Security


Fake Microsoft Security Update Makes Rounds

Sophos quickly warns of fake Trojan-laden e-mail disguised as Microsoft Security Bulletin update hitting inboxes.

Vista's UAC a Winner in Win7?

Plus: shedding more light on version 2 of Microsoft's RIA app; Citrix looking for total virtualization domination.

Busy October Patch Cycle Comes Around with 11 Fixes

Security-minded admins have their work cut out for them, as Microsoft coughs up 11 fixes in its October patch cycle.

Fortinet Helps DBAs Sniff Out DB Exploits

New security appliance gives DBAs a leg up on flaws and vulnerabilities lurking in corporate database management systems.

Microsoft Promises To Improve UAC in Windows 7

Microsoft has been talking about future changes to Windows Vista's most maligned feature, User Account Control (UAC).

11 Fixes Expected for Patch Tuesday

Microsoft's October patch release cycle promises to be a busy one as Redmond announced plans to roll out 11 security bulletins in its Tuesday security release.

Gartner Warns of Wi-Fi Vulnerabilities

A new study from Gartner concludes that the WLANs of today comprise a "significant vulnerability" for enterprise IT organizations.

Surveys Raise Doubts on Virtualization Security

Migration to virtualization won't be the quick transition that some technology evangelists have predicted, according to recent surveys by two IT security companies.

Beware of Hotel Internet Connections

Jet-setters should be careful about how they use the Internet connections supplied by hotels, as most are not secured properly, according to a new study from the Cornell University School of Hotel Administration.

Yahoo Fixing Zimbra Bug, Integrating With Exchange

Yahoo plans to resolve a password security vulnerability identified last week in its Zimbra open source e-mail and collaboration software.

Bringing Down the Grid

You can talk about SCADA. You can talk about vulnerabilities. But be careful about conflating the two.

Take Control of Digital IDs with ILM

Managing users' multiple identities -- and their multiple phases -- can get complicated. That's where ILM comes in.

Payment Card Security Toughens With DSS 1.2 Release

The Payment Card Industry Council on Wednesday released an updated version of its PCI data security standard, which is designed to help protect transmitted charge and debit card information.

Private Browsing's False Sense of Security

They call it private browsing. Microsoft recently released a beta version of Internet Explorer 8 that offers it. You'll find it in Mozilla's Firefox and the new Google Chrome. Apple's Safari has offered the feature for some time.

UPDATED: Browser-Makers Seek Clickjacking Fix

What is clickjacking? Security pros are trying to make sense of a new bug found by researchers that apparently affects various Web browsers, including Microsoft's Internet Explorer.

U.S. Tops List as Source for Botnet Attacks

The United States was the top source of distributed attack traffic, originating nearly three times as many attacks as second-place China, according to a recent study by security service provider SecureWorks Inc.

Privacy Uncertain With New IE8 Feature

Redmond continued to rebuff assertions that a "suggested sites" feature in Internet Explorer 8, currently at Beta 2 release, invades user privacy.

Japan, U.S., China Leading Sources of Web Attack Traffic

Japan, the United States and China topped the list of countries from which Internet attack traffic originates in a recent report by Akamai Technologies Inc. The three countries accounted for more than 60 percent of attack-oriented Internet traffic.

Buyer Beware with Virtualization Technology

As hackers continue to focus their attention on virtualized environments, those looking to adopt virtualization technologies should proceed with caution, according to report from InfoWorld.

September Patch To Fix Windows GDI Exploit and More

Redmond on Tuesday rolled out four critical fixes, as expected, for as many as eight remote code execution exploits for various Windows applications.

Subscribe on YouTube