Linux security professionals spend most of their time on concrete problems. Hardening SSH. Configuring SELinux or AppArmor. Building secure CI/CD pipelines. Managing patches across server fleets. The work is technical, hands-on, and measurable.
...
Two premiere security conferences -- Black Hat and DefCon -- run back-to-back in Las Vegas this week, each with their own distinct flavor. But even these events don't meet the needs of all computer security pros, setting the stage for a widening set of satellite events.
A capture-the-flag-style competition slated to take place at Defcon later this month has raised eyebrows at a number of companies who are concerned they will be embarrassed or negatively impacted in some way. CSO first reported the CTF challenge earlier this month in Defcon contest to spotlight social engineering. The challenge asks contestants to collect information about a "target" company, which they are assigned to by contest coordinators at the web site social-engineer.org.
The Internet Explorer, Firefox, Chrome, and Safari browsers are susceptible to attacks that allow webmasters to glean highly sensitive information about the people visiting their sites, including their full names, email addresses, location, and even stored passwords, a security researcher says.
Three years ago, Marc Maiffret was tired. He had been running hard as CTO of eEye Digital Security since co-founding the company at age 17. So after a decade, he walked away.
He recently resurfaced as chief security architect at FireEye, and did an extensive interview with CSO about how security threats have changed since his eEye days.
A security researcher plans to unveil a new Web browser add-on that cleans Adobe Flash code before a video can be played back, preventing attackers from targeting Adobe Flash file errors.
This year's Defcon event will feature a contest that asks social engineers to infiltrate target companies. But the challenge is only one part of a large mission to get people thinking about social engineering.
The Swedish anti-copyright group Piratbyran, which gave rise to the popular file-sharing website The Pirate Bay has disbanded.
Marcin de Kaminski, a founder of Piratbyran, which means "piracy bureau" in English, told BBC News "we don't feel we are needed" any more.
A federal judge has handed a major victory to anti-spam crusaders Spamhaus, slashing an $11.7m verdict to just $27,002.
US Judge Charles P. Kocoras of the Eastern District of Illinois said the plaintiffs, e360 Insight and its founder David Linhardt, failed to credibly calculate the damage that resulted when its promotional emails were targeted by Spamhaus.
I go to a lot of security conferences, almost always without my family in tow. The logistics and money involved with trekking them from one part of the country to the next is usually beyond my resources. But when a conference is local and there's something in it for the kids, I'm in 100 percent.
Sourcefire, the creators of Snort(R) and a leader in intelligent Cybersecurity solutions, today announced that its founder and CTO, Martin Roesch, will speak at the FS-ISAC 2010 Spring Conference. During the session, Roesch will discuss the techniques and solutions financial institutions need to implement to protect their data from today's evolving threat landscape.
Trends including the increase in web data and the number of people accessing the internet will have implications for information security in the future, says a report by PricewaterhouseCoopers (PwC), commissioned by government body the Technology Strategy Board.
Each spring, the MIS Training Institute hosts InfoSec World, an educational event that brings information security practitioners together to learn from each other. This year, volcanic fallout prevented a few participants from making the trek. But those who attended were treated to detail-rich sessions about today's biggest security threats.
Companies crave experience in their security staffers, dimming prospects for entry-level applicants. Bill Brenner on how a young upstart can break through. If you're young, breaking into the security industry can be hell.
Late last month, another kind of games was held in Vancouver: the Pwn2Own contest, where computer-security researchers were invited to hack computers using unknown, or
Owners of Apple products have a tendency to be complacent about security, but the results of this year's Pwn2Own contest suggest a little more wariness may be in order. "It's the fourth year they've run the contest, and every year someone's broken into Safari," noted Charlie Miller, the security analyst who won $10,000 and a MacBook Pro for hacking the browser in this year's event.
Hackers took down Apple 's iPhone and Safari browser, Microsoft 's Internet Explore 8 (IE8) and Mozilla's Firefox within minutes at today's Pwn2Own contest, as expected.
The two-man team of Vincenzo Iozzo and Ralf-Philipp Weinmann exploited the iPhone in under five minutes, said a spokeswoman for 3Com TippingPoint, the security company that sponsored the contest. The pair also walked away with $15,000 in cash, a record prize for the challenge, which is in its fourth year.
Privacy is not dead in the era of online social networking. It just needs careful curation.
That was the message Saturday from Danah Boyd, a social-media expert who works for Microsoft Research and who was Saturday's keynote speaker at the South by Southwest Interactive (SXSWi) festival here.
Speaking at the RSA Conference in San Francisco on Wednesday, Secretary of the Department of Homeland Security (DHS) Janet Napolitano announced the National Cybersecurity Awareness Campaign Challenge Competition, a contest to solicit ideas from individuals and industry about how to best engage the American public in a discussion about cybersecurity.