Having trouble viewing this email? View it online here
Infosecurity (UK)
          WEBSITE           MAGAZINE REGISTRATION           EVENTS           CONTACTS                                                                     RSS   RSS feed

Infosecurity (UK) News - 9 Mar 2010

Editor's Choice

Infosecurity professionals still in demand says ISC(2) survey Global research published today by ISC(2), the not-for-profit IT security industry association, claims to show that ITsec professionals have been more resilient than most when it comes to salary hikes and their skills being in demand. More

RSA: Schmidt announces transparent national US cybersecurity strategy Howard Schmidt, Cyber security advisor to President Obama, announced the launch of www.whitehouse.org/cybersecurity - a brand new web page launched to prove the commitment of the US government to its transparent cybersecurity strategy - during his keynote at RSA conference 2010 in San Francisco. More

Streamline Your Compliance and IT Risk Management EffortsStreamline Your Compliance and IT Risk Management Efforts

In today's highly regulated business environment, you face the challenge of complying with numerous requirements and the stakes are higher than ever before. Compliance by spreadsheet is a surefire way to extend the cost, time and resources needed to complete a regulatory IT audit - it’s no wonder many organizations today spend as much as 50 percent more on compliance than necessary. Learn how you can streamline audit and IT risk management workflows to reduce the burden and cost of compliance and provide value back to your business.

Data Loss

RSA: M86 introduces one-stop appliance technology and launches into cloud
M86 Security has taken the wraps off a one-stop integrated security appliance that combines its threat analysis technology with a drill-down dashboard interface. At the same time the company has extended its web gateway technology into the cloud computing environment.... More

What’s in store for 2010?
The Noughties are behind us now, but memories of a decade of data breaches will continue to haunt the infosec professional. If only there was a way of knowing what the threat landscape would look like in the months to come. Well you’re in luck as Davey Winder has dusted off the crystal ball and spoken to a broad church of infosec professionals to get some informed predictions for 2010... More

Application Security

Microsoft cautions WinXP users to avoid the F1 key
A new VBScript vulnerability that is apparently being exploited by hackers in the wild has caused Microsoft to warn Windows XP users to avoid hitting the F1 function key if requested to by a website.... More

RSA: Securing cloud computing is industry responsibility says Art Coviello
In his keynote at RSA 2010, San Francisco, RSA President Art Coviello spoke of the industry’s latest and greatest challenge: securing cloud computing. ... More

Veracode report exposes application security failures
According to the Veracode ‘State of Software Security’ report, between 58 and 88 percent of all applications submitted to Veracode for verification did not achieve an acceptable security score upon first submission. The exact percentage depends on the standard applied, based on application criticality. ... More

Featured Event: Infosecurity EuropeFeatured Event: Infosecurity Europe

Infosecurity Europe, where information security professionals address the challenges of today whilst preparing for those of tomorrow at Europe’s No. 1 industry event.

Participate in the unrivalled free education programme where influential global experts stimulate debate and industry practitioners share case study experiences. Over 300 international solution providers showcase current and emerging technologies and deliver practical, professional & technical expertise.
Infosecurity Europe, Earls Court, London, 27th – 29th April 2010.  Register free to visit

Business Continuity and Disaster Recovery

RSA: Solera networks partners with EMC
Active network forensics company Solera Networks announced its partnership with EMC at RSA Conference 2010 on March 2 in San Francisco. ... More

Compliance and Policy

Cyber-Ark to go large on privileged user account security
Cyber-Ark is planning to unveil v6.0 of its Privilege Identity Management Suite (PIMs) at the Infosecurity Europe show next month, Adam Bosnian, the firm's vice president of products, strategy and sales, has revealed.... More

Consumers' Association say `bullying' law firm complaint is being pursued by solicitor's association
A law firm that has been widely criticised for apparently falsely accusing hundreds of internet users of illegal file sharing is to be investigated by the Solicitor's Regulatory Authority (SRA), Which? magazine has announced.... More

Argos allegedly emails out embedded HTML payment card credentials
Reports are coming in that discount retailer Argos, which allows customers to buy from its website, as well as order goods online for pickup from one of its many stores, has allegedly been mailing out customer payment card details – including the three and four digit CVV codes normally found on the signature strip or the front of the card – in its confirmatory emails... More

Securing Your Business Against Future Internet ThreatsSecuring Your Business Against Future Internet Threats

Infosecurity’s Eleanor Dallaway speaks to Gerhard Eschelbeck, CTO of Webroot, about how to secure your business against future internet threats.

This podcast will examine how the internet has influenced business practices, and will look at the current and future threat landscape.

Encryption

RSA: PCI DSS survey shows that encryption is tops when it comes to end-to-end security
According to a survey of qualified security assessors (QSA), the optimum methodology for end-to-end security protection is encryption.... More

Identity and Access Management

RSA: Microsoft reveal plans for a safer internet
In his keynote address at the RSA Conference 2010 in San Francisco, Scott Charney, corporate vice president of Microsoft’s Trustworthy Computing Group, outlined how Microsoft will apply its end to end trust vision to cloud computing. ... More

Internet and Network Security

Sophos reveals how Twitter, Yahoo and Google Adsense can be used to infect users with malware
Sophos claims to have uncovered an interesting new hybrid style of security attack on Twitter users that taps into security issues with Yahoo and Google's Adsense advertising service.... More

Trend Micro's Rik Ferguson reports on Adware Spyware Detective
Whilst the RSA Conference 2010 is going on in San Francisco, Rik Ferguson, Trend Micro's security spokesperson has been expounding on how criminals are battling against the rising ride of anti-malware technologies in the marketplace.... More

RSA: Check Point unveils secure USB drive technology
Check Point Software Technologies has taken the wraps off a secure USB drive system. Known as Abra, the unit is designed to offer PC or Windows-based terminal users a secure virtualised workspace that is highly portable between machines.... More

Analyzing Top Malware in 2009 and Predictions for 2010Analyzing Top Malware in 2009 and Predictions for 2010

It has been a busy year in network security — cybercriminals have been crafty and creative, while security vendors have worked hard to stay a step ahead. 2009 was the year for malware. 

Malware and Hardware Security

SunbeltLabs detects surge in trojans during February
Sunbelt Software's list of top malware infections seen during February claims to show that there was a sizeable surge in trojans during the month.... More

Kaspersky researcher says `human vulnerabilities' need patching too
A paper just published by Kaspersky Lab, the Russian headquartered IT security vendor, claims to highlight the need for `human vulnerabilities' to be patched, in much the same way that computer software needs updating on a regular basis.... More

F-Secure intros Mac protection technology
F-Secure, an IT security vendor normally associated with PCs and Windows, has branched out into Apple Macs, with the development of Mac Protection, which it claims gives Mac users the same levels of IT security protection that its PC users have enjoyed for some time.... More

RSA: Qualys teams with Imperva on website security
Hard on the heels of announcing a free website infection scanning service, Qualys has teamed up with fellow IT security vendor Imperva to integrate some of their respective software offerings.... More

Mabezat worm targets job seekers
Reports are coming in about a worm that appears in an email, masquerading as a job offer or detailing job-related information. Known as Win32.Worm.Mabezat.J. The worm appears to be a variant of an earlier edition, but uses clever wording to persuade recipients to click through on to an infected web page.... More

Security Training and Education

RSA: (ISC)² cyber security awareness for kids
At the RSA Conference 2010 in San Francisco, (ISC)²,Microsoft, and RSA conference co-sponsor a session to train member volunteers for its Safe and Secure online programme.... More

Last week's top three stories on www.infosecurity-magazine.com

1. Laptop theft can be reduced by turning off WiFi

2. Real life security in the NHS revealed

3. HSBC offers free Trusteer password software to all

Wireless and Mobile Security

Laptop theft can be reduced by turning off WiFi
Credant Technologies, the endpoint data security specialist, has warned laptop users to turn off their WiFi signals when not in use to prevent the use of low-cost scanners tracking down the machines.... More

Events

Euro CACS
Dates: 22 March 2010 until 23 March 2010
Location: Budapest, Hungary
Website: http://www.isaca.org/Template.cfm?Section=By_Conference&Temp...
More

ICCCIS 2010: International Conference on Crypthography, Coding and Information Security
Dates: 29 March 2010 until 31 March 2010
Location: Paris, France
Website: http://www.waset.org/conferences/2010/france/icccis/
More

Black Hat Europe 2010
Dates: 12 April 2010 until 15 April 2010
Location: Barcelona, Spain
Website: http://www.blackhat.com/html/events.html
More

Infosecurity Europe 2010
Dates: 27 April 2010 until 29 April 2010
Location: London, UK
Website: http://www.infosec.co.uk
More

For a full list of events and conferences, please visit
http://www.infosecurity-magazine.com/events/

Lumension
Twitter
Facebook
LinkedIn
Infosecurity Europe

Received this from a colleague? Sign up for your own regular copy of Infosecurity (UK) Weekly.

This e-mail has been sent to you from Elsevier, The Boulevard, Langford Lane, Kidlington, Oxford OX5 1GB, registered in England with registered number 1982084.

You are receiving this e-mail because you are a registered subscriber of Infosecurity (UK). We respect your privacy and do not rent, sell or disclose your personal information to any non-affiliated third party without your consent, except as may be stated in our site's Privacy Policy: http://www.infosecurity-magazine.com/legal/privacy/