IT security experts have long loved to troll through hacker forums to gather intelligence on emerging threats and even (as in the ill-fated case of HBGary Federal CEO Aaron Barr) try to profile the hackers themselves. But as a report from IT security firm Imperva shows, many of the so-called hacker portals out there are more hangouts for newbie hackers (and possibly a few budding FBI informants) looking at how to get started in the game. . The article located at arsTechnica is no longer available. . Hacker forums serve as complex networks for novice hackers and seasoned professionals, fostering learning and gathering insight into emerging threats and techniques.. Hacker Training, Cybersecurity Intelligence, Threat Analysis. . LinuxSecurity.com Team
Tom Espiner surveys the security landscape for the shape of things to come. When my editor asked me to predict what would happen to security over the coming year, and over the next 10 years, my heart sank. The permanency of internet publishing, caching and so forth means predictions have a habit of coming back to haunt you.. Plus, I'm a firm believer in chaos theory and the natural entropy of any system. So any detailed prediction is unlikely to come true The link for this article located at ZDNet UK is no longer available. . Explore the evolving landscape of security dynamics in the forthcoming ten years, emphasizing the principles of chaos theory, adaptability, and emerging vulnerabilities.. Security Predictions, Future Trends, Cyber Resilience, Emerging Threats. . LinuxSecurity.com Team
Online criminals today know what they want, and they know where to find it: in your corporate database. Yet, despite a number of highly-publicized data breaches and thefts, many enterprises still have not fully developed a database security strategy. Experts agree that database information particularly customer lists and personal user data is currently the most marketable and attractive target for electronic thieves. But most databases aren't ready for the onslaught of attacks they are beginning to see, the experts warn. . In my opinion, database security is riddled with holes and it's the biggest problem we face in IT today," says David Litchfield, managing director of NGS Software, who has discovered numerous vulnerabilities in database software over the past year. (See Is Oracle Downplaying Security Vulnerabilities?) Next week at the RSA conference in San Francisco, several vendors will be stepping up to do something about that problem. Application Security on Tuesday will unveil DbProtect, a suite of tools that includes vulnerability scanning, database activity monitoring, and data encryption. The link for this article located at Dark Reading is no longer available. . Securing databases is paramount; specialists identify risks companies encounter due to digital theft in the present.. Database Security, Data Protection, Emerging Threats, Vulnerability Management. . LinuxSecurity.com Team
Last week, there were two stories that indicated how complacency is abroad and well in both the business and Government environments. The SysAdmin, Audit, Network Security (SANS) Institute specializes in information security training and certification. . . .. Last week, there were two stories that indicated how complacency is abroad and well in both the business and Government environments. The SysAdmin, Audit, Network Security (SANS) Institute specializes in information security training and certification. Last week in London, it unveiled its SANS Top-20 2004 on the most critical Internet threats facing organizations at a conference held at the Department of Trade and Industry, noting that on-line extortion was widespread. Alan Paller, director of Research, said that 6,000 to 7,000 organizations were paying out, and that the epidemic was growing. He said that the problems were not publicized because people were too embarrassed to talk about getting caught out. The other report that caught my attention concerned the departure of the latest U.S. Cybersecurity Chief. Amit Yoran, formerly an executive with Symantec Corp., was the third holder of the post to depart in less than two years. The link for this article located at Networks & Servers is no longer available. . Negligence in digital security is increasing within corporations and public sectors, underscoring severe online risks.. Cybersecurity Trends, Emerging Threats, Risk Management, Information Security. . Anthony Pell
Mikko Hypponen has made a name for himself as a computer security expert in directing anti-virus research at Finland's F-Secure, a $45 million company that regularly issues alerts warning of network threats. He spoke recently with Network World News Editor Bob Brown and Features Editor Neal Weinberg about the latest viruses and what enterprise network executives are up against. . . .. Mikko Hypponen has made a name for himself as a computer security expert in directing anti-virus research at Finland's F-Secure, a $45 million company that regularly issues alerts warning of network threats. He spoke recently with Network World News Editor Bob Brown and Features Editor Neal Weinberg about the latest viruses and what enterprise network executives are up against. What's your take on Mydoom.M, the latest worm making the rounds? Advertisement: It's a really interesting technique remembering how big Mydoom.A was in January. It was the single largest e-mail outbreak in history. Mydoom made headlines then because it was attacking SCO.com and then later on Mydoom.C was attacking Microsoft.com. What's happening here [with Mydoom.M] is that the attack that made headlines with Google going down wasn't really an attack on Google. It was just using Google to harvest more e-mail addresses. But what Mydoom.M left behind was a back door. We've seen this already with Mydoom.A, which left a back door and several days later its authors scanned public addresses looking for Mydoom.A-infected computers and then installed a spam proxy Trojan called Mitglieder. What seems to be the case with this new Mydoom is that instead of dropping in a spam Trojan they've dropped in a [Distributed Denial-of-Service}client aimed at overloading Microsoft.com's front page, though it hasn't been too successful. Do you have any idea who is behind it? I think it is the same people not only behind the other Mydooms, but also behind Bagle. Possibly even behind SoBig and others. I don't have any concrete evidence on where these guys are operating from, thoughthere are some indications they have come from Russia and are living in central Europe. I think it is more than one guy and that they are organized. The link for this article located at nwfusion.com is no longer available. . Mikko Hypponen delves into the battle against malware and the latest dangers threatening our digital infrastructures.. Mikko Hypponen, Malware Attacks, Anti-Virus Strategies, Network Defense. . Anthony Pell
At this time last summer, Code Red had infected our servers, and SirCam had infiltrated our desktops, while Nimda was waiting in the wings for its entrance. In contrast, so far this summer there have been no major virus outbreaks; the . . . . At this time last summer, Code Red had infected our servers, and SirCam had infiltrated our desktops, while Nimda was waiting in the wings for its entrance. In contrast, so far this summer there have been no major virus outbreaks; the last one was April's pesky Klez.H worm. But don't pop open the champagne bottles just yet. Although we may be better protected today than we were last year, we're still vulnerable to future threats. Even if every computer user in the world had some form of antivirus protection installed on his or her machine, viruses would continue to proliferate, says leading antivirus researcher Joe Wells. Here's why: Most antivirus products are signature-based, meaning the vendor has to supply your antivirus software with unique code to identify each virus. Although many programs automatically update their signature files, there's a delay of several hours between the time a new virus hits the Net and when the update for it gets to your antivirus software. The link for this article located at ZDNet is no longer available. . Investigating the reasons traditional antivirus programs still struggle with new types of cyber threats.. Antivirus Strategies, Malware Proliferation, Cybersecurity Awareness, Virus Identification, Protection Mechanisms. . Anthony Pell
The problem with IT security benchmarks is that the reference point is a constantly shifting target as new technologies and threats emerge. And that's an especially difficult problem to overcome, said corporate security systems managers. They are examining the fruits of . . . . The problem with IT security benchmarks is that the reference point is a constantly shifting target as new technologies and threats emerge. And that's an especially difficult problem to overcome, said corporate security systems managers. They are examining the fruits of a relatively new cooperative effort that this week will yield the near-final version of a systems security benchmark for Sun Microsystems Inc.'s Solaris. But despite concern about the benchmark's continued usefulness, end-user members of the Center for Internet Security said the organization's technical benchmark for securing Solaris systems will be key to their security efforts. The link for this article located at ComputerWorld is no longer available. . A safety standard meets the dynamic nature of technological criteria as developments in IT advance.. Solaris Benchmark, Security Standards, Emerging Threats, IT Security. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.