Make it your homepage

Add to favorites

Site map

The BEZPEKA portal - all about IT security



Navigation

Microsoft Certified Partner


Subscription to newsletters

Partners

Безопасность для всех CCTV Ukraine
Русские времена. Язык - душа народа.

News for 11 November 2008 Year

  • 22:46 Article: Trust No One
  • Its easy to say what were all securing our systems and data against. But isnt easy to say exactly who we need to secure against, nor who presents the biggest threat to our business. Certainly, the ... >>>

  • 22:36 Security World: Yoggie opens up its miniature hardware firewall
  • Yoggie Security Systems launched its new Open Firewall Pico and Open Firewall SOHO, the first open hardware firewalls based on its Gatekeeper technology. The Open Firewall products are extremely ... >>>

  • 21:31 MS Patch Tuesday: Critical Windows, Office flaws fixed
  • Microsoft’s scheduled batch of patches for November crossed the wires today with fixes for at least four documented vulnerabilities affecting millions of Windows and Office users. As previously reported, the company released two security bulletins — one rated critical, one rated important — with fixes for flaws that could lead to remote code execution attacks. The [...]
    >>>

  • 21:22 BBC hit by a DDoS attack
  • The British Broadcasting Corporation (bbc.co.uk) was hit by a DDoS attack on Thursday, according to a statement sent to the Inquirer : “In a statement to the INQ, the BBC said the attack originated in a number of different countries but didn’t specify which. When the Beeb’s techies blocked international access to a limited subset of [...]
    >>>

  • 20:13 Profitability of spam finally measured
  • Researchers at UCSD have determined the return on investment for spam generated by the Storm botnet. While the per-message response rate is astonishingly low, it is sufficient for a spammer to generate a profit. At this year’s ACM Conference on Computer and Communication Security, Stefan Savage, Vern Paxson and crew presented a paper that measures [...]
    >>>

  • 19:50 AVG and Rising signatures update detects Windows files as malware
  • Yesterday, a signatures update pushed by AVG falsely labeled a critical Windows file as a banker malware, prompting the company to quickly fix the issue and issue a workaround, following end users complaints at its support forums. AVG’s false positive causing downtime for Windows users is happening a week after Rising antivirus apologized to its customers [...]
    >>>

  • 19:50 November 2008 Bulletin Release
  • Hi! This is Tami Gallupe, MSRC Release Manager and I just wanted to give you an update on the two bulletins we released today:

                     MS08-068: Vulnerability in SMB Could Allow Remote Code Execution (957097). This has a severity rating of Important

                     MS08-069: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218). This has a severity rating of Critical.

    This information, and more, is also documented in the Microsoft Security Bulletin Summary for November 2008, and you can also read this months Security Vulnerability Research & Defense blog at http://blogs.technet.com/swi/ where the team dives into more technical details about this months release. 

    I hope you will also join us for the webcast that starts tomorrow (Wednesday, November 12th) at 11:00 AM PST.  I value this event as it gives us a chance to hear from you, to take your questions and answer them live, on the air. Click here to register for TechNet Webcast: Information About Microsoft November Security Bulletins.  We look forward to hearing from you tomorrow.

    Cheers!

    Tami

    *This posting is provided "AS IS" with no warranties, and confers no rights*

    >>>

  • 19:45 Security World: Critical infrastructure is not prepared for cyber attacks
  • Secure Computing announced the results of a study conducted during August and September 2008 in the US, Canada and Europe. The study surveyed 199 international security experts and other "industry ins... >>>

  • 17:06 All the stuff I dont have time to blog about
  • We’re all busy and the more stories I accumulate in my browser, the less time it seems I have to do anything with them.  So in order to clear out some of the open tabs, here’s some of the stories I’ve been reading lately: Express Scritps warns of potential large data breach tied to threat - [...] >>>

  • 16:18 Targeted attacks to add to ISP woes
  • As if brute-force DDoS assaults weren't enough

    Hacking attacks are growing more sophisticated and more prevalent, with hard-pressed ISPs facing a wider range of threats.

    >>>

  • 15:59 Lads from Lagos target Facebook
  • Beware 'friends' bearing begging bowl

    The ever-resourceful Lads from Lagos have been hanging around Facebook hoping to extract a few bucks from the unwary, the Sydney Morning Herald reports.

    >>>

  • 14:36 AVG slaps Trojan label on core Windows file
  • Second false alarm creates consternation

    Some users of AVG were left with unusable Windows systems after the popular AVG security scanner software slapped a Trojan warning on a core Windows component.

    >>>

  • 12:59 US Navy hacker avoids Romanian jail
  • Sharp contrast with McKinnon extradition saga

    A Romanian hacker who broke into systems run by the US Navy, NASA and the Department of Energy has avoided a custodial sentence in a trial at home but may still face extradition to the US.

    >>>

  • 07:42 Off the wire: Former inmate hacked prison computer to access prison management program
  • A former inmate of the Plymouth County Correctional Facility in Plymouth, Massachusetts was arrested late yesterday in North Carolina, on an Indictment charging him with damage to the prisons compute... >>>

  • 07:40 Security World: Automated information management in cloud storage environments with EMC Atmos
  • EMC announced its first cloud infrastructure offering, EMC Atmos, the first multi-petabyte information management solution designed to help customers automatically manage and optimize the distribution... >>>

  • 07:35 Security World: Meru Networks brings virtualization to wireless LANs
  • Meru Networks has brought the techniques of virtualization to its enterprise wireless LAN products, allowing an optimization of radio frequency (RF) resources that raises WLAN performance and reliabil... >>>

  • 04:39 What would you ask the Department of Homeland Security Secretary?
  • Michael Chertoff, the Secretary of the Department of Homeland Security, will be here in California tomorrow.  He’s hosting a blogger roundtable on Cybersecurity and I’m one of an unknown number of security bloggers who’ll be attending the event and talking to Mr. Chertoff face to face.  Quite frankly I was surprised that the Department of [...] >>>

  • 02:24 Denial, exposure and online security
  • Five top tips

    Web applications have huge attack surfaces. Most sites have hundreds of URLs, and each function has plenty of parameters, form fields, cookies, and headers for attackers to play with.

    >>>

  • 02:00 Reading a Letter from the Envelope it Was In
  • Fascinating:

    Paul Kelly and colleagues at Loughborough University found that a disulfur dinitride (S2N2) polymer turned exposed fingerprints brown, as the polymer reaction was initiated from the near-undetectable remaining residues.

    Traces of inkjet printer ink can also initiate the polymer. The detection limit is so low that details of a printed letter previously in an envelope could be read off the inside of the envelope after being exposed to S2N2.

    "A one-covers-all versatile system like this has obvious potential," says Kelly.

    "This work has demonstrated that it is possible to obtain fingerprints from surfaces that hitherto have been considered extremely difficult, if not impossible, to obtain," says Colin Lewis, scientific advisor at the UK Ministry of Defence. "The method proposed has shown that this system could well provide capabilities which could significantly enhance the tools available to forensic scientists in the future."

    >>>

  • 02:00 Brief: Anti-malware testing group release standards
  • Anti-malware testing group release standards >>>

  • 01:04 Security World: eEye bulnerability assessment via SaaS Model
  • eEye Digital Security announced the availability of Retina OnDemand, which provides network security via the Software-as-a-Service (SaaS) model. By using the SaaS model, Retina OnDemand simplifies the... >>>

  • 00:05 Apple ships patch for iLife security flaws
  • Apple has shipped a major iLife security update to fix three documented vulnerabilities that could expose Mac OS X users to arbitrary code execution attacks. The flaws patched with the new iLife Support 8.3.1 could be exploited via specially crafted TIFF or JPEG images, Apple warned in an advisory. Some raw details: CVE-2008-2327: (iLife 8.0 or Aperture [...]
    >>>

Advertising




The latest news