Archive for September, 2009

Icann opens up to the world

Wednesday, September 30th, 2009

Loosening US grip on the internet.

Brief: Firefox feature looks to foil XSS attacks

Wednesday, September 30th, 2009

Firefox feature looks to foil XSS attacks

A Glimpse Into the Future of Browser Security

Wednesday, September 30th, 2009

As we mentioned earlier we’ve been working for the past few months on turning the Content Security Policy specification into working Firefox code. (You’ll remember that CSP is a framework to protect websites from XSS and related attacks). We are happy to report that the work is nearly finished, and we have some preview builds available for you to try out.

We’re thrilled to have received so much great feedback from other browser vendors, web site administrators, and security researchers and we’re very proud of the design that has come out of that discussion. We would like to encourage any server administrators or web app security researchers who are interested in this project to grab a preview Firefox build and help us test the new features. Please be aware that there are still a few rough spots. The implementation is not quite complete so you may notice some small gaps between the preview builds and the spec. Most notably, HTTP redirects are not fully handled by CSP (but will be soon).

I posted a demo page where you can see the basic features of CSP in action, though we’re all much more excited to see all the tests and proof points our friends in the security research community are sure to turn up. Please grab a preview build and start testing!

Brandon Sterne
Security Program Manager

Exploiting the human body, H1N1 virus

Wednesday, September 30th, 2009

Currently, the H1N1 virus is running rampant (46,000+ cases) throughout the nation and the “official” flu season doesn’t start until Oct 4th. Like all viruses, H1N1 is made up of a DNA sequence, or code. The most amazing part is that it only takes about 3.2 Kbytes of data to code itself. A worm like Conficker takes over 112 Kbytes! Always striving for ultimate efficiency, it looks like Mother Nature…

Clinton thrilled to be president ….of the UN Security Council – AFP

Wednesday, September 30th, 2009

Voice of America

US: Iraq budget shortfall poses security challenge – The Associated Press

Wednesday, September 30th, 2009

AFP
US: Iraq budget shortfall poses security challenge
The Associated Press
Iraq's security plans have been derailed because of the drop in oil prices, hampering efforts to buy ships, planes and weapons and slowing down the
Iraq budget is 'challenge' for security forces: USAFP
Low Oil Prices Threaten Iraq's SecurityHeatingOil.com
US: Iraq budget constraints security challengeThe Associated Press

all 200 news articles »

Microsoft explores free option with Security Essentials – guardian.co.uk

Wednesday, September 30th, 2009

TrustedReviews
Microsoft explores free option with Security Essentials
guardian.co.uk
Amy Barzdukas has one of the computer industry's more thankless tasks: she's general manager for Internet Explorer and consumer security at Microsoft.
Microsoft launches free securityBBC News
One thumb up for MS Security Essentials in early testsRegister
Microsoft Covers the Basics With Security EssentialsPC World
ZDNet UK -Computerworld -InformationWeek
all 645 news articles »

UN Security Council Concerned About Guinea – Voice of America

Wednesday, September 30th, 2009

Voice of America
UN Security Council Concerned About Guinea
Voice of America
The UN Security Council has expressed its concern about the killing of scores of protesters in the West African nation of Guinea on
UN Security Council condemns Guinea bloodshedeTaiwan News
UN Security Council condemns violence in GuineaXinhua
UN condemns violence in GuineaCNN International
Le Mali en ligne -Earthtimes (press release) -Amnesty International UK
all 37 news articles »

Comments On Blogs Likely To Be Spam

Wednesday, September 30th, 2009

In the first half of 2009, 77 percent of websites with malicious code were legitimate sites that had been compromised, according to a new report from Websense.

Comments On Blogs Likely To Be Spam
Comments On Blogs Likely To Be Spam

The high percentage was maintained over the past six months due in part to widespread attacks including Gumblar, Beladen, and Nine Ball which aimed to compromise trusted and known properties with massive injection campaigns.

Web 2.0 sites allowing user-generated content are a top target for cybercriminals and spammers. The report found that 95 percent of user-generated comments to blogs, chat rooms and message boards are spam or malicious.

“The last six months have shown that malicious hackers and fraudsters go where the people are on the Web — and have heightened their attacks on popular Web 2.0 sites and continued to compromise established, trusted Web sites in the hope of infecting unsuspecting users,” said Dan Hubbard, Chief Technology Officer, Websense.

“From malicious Twitter spam campaigns and blog comment spam to the massive injection attacks, those perpetrating fraud are exploiting the inherent trust users have of known Web properties and other users.”

In addition, 69 percent of Web pages with content classified as objectionable also had at least one malicious link. This is becoming more widespread, as 78 percent of new web pages discovered in the first half of 2009 with objectionable content had at least one malicious link.

The convergence of blended web and email threats continues to increase. The report found that 85.6 percent of all unwanted emails in circulation during this period contained links to spam sites or malicious websites.

Immediacy Affects Risk Assessments

Wednesday, September 30th, 2009

New experiment demonstrates what we already knew: That’s because people tend to view their immediate emotions, such as their perceptions of threats or risks, as more intense and important than their previous emotions. In one part of the study focusing on terrorist threats, using materials adapted from the U.S. Department of Homeland Security, Van Boven and his research colleagues presented…

US: Iraq budget shortfall poses security challenge – The Associated Press

Wednesday, September 30th, 2009

Al-Arabiya
US: Iraq budget shortfall poses security challenge
The Associated Press
Iraq's security plans have been derailed because of the drop in oil prices, hampering efforts to buy ships, planes and weapons and slowing down the
Iraq budget is 'challenge' for security forces: US generalAFP
US: Iraq budget constraints security challengeThe Associated Press

all 173 news articles »

Wave search “poisoned”

Wednesday, September 30th, 2009

Google searches on terms related to its new collaboration and communications platform, Google Wave, are leading to a rogue anti-virus programs, according to the Websense Security Labs. Users seeking information on how to sign up for Wave, which currently is by invite-only, have been victimized by manipulated search results that lead to sites designed to trick victims into paying for a security solution that doesn’t work. Searches for Microsoft’s new Security Essentials consumer anti-virus product also have led to “poisoned” results. — CAM



UN demands end of sexual violence as tactic of war – AFP

Wednesday, September 30th, 2009

New Zealand Herald
UN demands end of sexual violence as tactic of war
AFP
UNITED NATIONS — With US Secretary of State Hillary Clinton in the chair, the UN Security Council on Wednesday unanimously adopted a resolution to halt the
UN Security Council demands end of sexual violence in armed conflictXinhua
Clinton to chair Security Council session on sexual violenceChristian Science Monitor
Hillary Clinton likes being president for a dayThe Associated Press
UN News Centre -New Zealand Herald -ISRIA
all 311 news articles »

Protests start ahead of IMF/WB meetings in Istanbul – Xinhua

Wednesday, September 30th, 2009

Daily Star – Lebanon
Protests start ahead of IMF/WB meetings in Istanbul
Xinhua
Turkish authorities have imposed tight security measures in its largest city of Istanbul. Turkish police officer Kartal Ordubakan said more than 300
Beware of IMF traffic in Istanbul until next ThursdayHurriyet Daily News
Turkey tightens security in Istanbul for IMF/World Bank meetingsXinhua

all 519 news articles »

URLZone touted as most sophisticated banking trojan yet

Wednesday, September 30th, 2009

The trojan not only retrieves banking credentials but also is directed to steal money from compromised accounts, often making it appear to the victim that it took less than it actually did.



Adware pushers evolve into malware distribution channel

Wednesday, September 30th, 2009

An industry built on serving adware has become a full-fledged malware distribution channel.



How essential will Microsoft Security Essentials be to you? – guardian.co.uk

Wednesday, September 30th, 2009

Techtree.com
How essential will Microsoft Security Essentials be to you?
guardian.co.uk
We have an interview with Amy Barzdukas, head of Internet Explorer and Microsoft's consumer security, in this week's Technology section (print! It's fun!).
Microsoft releases free Security Essentials downloadTelegraph.co.uk
Microsoft launches free securityBBC News
Microsoft Security Essentials shakes up consumer antivirusRegister
Computerworld -Infosecurity Magazine -Broadband Finder
all 551 news articles »

Prison officers upgraded on criminal security, control – AngolaPress

Wednesday, September 30th, 2009
Prison officers upgraded on criminal security, control
AngolaPress
Luanda – At least 182 prison officers concluded on Wednesday in Luanda, training for specialists of criminal security, re-education, criminal control and

and more »

£2m spent on Parliament security – The Press Association

Wednesday, September 30th, 2009

BBC News
£2m spent on Parliament security
The Press Association
Nearly £2 million is being spent on improving security at the Scottish Parliament, msps have heard. The measures include turnstiles controlled by swipe
£2m for Holyrood securityTeleText

all 17 news articles »

Security guards grab cash back – Bromley Times

Wednesday, September 30th, 2009
Security guards grab cash back
Bromley Times
A SECURITY guard chased thieves down the street who tried to escape with bags of cash. On Saturday at 1.05am in the High Street, Penge, two black men
PENGE: Plucky security guard fends off gang ambushNews Shopper

all 2 news articles »