Facebook Mystery Friend? No, Malware.

Cyber criminals continue to use the popular social networking site Facebook to bait users. A new threat follows the phishing operation that we blogged about just two weeks ago. This current Facebook threat begins with the following spammed email message:

This bogus message tells recipients that a friend has added them to their social [...]

UTM devices are making headway

Customers using unified threat management devices say the appliances represent a more streamlined way to provide multiple security functions and to track down security data, but don’t necessarily meet all gateway security needs adequately.

Read entire article

Memory exhaustion DoS vulnerability hits Google’s Chrome

Aditya K Sood from the EvilFingers community, which disclosed the first Chrome DoS vulnerability at the beginning of the month, has released a proof of concept demonstrating a memory exhaustion DoS vulnerability affecting Google’s Chrome versions Chrome/0.2.149.30 and Chrome/0.2.149.29 :“The Google chrome browser is vulnerable to memory exhaustion based denial of service which can [...]

Clickjacking: Researchers raise alert for scary new cross-browser exploit

Researchers are beginning to raise an alarm for what looks like a scary new browser exploit/threat affecting all the major desktop platforms — Microsoft Internet Explorer, Mozilla Firefox, Apple Safari, Opera and Adobe Flash. The threat, called Clickjacking, was to be discussed at the OWASP NYC AppSec 2008 Conference but, at the request of Adobe [...]

Defense-in-depth in practice

A long portion of my career in information security was spent as a security consultant. I would come into an engagement and either analyze data or an architecture and provide recommendations to the client on improvements they could make in their security posture. Maybe 9 times out of 10 I would be end [...]

Read [...]