Survey: 37% of employees would become insiders given the right incentive

Would you sell sensitive company data if you’re offered the right incentive? Using the current economic situation, or pure greed as an excuse, 37% of  employees surveyed at this year’s Infosecurity Europe event said that they are keeping their options open. What type of information are they willing to sell, and what kind of [...]

Five ‘must-secure’ Web app vulnerabilities

Security holes in the Apache Geronimo Application Server and SAP cFolders headline a list of five serious Web app vulnerabilities that demand immediate attention. According to Mark Painter from the HP Security Laboratory, the Geronimo flaws expose users to a variety of attack vectors that could lead to the theft of sensitive information and [...]

Online broker CommSec criticised for weak passwords, lack of SSL

In times when vendors are vertically integrating by offering virtual keyboards for secure Ebanking, and banks themselves are requiring end users to run antivirus software if they were to file a fraud claim, others are busy fixing security design flaws. Earlier this month, a Melbourne based computer programmer discovered that the 1.7m customers of [...]

Adobe: Turn off JavaScript in PDF Reader

In response to confirmed reports of a zero-day vulnerability in its PDF Reader software, Adobe today urged users on all platforms to disable JavaScript as a temporary measure to avoid code execution attacks. In sharp contrast to previous problems in responding to known security issues, the company acted swiftly to provide information on the affected [...]

Windows AutoRun gets a makeover to combat malware

In direct response to Conficker and an increased wave of malware attacks targeting the dangerous Windows AutoRun mechanism, Microsoft today announced significant changes to the way the operating system operates when USB drives are used.

[ Roel Schouwenberg: Is there no end to the AutoRun madness? ] The changes, detailed on Redmond’s Security Research & [...]