June 26, 2008
Data loss and latop theft increase
By Grant Draper
Absolute Software, a laptop tracking and recovery firm, has offered its advice on security as the number of cases relating to data loss, and laptop theft, increase.
The fact that laptops continue to fall in price for a basic model is irrelevant, as the data stored on them becomes ever more valuable, with the average laptop [...]
May 28, 2008
Directors’ guide to information risk
By Grant Draper
A three way partnership in the form of IAAC, BT and the Information Security Awareness Forum (ISAF), will distribute directors’ guides on information security risk prevention.
The guides include a wealth of knowledge, almost a summary of the information held between its members.
The Directors’ Guides are the result of the distillation of this knowledge, which is [...]
May 16, 2008
Users hit by phony MP3 files
By Dave Nixon
Adware peddlers have found a novel method to deceive users, said security vendor McAfee.
The company stated that it has seen a vast increase in fake MP3 file distribution on peer-to-peer networks.
Even though the files have names that make them appear as audio recordings, they are essentially Trojan horse programs that attempt to install an [...]
May 16, 2008
Microsoft to release four new patches
By Dave Nixon
Microsoft is scheduled to fix serious defects in its Word, Publisher and Jet database software this week.
Additionally the software vendor aims to release a lesser-critical update for its anti-virus products, addressing a defect that attackers could leverage to initiate a denial of service (DoS) attack against products such as Windows Live OneCare and Microsoft Forefront [...]
April 28, 2008
Apple improves software download utility for Windows with version 2.1
By Janine de Blois
Apple has responded to critism of its “Software Update” tool for Windows. In version 2.1 users now see a split window with two separate lists for updates and new software.
The complaint from many security (and other) sources had been that users of the old version often ended up with new software they had not [...]
April 17, 2008
Only 21% Reveal Passwords
By Lashan Clarke
A wise person will be protective of their password in the times we live in. However, current research has shown that not everyone is as wise to protect their personal information.
Using a survey conducted outside of Liverpool Street Station, the results showed that a little more than twenty percent of people gave up their [...]
April 11, 2008
Adobe Issues Flash Update
By Lashan Clarke
After the recent fall of the Windows Vista laptop using a security hole in Adobe Flash, Adobe issued a new update to correct the hole within the software.
This update was issued to correct the compromise that was realised at the CanSecWest Conference. The new update was also issued to correct other problems within the [...]
April 9, 2008
Microsoft Releases Plans To Make Hardware and Software More Secure
By Lashan Clarke
Information released by Microsoft at the RSA Security Conference highlighted what the company plans to do to protect its customers from malicious software.
Microsoft stated that it will do its best to increase the security levels of its software, and provide a more private environment for anyone using its software to access to the Internet. [...]
April 6, 2008
Intel to launch laptop anti-theft technology
By Dave Nixon
Intel is looking to release an anti-theft technology for laptops, even though the company is keeping quiet about the exact details.
The new competence, which will be called Intel Anti-Theft Technology, is to be added to Intel’s Active Management Technology, part of Centrino vPro and allows IT managers to remotely access and configure computers.
In the event [...]
April 6, 2008
Microsoft warns April will be big month for patches
By Dave Nixon
Microsoft is to release eight security updates next week, five of which are rated vital by the software vendor.
The critical patches affect Windows, the VBScript programming software, Microsoft Project and Internet Explorer, which will get two updates. They will be released as part of the company’s monthly software update series, which provides security updates on [...]
April 6, 2008
Opera patches ’severe’ attack defects
By Dave Nixon
Opera has warned of two severe flaws in its browser, which could let attackers occupy a system via straightforward elements embedded in web pages.
The first bug involves Opera’s management of news feed sources.
When the browser encounters a feed source, it usually triggers a user prompt, but a specially crafted source could be exploited to cause [...]
March 31, 2008
Ubuntu Linux stands through hacking contest
By Janine de Blois
The CanSecWest contest in Vancouver has left only the Ubuntu Linux undefeated, though several attempts to crack it were made.
On the final day of the contest Shane Macaulay spent almost four hours attempting to use his exploit of a previously unknown flaw in Adobe Flash.
He alternated his attempts between Vista and [...]
March 30, 2008
Apple loses three-way hacking contest
By Dave Nixon
An Apple Mac was the first casualty in a hacker shoot-out to establish which operating system is the most secure.
A former US National Security Agency employee has won $10,000 for breaking into a MacBook Air at CanSecWest security conference’s PWN 2 OWN hacking contest. The MacBook was up against Linux and Vista PCs which [...]
March 28, 2008
Google Calendar used to deliver spam
By Isabelle Chaize
According to Trend Micro, the Google Calendar tool is being used by spammers to get round spam filters, which is the first time they have seen such a mechanism being used.
Trend Micro have been tracking spam in all its different forms over the last 12 months, and have discovered this new method for delivering [...]
March 28, 2008
Mac Os X First To Go Down
By Lashan Clarke
The first attempt to attack a computer during the PWN2OWN hacking competition was successful on the Apple Mac operating system. The analyst who was successful in the security breach was able to win the computer and $10,000 for his efforts. The security breach was completed against the Safari browser.
The breach carried out by [...]
March 28, 2008
Finjan discovers website offering volume purchase of stolen credit cards
By Janine de Blois
“If further proof were needed that there is a very serious problem facing the card acceptance and processing industry, this is it,” said Yuval Ben-Itzhak, chief technology officer at Finjan.
“Prices are segmented depending on whether a card is a Classic Visa or MasterCard, a premium account such as a Gold, Platinum or Business/Corporate [...]
March 27, 2008
Slow Day At PWN2OWN Contest
By Lashan Clarke
Security experts and hackers, gathered at the Marriott Renaissance Hotel to take part in a hacking contest. However, during day one the three laptop computers, where waiting to be tampered with. This yearly contest is known as the creative PWN2OWN Hacking Contest, with prices ranging from computers to cash for the best attack.
However, during [...]
March 26, 2008
Word users have been targeted in attacks due to vulnerability in Microsoft Jet Database Engine
By Janine de Blois
Microsoft is investigating attacks which have been found using a vulnerability in Microsoft Jet Database Engine and exploited through MS Word.
The attacks have been targeted and require the user to open a corrupted MS Word file either via an email link , web site or similar source.
If successful, it would allow [...]
March 22, 2008
Microsoft acquires security company
By Dave Nixon
Microsoft has bought security specialist Komoku, a developer of rootkit discovery products.
The company aims to include Komoku’s technology into its Forefront and Windows Live OneCare products. Forefront is Microsoft’s collection of enterprise security software that incorporates malware protection for PCs, security tools for Exchange and SharePoint servers, and gateways that secure remote access to [...]
March 21, 2008
Highly critical patches released for Kerberos 5-multiple vulnerabilities
By Janine de Blois
Kerberos credits Jeff Altman of Secure Endpoints, and Red Hat Security Response Team for discovering critical vulnerabilities in various versions of Kerberos 5. The bugs may cause DoS (Denial of Service), or otherwise compromise vulnerable systems.
The first problem is the Key Distribution Center (KDC). Incoming krb4 requests can be exploited to crash [...]

