IT Security Training

RSA: Cybercriminals keeping up with banking safeguards

April 22, 2009

Threats are becoming more sophisticated, and cybercriminals are getting smarter at evading new authentication controls, according to an RSA Conference panel of security practitioners representing three major financial institutions.
 

Trustwave branches out into application pen-testing

May 26, 2008

The security services company is to try to help enterprises protect their web-based apps from attacks like SQL injection, buffer overflow and cross-site scripting
 

Firebrand launches disaster recovery training

May 19, 2008

How to prepare a disaster recovery plan and DR policy plus how to assess risks are among the topics taught at a residential training course aimed at security professionals
 

SPI Dynamics creates script-based, self-propagating website vulnerability scanner

Dan Kaplan March 22, 2007

A security researcher on Saturday is set to unveil the first website-scanning script, a tool which allows attackers to gain control of infected users' web browsers and drastically reduce the time it takes to search the web for vulnerabilities.
 

RSA Conference 2007: Does end-user education work?

Dan Kaplan February 08, 2007

Educating consumers about internet risks is a dicey proposition, one security expert said during a panel at RSA Conference 2007 in San Francisco.
 

RSA Conference 2007: Don't worry, be happy to achieve security agenda, says ConAgra Foods risk exec

Dan Kaplan February 08, 2007

Smile, relax, listen and exude confidence — but keep that ego in check. Oh, and don't forget that morning pep talk with yourself.
 

IT security industry gathers at RSA Conference 2007

Ericka Chickowski February 06, 2007

Security professionals from around the globe gathered in San Francisco today to kick off RSA Conference 2007.
 

Experts say global cooperation key to fighting cybercrime

Dan Kaplan February 01, 2007

International cooperation among law enforcement agencies is key to taking the allure from cybercrime, a panel of experts said today at a Kaspersky Lab-sponsored breakfast in New York.
 

Data security firms start Payment Card Industry Vendor Alliance

Ericka Chickowski January 31, 2007

A handful of data security companies announced they're forming a new alliance to advocate for firms who must comply with the payment card industry data security standards (PCI DSS).
 

Webroot: Windows Vista is more secure, but not secure enough

Dan Kaplan January 29, 2007

Windows Vista may be hailed as Microsoft's most secure operating system to date, but the platform contains weaknesses in its default anti-malware capabilities, one security vendor has concluded.
 

Academics warn of fingerprint biometrics weaknesses

Ericka Chickowski January 24, 2007

Experts from the University of California, Davis warned this week that the reliability of fingerprint biometrics has declined considerably due to technological concerns and a growing world population.
 

Sophos: U.S. still world's spam leader; attackers warm to web threats

Ericka Chickowski January 23, 2007

While the percentage of infected emails declined significantly last year, web-related threats rose significantly, reported researchers at Sophos this week.
 

No slowing growth of image spam in 2006

Frank Washkuch Jr. January 18, 2007

The use of image spam continues to grow, now accounting for as much as two-thirds of all spam, security researchers said this week.
 

Spammers hijacking legit newsletters

Frank Washkuch Jr. January 16, 2007

Newsletter creators aren't the only ones hoping their products don't get caught in spam filters now that hackers have begun using newsletters to launch spam.
 

Court orders Movieland.com to limit pop-ups

Dan Kaplan January 12, 2007

A U.S. District Court in California has ordered a movie download service to stop barraging users with pop-up advertisements.
 

CA backup and recovery solution contains flaws

Dan Kaplan January 11, 2007

Two vulnerabilities were reported today in a CA backup and recovery solution that, if exploited, could allow an attacker to execute remote code and gain unauthorized administrative privileges.
 

'Make your own man-in-the-middle attack' online kit found

Dan Kaplan January 10, 2007

Fraudsters are hawking free trials of "universal" man-in-the-middle phishing kits through an online forum, security researchers said today.
 

PayPal, Barclays are phishers' favorites, according to PhishTank

Frank Washkuch Jr. January 08, 2007

PayPal, Barclays Bank and eBay were the three firms most targeted by phishers last month, according to statistics compiled by PhishTank users.
 

Late-emerging New Year's scam was December's top virus

Frank Washkuch Jr. January 04, 2007

A worm posing as a New Year's greeting has been ranked as last month's most widespread virus, despite not appearing until Dec. 30.
 

Man-in-the-middle phishing scheme targets Amazon.com

Dan Kaplan January 03, 2007

Amazon.com is the latest target of a new wave of phishing schemes known as man-in-the-middle attacks.
 

Google fixes Gmail cross-site request forgery flaw

Dan Kaplan January 02, 2007

Web application giant Google said today that it has fixed what researchers described as a cross-site request forgery vulnerability that could allow an attacker to steal a Gmail user's contact list.
 

IM threats jump 15 percent in 2006, says Akonix

Frank Washkuch Jr. January 02, 2007

More than 400 attacks on instant messenger (IM) platforms were spotted last year, an increase of 15 percent from the year before, according to researchers at Akonix.
 

Firm: Seven steps for a more secure network

Greg Masters December 27, 2006

IT security professionals should rely on personal vigilance and implemented methodologies - not just the slew of new products hitting the marketplace - to protect their networks in 2007.
 

New Year's, Christmas malware targeting inboxes

Frank Washkuch Jr. December 27, 2006

Email users are again getting the electronic age's version of coal in a stocking - holiday-season spam and malware.
 

Hackers greet CafePress.com with holiday DoS attack

Ericka Chickowski December 22, 2006

The popular ecommerce website CafePress told members it was hit by distributed denial-of-service (DDoS) attacks this week.
 

Big Yellow worm avoids Microsoft applications, targets Symantec products, says eEye

Frank Washkuch Jr. December 15, 2006

Researchers at eEye Digital Security have discovered malware with both botnet and worm characteristics that targets Symantec anti-virus software, not Microsoft applications.
 

Avert Labs snags PoC mobile spyware

Frank Washkuch Jr. December 11, 2006

Researchers from McAfee Avert Labs claim to have discovered proof of concept (PoC) spyware for mobile devices.
 

eEye releases Zero-Day Tracker

Ericka Chickowski December 07, 2006

Researchers with eEye Digital Security released a new vulnerability tracking tool this week designed to help security practitioners reduce their risks of Zero-Day attacks.
 

Some websites reporting common error code contain adware

Dan Kaplan December 04, 2006

Web surfers are accustomed to seeing a 404 error message when they try to reach a website that is not available. But now hackers are using that common occurrence to their advantage by creating fake sites containing the error message to load spyware and adware, security researchers said today.
 

Vista launch: New OS vulnerable to common threats

Ericka Chickowski December 01, 2006

Microsoft Vista is susceptible to common malware attacks that have been in the wild for more than two years, experts at Sophos warned this week.
 

SC Webcasts

Security beyond the (fire)wall

Streaming live on 19th June at 3pm BST

This webcast addresses the technological challenges of maintaining full control of your most sensitive information - even once it goes beyond the firewall - while maintaining the freedom and flexibility necessary to allow your staff and other stakeholders to work as efficiently as possible. Tune in for free to hear from our regular and popular guest speaker, Bola Rotibi from (ISC)2 application security advisory board. To secure your place, please click here.


The truth about vulnerability management: Compliance checkbox or real protection?

Streaming live 2nd July at 3pm BST

How often are you assessing network vulnerabilties? Is your current vulnerability management program merely a compliance checkbox for auditors? Tune into this webcast live to hear from Joerg Weber, head of attack monitoring, Barclays, Lee Barney, an information risk consultant, and Skybox's Michelle Cobb on how you can prioritise vulnerabilities in a way that makes sense for your specific threat posture. Secure your free place here.

SC Featured Webcast

Employee file sharing: the good, the bad and the ugly

This recently held webcast unveiled the full results from the latest data security survey, where it was revealed that 50 per cent of the information security professionals asked said that they had 'no real visibility' of how data is being sent within and outside the company. Guest speakers included the director of information security from Monster.co.uk and the ISO from Atos. If you missed the live show, you can tune into the on-demand video here.

SC Whitepapers

Java security: Balancing existing testing platforms with open source solutions

In a rush to get new products out to market quickly, companies expose themselves to the risk of software failure. Java developers often turn to open source solutions to help protect themselves from risk. This new whitepaper explains how you can use your existing testing platforms alongside open source solutions to fix those issues related to both security and quality within your Java code. To download the paper for free, please click here.


DDoS and downtime: Considerations for risk management

The purpose of this paper is to start a conversation about the often overlooked risk of downtime caused by DDoS attacks and to provide sufficient content for risk managers to account for the DDoS threat as they evaluate risks to their day-to-day operations and long-term mission. To read the paper in full, please download it for free here.


Ponemon 2012 Global Encryption Trends Study

In Ponemon's recent Global Encryption Study, the organisation surveyed 4,205 information security professionals across seven countries to examine how encryption has evolved over the last eight years. The study focused on data protection priorities, budgeted expenditures for encryption and the types of encryption technologies involved, with the findings revealing some interesting insight into the relationship between encryption and its impact on the security position of organisations. To read the full report for free, please download it here.


Advanced spear phishing: The rise of industrial phishing attacks

With phishing still the most common form of attack, hackers are now engaging in industrial-scale phishing attacks that leverage sophisticated customisation and delivery techniques. Borrowing tactics from cloud computing and database marketing, this study looks at longline phishing - an advanced form of spear phishing, which has higher clickthrough and penetration rates than traditional attacks, potentially causing a higher risk to IT security departments across the world. To read the study for free, please click here.


Home | News | Products | Whitepapers | Jobs | Subscribe | Contact Us | About Us | Advertising | Sitemap | Editorial | Subscribe to our RSS feeds RSS

This material may not be published, broadcast, rewritten or redistributed in any form without prior authorization.

Your use of this website constitutes acceptance of Haymarket Media's Privacy Policy and Terms & Conditions