Showing posts with label Security - Information Technology. Show all posts
Showing posts with label Security - Information Technology. Show all posts

Wednesday, October 15, 2008

[USA] Guide to Bluetooth Security: Recommendations of the National Institute of Standards and Technology / National Institute for Standards and Technology, September 2008
PDF - http://csrc.nist.gov/publications/nistpubs/800-121/SP800-121.pdf

Wednesday, September 24, 2008

Striking at the weakest point / The Times, August 23, 2008
http://www.timesonline.co.uk/tol/news/uk/crime/article4592676.ece
"The prospect of “cyberwar” - the use of computers to carry out attacks on either government or commercial networks – is increasingly real. There are two main threats: industrial espionage, where hackers based in foreign countries attempt to break into networks to steal company secrets, and attacks designed to cause widespread social disruption. Terrorists using computer-hacking techniques are more likely to be intent on bringing down the networks that run essential services, including power, water and other utilities, as well as banking and telecommunications systems. All of these rely on interconnected computer networks, which, if not protected, are prone to being infiltrated by hackers."

Monday, September 22, 2008

Critical Infrastructure Protection: DHS Needs to Fully Address Lessons Learned from Its First Cyber Storm Exercise / Government Accountability Office , 9 September 2008
PDF - http://www.gao.gov/new.items/d08825.pdf
Securing the world against terrorists, scammers, and thugs: A day in the life of a cyber gumshoe / The Register, 17 September 2008
http://www.theregister.co.uk/2008/09/17/cyber_crime_fighting/
Watchdog: US Computer Emergency Readiness Team isn't ready / The Register, 17 September 2008
http://www.theregister.co.uk/2008/09/17/gao_criticizes_us_cert/
"A government watchdog agency has taken the US Department of Homeland Security to task for failing to adequately protect the nation's critical computer networks in a report that singles out the US Computer Emergency Readiness Team."

Monday, September 15, 2008

Off switch could protect your smart-card secrets
New Scientist, 8 September 2008 , Issue 2672
http://technology.newscientist.com/channel/tech/mg19926726.300-off-switch-could-protect-your-smartcard-secrets.html?feedId=online-news_rss20
"In the last couple of months, a clutch of computer security experts have demonstrated just how easily the information stored in electronic passports can be cloned or manipulated without the owner's knowledge."
[Sub required]

Wednesday, August 13, 2008

Personal Internet Security: Follow-up: Science and Technology Committee
4th Report of Session 2007–08
/ TOS, 8 July 2008
http://www.publications.parliament.uk/pa/ld200708/ldselect/ldsctech/131/131.pdf
HL Paper 131
Top IT cops say lack of authority, resources undermine security / GovExec.com, 13 August 2008
http://www.govexec.com/story_page.cfm?articleid=40700&dcn=e_hsw
"To understand what it's like to be a federal chief information security officer, consider Larry Ruffin. As CISO at the Interior Department, his job could be described as having little to do with being a chief and not much more about security."
Ex-White House security adviser to head up ISF / vnunet.com, 12 August 2008
http://www.vnunet.com/itweek/news/2223743/schmidt-head-isf
"Former White House IT security advisor Howard Schmidt has been appointed as the first president of the not-for-profit Information Security Forum (ISF).
The ISF is an international association of around 300 of the world's largest public and private sector organisations, which was set up to conduct business-oriented security research and develop best-practice methodologies, processes and tools."
Converged threats plague firms / vnunet, 12 August 2008
http://www.vnunet.com/vnunet/news/2223765/converged-threats-plague-firms
"Firms are facing an increasing risk from converged attacks, as hackers look to new ways to bypass traditional security measures, according to new reports."
Marshal Security Threats: Email and Web Threats
/ Marshal, July 2008
PDF - http://www.marshal.com/newsimages/trace/Marshal_Trace_Report-July_2008.pdf
Secure Computing Internet Threats Report / Secure computing
http://www.securecomputing.com/pdf/SCC-InternetThrtRprt-July08.pdf

Monday, August 11, 2008

Waging war on the web's bad guys: Inside Symantec's security operations centre / silicon.com, 21 July 2008
http://software.silicon.com/security/0,39024655,39261455-1,00.htm
UK at risk from repeat of US hack attack? / silicon.com, 6 August 2008
http://www.silicon.com/retailandleisure/0,3800011842,39268402,00.htm
"UK shoppers credit card details could be at risk from the same wireless hack technique that snared more than 40 million people's details in the US, according to security experts."
GPS tracking slapped on laptop recovery service / out-law.com, 8 August 2008
http://www.out-law.com//default.aspx?page=9334
"The availability of geolocation tracking for Computrace will allow asset managers to track GPS-enabled laptops to within ten metres and view their location using Google Maps technology. The technology will also speed recovery of missing or stolen computers, being easier to use than previous IP address-based tracking technology."
Surfing Google may be harmful to your security / The Register, 9 August 2008
http://www.theregister.co.uk/2008/08/09/google_gadget_threats/
"A well-known researcher specializing in website security has strongly criticized safety on Google, arguing the world's biggest search engine needlessly puts its millions of users at risk.
"Google is and will be and always has been vulnerable," Robert Hansen, CEO of secTheory, told a standing-room-only audience at the Defcon security conference in Las Vegas. "They haven't been open with consumers. Ultimately, this all comes down the the fact that they just want to track you guys.""
Drive-by download attacks menace UK.gov / The Register, 23 July 2008
http://www.theregister.co.uk/2008/07/23/drive_by_download_asprox_menace/
"Malicious downloads from compromised websites have replaced infected email attachment as the favourite tactic for malware authors. During the first half of 2008, web security firm Sophos detected 16,173 malicious webpages every day – or one every five seconds. The rate at which infected websites spring up is three times faster than during 2007."
FBI Warns of Storm Worm Virus / ResourceShelf, 3 August 2008
http://www.resourceshelf.com/2008/08/03/fbi-warns-of-storm-worm-virus/
"The FBI and its partner, the Internet Crime Complaint Center (IC3), have received reports of recent spam e-mails spreading the Storm Worm malicious software, known as malware. These e-mails, which contain the phrase “F.B.I. vs. facebook,” direct e-mail recipients to click on a link to view an article about the FBI and Facebook, a popular social networking website. The Storm Worm virus has also been spread in the past in e-mails advertising a holiday e-card link. Clicking on the link downloads malware onto the Internet connected device, causing it to become infected with the virus and part of the Storm Worm botnet."

Wednesday, July 30, 2008

Risk at home: privacy and security risks in telecommuting / Ernst and Young, July 2008
PDF - http://www.ey.com/Global/assets.nsf/US/Risk_at_home/$file/Riskathome.pdf
"Personal and private information related to both employees and their employers may be compromised by telecommuting staff if privacy risks are not dealt with effectively. This is according to a new report from Ernst & Young and the Center for Democracy and Technology. “Risk at home: privacy and security risks in telecommuting” identifies such issues in work-from-home arrangements. Read about effective approaches — as well as areas in need of improvement in how organizations protect personal and other sensitive company-related information."

Tuesday, July 29, 2008

Insiders are a bigger security fear than hackers / Techworld, 18 July 2008
http://www.techworld.com/security/news/index.cfm?RSS&NewsID=102184
"IT security executives are starting to face up to the realisation that the biggest threat they face comes from internal security attacks and data breaches."
Huge rise in malware during first half of 2008, study finds / Techworld, 18 July 2008
http://www.techworld.com/security/news/index.cfm?RSS&NewsID=102180
"Malware has risen by a staggering 278 percent in the first half of 2008, thanks in part to the large number of websites comprised last month, so says a new study by ScanSafe. And it warns that things are only going to get worse, especially after Dan Kaminsky goes public with details about his 20 year-old DNS vulnerability."

Monday, July 28, 2008

Oyster hack will be published, rules Dutch court / out-law.com, 22 July 2008
http://www.out-law.com//default.aspx?page=9279
"A team of Dutch researchers has been given permission to publish details of how it cracked the security on which the pre-payment card for London's transport network is based."