Global Security Watch > June 28, 2008

Malicious Web Site / Malicious Code: ICANN Web Site Compromise

Latests Alerts From Websense Security Labs[Latests Alerts From Websense Security Labs] The ICANN and IANA web sites were defaced and left the following message: “You think that you control the domains but you don’t! Everybody knows wrong.

Read related posts for „Malicious Web Site / Malicious Code: ICANN Web Site Compromise“.


 

Reports Detail Progress in Afghan Security, National Forces

Afghan Regional Security Integration Command- Southhttp://arsicsouth7.wordpress.com/2008/06/28/reports-detail-progress-in-afghan-security-national-forces/ [Afghan Regional Security Integration Command- South] The Report on Progress Toward Security and Stability in Afghanistan depicts a “fragile” security environment in much of the country. It concludes, however, that coalition forces’ counterinsurgency approach has demonstrated how a hybrid of military and nonmilitary resources can create stability and connect Afghan citizens to their government.

Read related posts for „Reports Detail Progress in Afghan Security, National Forces“.

Posted at 02:32 PM

June 28, 2008

Malicious Web Site / Malicious Code: ICANN Web Site Compromise

Latests Alerts From Websense Security Labs[Latests Alerts From Websense Security Labs] The ICANN and IANA web sites were defaced and left the following message: “You think that you control the domains but you don’t! Everybody knows wrong.

Read related posts for „Malicious Web Site / Malicious Code: ICANN Web Site Compromise“.

Posted at 02:34 PM

Reports Detail Progress in Afghan Security, National Forces

Afghan Regional Security Integration Command- Southhttp://arsicsouth7.wordpress.com/2008/06/28/reports-detail-progress-in-afghan-security-national-forces/ [Afghan Regional Security Integration Command- South] The Report on Progress Toward Security and Stability in Afghanistan depicts a “fragile” security environment in much of the country. It concludes, however, that coalition forces’ counterinsurgency approach has demonstrated how a hybrid of military and nonmilitary resources can create stability and connect Afghan citizens to their government.

Read related posts for „Reports Detail Progress in Afghan Security, National Forces“.

Posted at 02:32 PM

June 26, 2008

Security Tip: Blocking Access to ASP.NET MVC Views Using ...

you've been HAACKEDhttp://haacked.com/archive/2008/06/25/aspnetmvc-block-view-access.aspx [you've been HAACKED] When you create a new ASP.NET MVC project using our default templates, one of the things you might notice is that there is a web.config file within the Views directory. This file is there specifically to block direct access to a view.

Read related posts for „Security Tip: Blocking Access to ASP.NET MVC Views Using ...“.

Posted at 02:32 PM

BUG: XSS Security flaw in BaseCamp Messages

Untitledhttp://simonwillison.net/2008/Jun/26/bug/ [Untitled] BaseCamp lets users include HTML and JavaScript in messages, on the basis that anyone with a BaseCamp account is a trusted party. I’m not convinced: you could use this to circumvent .

Read related posts for „BUG: XSS Security flaw in BaseCamp Messages“.

Posted at 02:31 PM

June 24, 2008

Improving OS X Security

securosis.comhttp://securosis.com/2008/06/23/improving-os-x-security/ [securosis.com] These are fully exploitable on Macs and other Apple products until Apple issues an update. I realize this is a very tough issue, because Apple needs to run through extensive evaluation and testing before releasing updates, but they can mitigate this timeline by engaging deeply with those various open source teams to reduce the windows where users are exposed to the vulnerabilities.

Read related posts for „Improving OS X Security“.

Posted at 02:06 PM

New ID Requirements: The First 48

Evolution of Securityhttp://www.tsa.gov/blog/2008/06/new-id-requirements-first-48.html [Evolution of Security] What these folks aren't getting is that by requiring ID, you're closing that old loophole that allowed (up until Saturday) anyone, good or bad, to show up with any boarding pass (theirs or someone else's), say they lost their ID, get a pat-down and bag check and be on their way. Now, no self respecting terrorist is going to subject him or herself to all the additional attention the new procedures brings.

Read related posts for „New ID Requirements: The First 48“.

Posted at 02:05 PM

June 21, 2008

Trend Micro announces email encryption solution portfolio

Digg / Security / upcominghttp://digg.com/security/Trend_Micro_announces_email_encryption_solution_portfolio [Digg / Security / upcoming] Trend Micro Inc., a provider of Internet content security, announced Wednesday its entry into the email encryption marketplace, with the launch of Trend Micro Email Encryption Client 5.0 and Trend Micro Email Encryption for InterScan Messaging Hosted Security (IMHS).

Read related posts for „Trend Micro announces email encryption solution portfolio“.

Posted at 02:32 PM

Product Review: IronKey USB Memory and Encryption

Full text legal articles - Content for Reprinthttp://www.content4reprint.com/legal/product-review-ironkey-usb-memory-and-encryption.htm [Full text legal articles - Content for Reprint] IronKey offers the following features: drive contents encrypted using AES CBC-mode encryption, a true random number generator for the maximum protection generates encryption keys in hardware, securely stores passwords, fast (30MBPS) read, fast (20MBPS) write, encased in a potted metal case- not plastic which makes it one of the strongest USB keys around, exceeds military waterproofing standards, and has the ability to safely tunnel through insecure wireless networks.

Read related posts for „Product Review: IronKey USB Memory and Encryption“.

Posted at 02:31 PM

June 19, 2008

Obama Announces Senior Working Group on National Security

Obama HQ[Obama HQ] Senator Obama today announced the formation of his Senior Working Group on National Security, a group of advisors that he will consult on a regular basis between now and the election. Obama will meet with the group for the first time today in Washington, DC for a wide-ranging discussion of the immense challenges faced by the United States in the wake of the disastrous foreign policies of George Bush.

Read related posts for „Obama Announces Senior Working Group on National Security“.

Posted at 02:32 PM

Obama Convenes National Security Team

The Caucushttp://thecaucus.blogs.nytimes.com/2008/06/18/obama-convenes-national-security-team/ [The Caucus] The presumptive Republican nominee and the president will tour areas of Iowa hard hit by floods on Thursday, but the McCain campaign said that it was not trying to step on Mr. Bush’s trip.

Read related posts for „Obama Convenes National Security Team“.

Posted at 02:31 PM

June 17, 2008

Beware of Yahoo Search Marketing Phishing Email Scams

Search Engine Roundtablehttp://feeds.seroundtable.com/~r/SearchEngineRoundtableFull/~3/313737197/017428.html [Search Engine Roundtable] A couple weeks ago we reported that more Google AdWords phishing email scams were being sent out. While those emails continue to be sent out, the same scam artists are sending out similar emails branded for Yahoo Search Marketing.

Read related posts for „Beware of Yahoo Search Marketing Phishing Email Scams“.

Posted at 02:02 PM

Fake Postcards Send Malware Greetings

TrendLabs | Malware Blog - by Trend Microhttp://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/313732272/ [TrendLabs | Malware Blog - by Trend Micro] Trend Micro Content Security recently came across an all-in-one attack that involves a fake postcard, a phishing site and of course, a malware. A fake postcard launcher was found pretending to be Gusanito, one of the most popular .

Read related posts for „Fake Postcards Send Malware Greetings“.

Posted at 02:02 PM

June 14, 2008

Secure Account Update.

Phishing Scamshttp://www.millersmiles.co.uk/report/7252 [Phishing Scams] The spoof website this email links to was not online at time of this report, but variations of the scam which link to working websites are bound to exist, so be wary! The website may have been taken down or disabled by the hosts, but quite often these websites are hosted on the personal computer of the phishers, so may only be online at certain times.

Read related posts for „Secure Account Update.“.

Posted at 02:37 PM

Beware of PICS FOR MSN FRIENDS Phishing Websites

Absolute Underground[Absolute Underground] First thing is to tell your friends to change their password or phasphrase. By doing that, the bots can no longer access your friend’s MSN account and spam their contact list.

Read related posts for „Beware of PICS FOR MSN FRIENDS Phishing Websites“.

Posted at 02:32 PM

June 12, 2008

Privacy laws regarding kids called into question

Opinion - The Oregonian - OregonLive.comhttp://blog.oregonlive.com/oregonianopinion/2008/06/privacy_laws_regarding_kids_ca.html [Opinion - The Oregonian - OregonLive.com] tags[tags.length] = "Oregonian";blogs[blogs.length] = "1562"; titles[titles.length] = "Jack Ohman";cats[cats.length] = "Jack Ohman";

Read related posts for „Privacy laws regarding kids called into question“.

Posted at 02:38 PM

Live Notes from “Privacy & Data Portability for Social Networks”

Inside Facebook[Inside Facebook] Morin: In regards to dynamic privacy, a simple example of is when I choose to use my Facebook profile picture and name on another site and then change that same picture on Facebook I want that change to be reflected on that other site as well automatically.

Read related posts for „Live Notes from “Privacy & Data Portability for Social Networks”“.

Posted at 02:37 PM

June 10, 2008

Medical Identity Theft Could Be A Matter Of Life And Death

Identity Theft Protection[Identity Theft Protection] Its noticable (once you know to look) that medical identity theft never gets a mention in the advertising literature of these identity theft protection services. Thats because placing a fraud alert by your name with a credit agency does nothing to protect you against medical identity theft just as it does nothing to stop a criminal applying and taking a job in your name so that they can rob their new employer, again in your name.

Read related posts for „Medical Identity Theft Could Be A Matter Of Life And Death“.

Posted at 02:02 PM

New Identity Theft Stats

securosis.comhttp://securosis.com/2008/06/09/new-identity-theft-stats/ [securosis.com] On our call Debix committed to providing more statistics down the road (all anonymized of course). We gave them a few suggestions, including some ways to add controls to their analysis, and I’m really looking forward to seeing what numbers pop out in the coming years.

Read related posts for „New Identity Theft Stats“.

Posted at 02:01 PM

June 07, 2008

Israeli-Style Airport Security Coming to US?

Pajamas Mediahttp://pajamasmedia.com/blog/israeli-style-airport-security-coming-to-us/ [Pajamas Media] Security experts familiar with Israel’s behavior profiling system have long since criticized U.S. airport security for its approach. The lion’s share of TSA’s $4.9 billion annual budget is spent looking for bombs, not bombers.

Read related posts for „Israeli-Style Airport Security Coming to US?“.

Posted at 02:34 PM

Iraqi Security Forces Order of Battle: June 2008 Update

The Long War Journal[The Long War Journal] During a May 28 briefing, General Abadi, the second-ranking officer in the Iraqi Armed Forces said operations in the Shula neighborhood, a Mahdi Army stronghold in Baghdad, have been put on hold due to a shortage of Iraqi forces.

Read related posts for „Iraqi Security Forces Order of Battle: June 2008 Update“.

Posted at 02:33 PM

June 05, 2008

“Bonnie’s” Identity Theft and Fraud Plea Hearing Postponed (KYW ...

I Stole Your Identity[I Stole Your Identity] Federal prosecutors say a Philadelphia plea hearing is being postponed for a young beauty charged with identity theft that helped pay for a year of lavish world travel.

Read related posts for „“Bonnie’s” Identity Theft and Fraud Plea Hearing Postponed (KYW ...“.

Posted at 02:40 PM

“The thieves are just getting better and there’s more fraud”

The Whistler's Earhttp://whistlersear.wordpress.com/2008/06/05/the-thieves-are-just-getting-better-and-theres-more-fraud/ [The Whistler's Ear] Romanosky’s team took a state-by-state look at FTC identity theft complaints filed between 2002 and 2006 to see whether there was a noticeable impact on complaints in states that had adopted data breach notification laws such as California’s SB 1386, which compels companies and institutions to notify state residents when their personal information has been lost or stolen. Their paper is set to be presented at a conference on Information Security Economics held at Dartmouth College later this month.

Read related posts for „“The thieves are just getting better and there’s more fraud”“.

Posted at 02:35 PM