIO magazine polled practitioners and analysts for their own list of network security best practices.

1. Assess Your Risk
2.Define Your Boundaries
3.Rely on Multiple Solutions
4.Market Your Program
5.Take Your Measure
6.Set Some Standards
7.Train and Mentor
8.Use Biometrics

http://www.cio.com.au/index.php/id;1449363213;fp;16;fpid;0

Read more

Computer hacking laws discussed in Parliament

Posted on March 7, 2006December 30, 2021 by admini

Home secretary Charles Clarke outlined details of the legislation, including an update of the 1990 Computer Misuse Act.

By amending section three of the CMA to explicitly make denial of service attacks a criminal offence, the UK government also plans to ratify its position as a member of the Council of Europe’s cyber crime convention, which sets out a common international approach to prosecuting hackers, virus writers and internet extortionists.

http://www.computing.co.uk/computing/news/2151493/computer-hacking-laws-discussed

Read more

IT security top concern for fed CIOs

Posted on March 7, 2006December 30, 2021 by admini

While some high-profile agencies have addressed privacy issues, “privacy is a much less mature concern in government” than security, Wohlleben said.

The 16th annual ITAA survey of U.S. government CIOs included interviews with 36 CIOs or assistant CIOs and three government oversight officials between August and December 2005.

In addition to security concerns, federal CIOs also identified as key priorities standardizing and consolidating their IT infrastructure, improving project management, and examining ways to use managed services from outside vendors, according to the survey.

One general theme in the interviews was concern about executing long-term plans, Wohlleben said. While federal CIOs see themselves as agents of change in coming years, shifting priorities within government can make it difficult to carry through long-term IT plans, he said. They’re multiyear implementations in a political environment where laws are being changed, in a budgetary environment where budgets are being changed.”

http://www.infoworld.com/article/06/03/07/76192_HNsecuritytopgovcio_1.html

Read more

Black market thrives on vulnerability trading

Posted on March 7, 2006December 30, 2021 by admini

China saw the largest increase in botnet activity with a 37 per cent growth of botnet infected systems and a 153 per cent increase in attacks originating there. That’s not to say China is full of criminals. But with a well-documented history of software pirating, it stands to reason that many systems hooking up to the Net in the People’s Republic aren’t patched properly and vulnerable to infection.

With a population of 1.3bn, the 94m Chinese who are online represents a point right at the bottom of the S-curve expected as the Internet revolution takes off there. If the black market in vulnerability trading increases, as Symantec predicts, massive numbers of systems coming online in China will prove an ideal vector for attack.

http://www.pcpro.co.uk/news/84523/black-market-thrives-on-vulnerability-trading.html

Read more

Posts navigation

  • Previous
  • 1
  • …
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • …
  • 421
  • Next

Recent Posts

  • AI/ML News – 2024-04-14
  • Incident Response and Security Operations -2024-04-14
  • CSO News – 2024-04-15
  • IT Security News – 2023-09-25
  • IT Security News – 2023-09-20

Archives

  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2025 CyberSecurity Institute | Powered by Superbs Personal Blog theme