Security6 – Security news on IT threats, vulnerabilities

Secunia brings own spin to vulnerability rewards programs

January 24, 2012 by security6 in Website Security

Another day, another vulnerability reporting reward program. Kinda.

Read More:
Secunia brings own spin to vulnerability rewards programs

Report: ‘R&D is under attack’ from China, Russia

January 24, 2012 by security6 in Website Security

According to a U.S. intelligence report made available to Congress, foreign nations and other actors are using cyberespionage to take sensitive technology and trade data, and those actions pose a threat to American interests. Reuters reported Thursday that in a report titled “Foreign Spies Stealing US Economic Secrets in Cyberspace,” the Office of the National Counterintelligence confirmed that foreign intelligence services, corporations and individuals have increased their efforts to take research and development data relating to U.S

Link:
Report: ‘R&D is under attack’ from China, Russia

Cloud security among PCI Council 2012 special interest groups

January 24, 2012 by security6 in Website Security

The PCI Security Standards Council announced the latest slate of special interest groups that it will prioritize next year. Merchants, financial institutions, service providers and others voted on a variety of potential SIGs before settling on cloud, ecommerce security and risk assessment

Read More:
Cloud security among PCI Council 2012 special interest groups

Facebook users targeted by transformed Carberp Trojan

January 19, 2012 by security6 in Website Security

Attackers seize on the trust victim?s have in the social network by setting up a tricky man-in-the-browser attack and demanding $25 in cash.

Read the original post:
Facebook users targeted by transformed Carberp Trojan

Symantec breach: Data breach basis of Norton source code leak

January 19, 2012 by security6 in Website Security

Investigators confirmed that a 2006 breach at Symantec Corp. is the root cause of a source code leak of its Norton Antivirus software.

Read the original post:
Symantec breach: Data breach basis of Norton source code leak

Rapid7 massive VC funding opens door to acquisitions, expansion and maybe IPO?

January 18, 2012 by security6 in Website Security

Vulnerability management company Rapid7, commercial home of the Metasploit Project, announced today it has secured $50 million in venture funding from Technology Crossover Ventures of Palo Alto, Calif. The company said it will use the money for new hires, international expansion and to explore acquisitions. Bigger picture, Rapid7 could also position itself for an initial public offering, something CEO Mike Tuchen would not address in an interview with SearchSecurity.com

More here:
Rapid7 massive VC funding opens door to acquisitions, expansion and maybe IPO?

Symantec launches mobile security evaluation, app assessment services

January 18, 2012 by security6 in Website Security

Security assessment reviews an organization’s mobile security policies and technologies, evaluating the mobile security posture against a set of 15 core elements. Symantec’s consulting team is launching a mobile security assessment service , designed to assess a business’ mobile security policies and defensive technologies. The new service is an extension of the Symantec Security Program Assessment.

View original post here:
Symantec launches mobile security evaluation, app assessment services

Website weaknesses at fault in T-Mobile hacktivist attack

January 17, 2012 by security6 in Website Security

A hacktivist group is claiming responsibility for exploiting website vulnerabilities and stealing the personal information of approximately 80 T-Mobile employees.

Read the article:
Website weaknesses at fault in T-Mobile hacktivist attack

Nitro attackers sending malicious emails using Symantec report

January 11, 2012 by security6 in Website Security with 0 Comments

By Hillary O’Rourke, Contributor The cybercriminals responsible for the Nitro attacks have certainly showed audacity in their latest move: Sending malicious emails claiming to be from security vendor Symantec with the company’s own report on those Nitro attacks. According to a Symantec blog post, the group, which is currently targeting chemical companies, is using the same social engineering techniques they have used in previous attacks, but lately they have been sending malicious emails that are created to look like they were sent by Symantec’s technical support department. “They are sending targets a password-protected archive, through email, which contains a malicious executable,” explained Symantec researchers keeping a close watch on the group’s attack techniques.

Visit site:
Nitro attackers sending malicious emails using Symantec report

Typosquatter hive targets holiday shoppers

January 11, 2012 by security6 in Website Security with 0 Comments

Every year the holiday season is a boon to typosquatters using scams to phish unsuspecting users of sensitive information or peddle rogue antivirus software. By Hillary O’Rourke, Contributor With the hassle of finding the best deal and coping with the constant crowds, online shopping has never been more popular for the holiday season. But with that ease comes a warning from Websense: keep an eye out for online scams, particularly typosquatted sites

Continued here:
Typosquatter hive targets holiday shoppers

Page 1 of 612345»...Last »