RSS News
Security & Tech:
Security Warnings- Vuln: Pligg CMS 'status' Parameter SQL Injection Vulnerability December 28, 2012Pligg CMS 'status' Parameter SQL Injection Vulnerability […]
- Vuln: CVS CVE-2012-0804 'proxy_connect()' Heap Buffer Overflow Vulnerability February 21, 2012CVS CVE-2012-0804 'proxy_connect()' Heap Buffer Overflow Vulnerability […]
- Vuln: Pligg CMS 'status' Parameter SQL Injection Vulnerability December 28, 2012
Cnet Tech News- New Microsoft ad aims knife at Google's jugular February 22, 2012New video attempts to accuse Google of Googlighting. Should you be unfamiliar with this term, it allegedly means an ad agency selling productivity software in its spare time. [Read more] […]
- Ultrabooks with hybrid drives could start at $600 February 21, 2012The new devices could appear later this year, with hybrid disk drives helping keep costs low, according to a report. [Read more] […]
- Facebook readying new premium ads? February 21, 2012Leaked document shows ad upgrade presentation apparently targeting the friends of advertisers' fans. [Read more] […]
- Samsung Galaxy S Blaze 4G to spark up T-Mobile in March February 21, 2012T-Mobile's latest Galaxy S Android Gingerbread handset will feature a 4-inch Super AMOLED screen, a dual-core processor, and HSPA+ speeds for less than $200. [Read more] […]
- Apple confirms plans to build data center in Oregon February 21, 2012Tech giant's secret project to construct another large data center in the country's Northwest is revealed. [Read more] […]
- New Microsoft ad aims knife at Google's jugular February 22, 2012
Sans Security Tips
US-Cert.gov Vulns- Adobe Releases Security Advisory for Adobe Flash Player February 16, 2012
- Google Releases Chrome 17.0.963.56 February 16, 2012
Geek News:
Sans Security Alerts- SANSFIRE 2011SANSFIRE 2011 […]
- (1) HIGH: Microsoft Patch Tuesday VulnerabilitiesCategory: Widely Deployed Software Affected: Internet Explorer Visio 2003 Visio 2007 Visio 2010 Windows XP Windows 2003 Windows Server 2008 Windows Vista Windows 7 […]
- SANSFIRE 2011
SecurityFocus – Vulns- Vuln: Pligg CMS 'status' Parameter SQL Injection Vulnerability December 28, 2012Pligg CMS 'status' Parameter SQL Injection Vulnerability […]
- Vuln: CVS CVE-2012-0804 'proxy_connect()' Heap Buffer Overflow Vulnerability February 21, 2012CVS CVE-2012-0804 'proxy_connect()' Heap Buffer Overflow Vulnerability […]
- Vuln: Pligg CMS 'status' Parameter SQL Injection Vulnerability December 28, 2012
Securityfocus – News- News: Change in Focus March 9, 2010Change in Focus […]
- News: Twitter attacker had proper credentials December 17, 2009Twitter attacker had proper credentials […]
- News: Change in Focus March 9, 2010
Hack-In-The-Box:
“Keeping Knowledge Free”- Fake RIAA copyright violation notification serves malware February 21, 2012First spotted nearly a week ago, notifications of copyright violation supposedly sent by the Recording Industry Association of America are still hitting inboxes around the world. The sender's email address is spoofed to make the message seem legitimate, and the email contains a warning and an attachment that the user is asked to open in order to see det […]
- Obama signature could bring surveillance drones to your backyard February 21, 2012President Obama last week signed the FAA Air Transportation Modernization and Safety Improvement Act of 2012. Tucked inside the legislation is a provision that could have far-reaching implications in the coming decade: widespread civilian use of unmanned aerial drones.Tags: PrivacyGOVLaw and Order […]
- OS X Mountain Lion Gatekeeper: Can it Really Keep Malware Out? February 21, 2012OS X Mountain Lion has extended the functionality of its predecessor viz. Mac OS X Lion by adding over 100 new features to it. Gatekeeper is one of those news features and it provides a whole new security mechanism for Mac users.Tags: AppleSecurityOS XViruses & Malware […]
- Fake RIAA copyright violation notification serves malware February 21, 2012
SANS Handlers Diary:
SANS Internet Storm Center, InfoCON: green- Infocon: greenISC StormCast for Wednesday, February 22nd 2012 http://isc.sans.edu/podcastdetail.html?id=2344 […]
- ISC StormCast for Wednesday, February 22nd 2012 http://isc.sans.edu/podcastdetail.html?id=2344, (Wed, Feb 22nd) February 21, 2012...(more)... […]
- How to test OS X Mountain Lion's Gatekeeper in Lion, (Wed, Feb 22nd) February 21, 2012While I started working on comparing various OS X hardening guides (see the prior diary from a coupl ...(more)... […]
- ISC StormCast for Tuesday, February 21st 2012 http://isc.sans.edu/podcastdetail.html?id=2341, (Tue, Feb 21st) February 20, 2012...(more)... […]
- DNSChanger resolver shutdown deadline is March 8th, (Mon, Feb 20th) February 20, 2012The ISChas written a number of diaries about DNSChanger in the past, including this excellent ...(more)... […]
- Infocon: green
F-Secure Weblog:
“Weblog of the F-Secure Antivirus Research Team”- Nightline Takes "A Trip to The iFactory"Nightline, a U.S. news program, will air what's being billed as a special episode this evening on the ABC network. In it, Nightline Co-Anchor Bill Weir will tour Foxconn's factory floor. If you haven't heard of Foxconn, they're the company that manufactures devices such as iPad, iPhone, Kindle, PlayStation 3, Wii, and the Xbox 360.Weir […]
- Network Security, Circa 1990AT&T recently released a film from its archive called "Computer Security: You Make The Difference".While you might chuckle at the 1990's music and production values – the truth is this – many of basic issues that the video (which is a series of films stitched together) attempts to illustrate are still with us today, 22 years later.And that […]
- Mountain Lion's Gatekeeper: More Control For "You"Yesterday, Apple released Mac OS X Mountain Lion Developer Preview. From a security perspective, its most interesting new feature is Gatekeeper, which restricts installation of downloaded applications based on their source."Allow applications downloaded from: Mac App Store; Mac App Store and identified developers; Anywhere"The default setting is re […]
- Nightline Takes "A Trip to The iFactory"
Kasperky Lab Weblog:
“Analyst’s Diary”- The where and why of HLUX February 15, 2012This is not the first time the HLUX botnet has been mentioned in this blog, but there are still some unanswered questions that we’ve been receiving from the media: What is the botnet’s sphere of activity? What sort of commands does it receive from malicious users? How does the bot spread? How many infected computers are there in the botnet?Before answering t […]
- Patch Tuesday February 2012 February 14, 2012Microsoft is releasing 9 Security Bulletins this month (MS12-008 through MS12-016), patching a total 21 vulnerabilities. Some of these vulnerabilities may enable remote code execution (RCE) in limited circumstances, and offensive security researchers have claimed that a "bug" fixed this month should be client-side remote exploitable, but after mont […]
- Will the PIN hacks be the end of Google Wallet? February 14, 2012Last week researchers found vulnerabilities in the Google Wallet payment system. The first vulnerability was found by Zvelo, which required root access. Rooting devices has become just short of trivial at this point with the availability of “one-click root” applications for most platforms. The vulnerability was leveraged to display the current PIN number. Th […]
- The where and why of HLUX February 15, 2012
InfoSec Writers:
Infosec Writers Latest Security Papers- Old School Newbie Guide circa 2000 December 5, 2011This is a flashback paper written by the founder and creator of SWG, our original site. Later it changed ownership and direction and became ISW. To those that remember Raven, enjoy! This is in celebration of our 10 year anniversary at ISW! […]
- Analysis of Malicious Software Infections November 28, 2011Kenneth Davis submits this paper on a study of Malicious Softwares. He discussed the threats and ways to help mitigate the risks associated. […]
- Malware in Information Security November 27, 2011Jared Dukes submits this paper on Malware. He discusses the history of Malware as well as reasons one could become infected. […]
- Old School Newbie Guide circa 2000 December 5, 2011
IT Observer:
“Information Technology Security Magazine”- Websense Wireless Security Expert to Present on Emerging Security & Web Content Threats in 3G at QuEST Forum EMEA January 20, 2009Websense, Inc. (Nasdaq: WBSN), a global leader in web security and web filtering productivity software, today announced that Mark Fogel, vice president for Websense(R) Wireless, a Division of Websense, Inc., will be giving a presentation on Emerging Security & Web Content Threats in 3G at the third annual QuEST Forum (Quality Excellence for Suppliers of […]admin
- AI-based Security Appliance Stops MySpace Email Scam January 15, 2009Espion has announced the discovery of the first email-based MySpace Spam Scam. At 5:35pm EST an email was trapped in our unprotected honey pot. At the same time an identical email was stopped by Espion´s Interceptor anti-spam and security appliance. The trapped email looks like a legitimate message from MySpace with the subject reading [New message […]admin
- Compliance and mobility govern security January 15, 2009The one segment in IT that has seen tremendous growth over the past few years is security. Despite advances in technology, security threats are growing at an alarming rate. The Indian network security market experienced a healthy growth in 2005 reaching about $116 million, up 70 percent compared to last year, says business consulting firm […]admin
- Winny Virus Wrecks Data Havoc In Japan January 15, 2009Top-secret military information, business documents of hundreds of corporate firms , personal and confidential data related to thousands of patients, complete information of Yahoo shopping mall, high profile information of Liberal Democratic Party and thousands more are all floating currently on the internet, creating an enormous flood of information leakage […]admin
- Protection from Emerging Virus Threats January 15, 2009Today’s malware distributors skirt traditional defenses by exploiting the zero hour gap, the time it takes to identify the attacking malware and write signatures that can detect and neutralize it. Recent studies have shown the lag time or gap between when a virus is recognized and a signature written to combat it can range from […]admin
- Websense Wireless Security Expert to Present on Emerging Security & Web Content Threats in 3G at QuEST Forum EMEA January 20, 2009

