Having trouble viewing this email? View it online here
Infosecurity
          WEBSITE           MAGAZINE REGISTRATION           EVENTS           CONTACTS                                                                     RSS   RSS feed

Infosecurity News - 4 Oct 2011

Editor's Choice

Please Feed the Bear: The Growing Russian Infosec Market The Russian information security market is thriving, fueled by a rise in cybercrime. Some foreign security firms, however, have found it difficult to break into the market. Fred Donovan explains why More

Cashing in on Security Training At long last, a cybersecurity career field has emerged. The (ISC)² US Government Advisory Board Executive Writers Bureau examines where employment opportunities lie and how much you can expect to be paid in this very important sector More

Qualys backs Marlinspike-inspired Convergence notaries Cloud security specialist Qualys is supporting two Convergence notaries, based on an approach developed by security researcher Moxie Marlinspike, as an alternative to SSLs and certificate authorities (CAs). More

Data Loss

China unlikely behind hack of Japanese defense contractor, says Bitdefender
China is unlikely to be the culprit behind the cyberattack against Mitsubishi Heavy Industries, a major Japanese defense contractor, despite the discovery of Chinese characters in the malware used in the attack, said Catalin Cosoi, head of Bitdefender Threat Labs.... More

Russia's StarForce intros cloud-based anti screen-grabbing technology for documents
StarForce Technologies, a copy protection specialist, has taken the wraps off an a cloud-based service that allows organisations to publish documents on the web without any worries that the information will be screen grabbed.... More

Merchants get failing grade on compliance with payment card standards
Most businesses fail to meet PCI DSS payment card security standards, according to a new Verizon report.... More

Betfair loses data on more than three million customers to hackers
Betfair has apparently admitted that data on more than three million of its customers – including 2.9 user names and almost 90,000 bank account details – was hacked by cybercriminals, possibly from Cambodia.... More

Application Security

Apple OS X Lion passwords cracked
It looks as though the security of the password system on Apple's OS X Lion operating system has been compromised, with a security researcher claiming that there is a workaround that allows users to crack the password on a Mac system that has been password-protected.... More

Trend Micro threat researchers track major international targeted APT attack
A pair of threat researchers are reporting the arrival of a major targeted attack campaign against servers in 61 countries, with victims ranging diplomatic missions, government ministries, space-related government agencies and other companies and research institutions.... More

Mozilla fixes 10 critical flaws with Firefox 7 update
Mozilla has released version 7 of its popular Firefox browser, including fixes for 11 security flaws, 10 of which are rated critical. ... More

Running Internet Explorer 6 apps securely under Windows 7 native mode now possible
A company called Browsium claims to have developed a legacy-enhancing technology that allows IE6 applications to run on Windows 7 - and natively in IE8 and IE 9 browsers - without the need for application rewrites or the use of virtualisation.... More

Compliance and Policy

Trend Micro expert calls new Facebook interface a 'stalker enabler'
If you use Facebook, you'll undoubtedly have noticed a series of major changes to your web interface over the last few days. According to a Trend Micro solutions architect, users should not lose sight of the fact that the underlying data remains intact, and there are still security issues that need to be addressed.... More

Hospitals fail to innoculate themselves against new media security bugs
Over half of the healthcare organizations surveyed by PricewaterhouseCoopers (PwC) did not have security policies in place for mobile devices or social media.... More

Osirium says deceptive IT practices put security audits at risk
A privileged user and infrastructure management specialist has released Quocirca-completed research that is billed as showing that deceptive IT practices could have hidden and potentially serious consequences that would have a major impact on businesses.... More

Merchants get failing grade on compliance with payment card standards
Most businesses fail to meet PCI DSS payment card security standards, according to a new Verizon report.... More

72% of businesses now block access to social networking sites
In what may well be a knee-jerk reaction to the scale of the security problem, it appears that many companies are simply locking down access to social media sites and services from the workplace.... More

Identity and Access Management

Elcomsoft enhances password recovery software to crack encrypted BlackBerry media cards
Russian password recovery specialist has enhanced its Phone Password Breaker software to crack encrypted media cards for the BlackBerry smartphone. The password recovery specialist claims the software's password recovery rate on the BlackBerry is in the order of millions passwords per second.... More

Internet and Network Security

Phish now tastes better than spam to hackers, says Symantec researcher
A Symantec researcher is reporting that phishing is now a better choice for cybercriminals in terms of the returns it generates for their bottom line.... More

Trend Micro expert calls new Facebook interface a 'stalker enabler'
If you use Facebook, you'll undoubtedly have noticed a series of major changes to your web interface over the last few days. According to a Trend Micro solutions architect, users should not lose sight of the fact that the underlying data remains intact, and there are still security issues that need to be addressed.... More

Go Daddy goes phishing
The breach of websites hosted by Go Daddy was likely the result of a phishing attack, said Nicholas Percoco, head of Trustwave SpiderLabs.... More

Dutch government revokes DigiNotar's CA root certificates
The Dutch government is revoking the DigiNotar’s subordinate certificate authorities (CAs) under the Staat der Nederlanden root certificates.... More

China unlikely behind hack of Japanese defense contractor, says Bitdefender
China is unlikely to be the culprit behind the cyberattack against Mitsubishi Heavy Industries, a major Japanese defense contractor, despite the discovery of Chinese characters in the malware used in the attack, said Catalin Cosoi, head of Bitdefender Threat Labs.... More

European survey shows internet shoppers still worried about online security
Research just released claims to show that European internet users are still worried about security issues about shopping online, with around 20% avoiding e-shopping because of their concerns. ... More

Canadians are 'offside' when it come to online protection, says report
Canadian citizens are failing to take basic steps to protect themselves online, concludes a new report by the Conference Board of Canada.... More

Microsoft warns on combination SSL/TLS security risk
Microsoft’s Trustworthy Computing operation has warned on a potential security issue with Secure Sockets Layer (SSL 3.0) and Transport Layer Security (TLS 1.0) across all browser platforms. Under certain conditions, the software giant says, a Windows-based HTTPS-enabled session could be vulnerable to a man-in-the-middle data interception.... More

I'll sue you for spamming me (but I'll also quietly infect your computer) scam revealed
Security training firm KnowBe4 says it is has spotted a new social engineering scam appearing in internet users' mailboxes – the attack tries to scare recipients into opening the infected attachment by threatening to sue them for spamming.... More

Cyberpirates harpoon big fish through whaling
Cybercriminals are increasingly using “whaling” – a targeted spear phishing attack that goes after “big fish” in an organization – to gain access to critical proprietary data, according to IBM’s X-Force 2011 Mid-Year Trend and Risk Report.... More

Is Secure Sockets Layer broken?
As reported earlier this week, after two Far Eastern researchers revealed potentially severe security problems with SSL 3.0 and TLS 1.0 technology, Microsoft's Trustworthy Computing operation released an advisory to Windows users, warning them of the problem.... More

Australia's NetRegistry suffers a major DDoS attack
Reports are coming in that the NetRegistry, one of Australia's key internet registries, has suffered a major distributed denial of service (DDoS) attack this week.... More

IT Forensics

Comment: Network Forensics – Beyond Activity Monitoring
Network activity monitoring can alert a company to a security breach or an attack, but Jay Botelho of WildPackets points out that a network forensics solution can take network monitoring a step further and use this information to prevent future attacks... More

Kaspersky Lab sets record straight on Kelihos botnet takedown
Apparently feeling slighted, Kaspersky Lab launched a press campaign to make sure that Microsoft does not get all the credit for the takedown of the Kelihos botnet.... More

Malware and Hardware Security

Microsoft’s malware detection blocks Google’s Chrome browser
An emergency update for Microsoft’s Security Essentials was issued Friday after users notified the company that its malware detection was blocking – and in some cases deleting – the Chrome web browser and flagging it as Zeus financial malware. ... More

Trend spots malware hidden within rogue copies of Opera Mini Java edition
A Trend Micro fraud analyst claims to have spotted rogue versions of Opera Mini, a Java (jar) mobile phone browser that can be downloaded and used on a wide number of mobile phones.... More

CA Technologies dissects the latest Mac PDF trojan
Following on from last week's discovery of the OSX/Revir.A Apple Mac trojan by F-Secure, CA Technologies has dissected the malware and come up with some interesting information.... More

Major botnets have infected over 20 million computers, says Kaspersky
More than 20 million computers are infected by the four largest botnets, according to Vitaly Kamluk of Kaspersky Lab.... More

Superbotnet poised to be unleashed by cybercriminals
A cybercriminal organization is creating a superbotnet by sending out billions of malware-laden emails for an unknown purpose, according to Commtouch researcher Avi Turiel.... More

Symantec reports polymorphic malware soaring to 72% during September
The latest monthly analysis from Symantec claims to show that around 72% of all email-borne malware seen so far in September have been characterized as aggressive strains of generic polymorphic malware – up from just 23.7% tracked during July of this year. ... More

Public Sector

ISPs would notify consumers about botnet infections under US proposal
The US Departments of Homeland Security and Commerce are seeking public comments on a proposed voluntary program under which Internet service providers (ISPs) would notify users when their computers have been infected by botnet malware.... More

Security Training and Education

ISF issues major update on Standard of Good Practice for IT security professionals
The Information Security Forum (ISF) has published a major update on its Standard of Good Practice for IT security professionals, which is billed as the industry’s most business-focused, all-in-one guide to information security assurance. ... More

Last week's top three stories on www.infosecurity-magazine.com

1. Apple OS X Lion passwords cracked

2. Some companies view cloud computing as a threat to their IT security

3. Major botnets have infected over 20 million computers, says Kaspersky

Wireless and Mobile Security

CA Technologies researcher spots trojan posing as new Android browser
Android users are constantly on the lookout for an enhanced web browser, and it appears that hackers have latched on to this fact, coding up a trojan that appears to be just such an app.... More

ISACA warns on mobile device geo-location security risks
Not-for-profit IT security association ISACA has warned its members and the IT industry at large of the security risk that geo-location technology on mobile devices now poses the modern organisation.... More

Cloud Computing

Comment: Tackling Data Protection Concerns on Public Cloud Services
To ensure highest security and compliance standards are met in the cloud, organizations need to adopt a data-centric approach that focuses on protecting data throughout its lifecycle, argues Mike Smart of SafeNet.... More

Management clueless about data center security, says survey
A full 60% of data center managers say that their corporate management believes that data center security is stronger than it actually is, according to a survey by Gabriel Consulting Group.... More

Fuzzy definitions delay cloud-based security as a service adoption
The lack of clear definitions for cloud-based security as a service (SecaaS) has caused market confusion and has led to slow SecaaS adoption, according to the Cloud Security Alliance (CSA).... More

Some companies view cloud computing as a threat to their IT security
Research just released by Kaspersky Lab claims to show that around a quarter of companies (23%) see the cloud as a threat to their IT security.... More

Industry News

Report says ISACA certifications earn top pay premiums
Independent research just released confirms what many IT security professionals have guessed for some time, namely that security qualifications from ISACA allow employees to command the best premium in the jobs marketplace.... More

Events

RSA Europe 2011
Dates: 11 October 2011 until 13 October 2011
Location: London, UK
Website: http://www.rsaconference.com/index.htm
More

e-Crime Turkey
Dates: 18 October 2011 (1 day event)
Location: Istanbul, Turkey
Website: http://www.e-crimecongress.org/
More

PCI Istanbul
Dates: 18 October 2011 (1 day event)
Location: Istanbul, Turkey
Website: http://www.pci-portal.com/
More

SecTor 2011
Dates: 18 October 2011 until 19 October 2011
Location: Toronto, Ontario, Canada
Website: http://www.sector.ca/
More

For a full list of events and conferences, please visit
http://www.infosecurity-magazine.com/events/

Follow Infosecurity on Twitter
Join the Information Security Community
Find Infosecurity on Facebook

Received this from a colleague? Sign up for your own regular copy of Infosecurity Weekly.

This e-mail has been sent to you from Elsevier, The Boulevard, Langford Lane, Kidlington, Oxford OX5 1GB, registered in England with registered number 1982084.

You are receiving this e-mail because you are a registered subscriber of Infosecurity. We respect your privacy and do not rent, sell or disclose your personal information to any non-affiliated third party without your consent, except as may be stated in our site's Privacy Policy: http://www.infosecurity-magazine.com/legal/privacy/