Oracle releases critical fixes for Java

, June 19, 2013

Oracle has released version SE 7, Update 25 as its latest update for Java.
 

Malicious email that recipient is on 'Prism watchlist' linked to espionage campaign

June 18, 2013

The group behind the 'NetTraveler' espionage malware campaign is now sending emails claiming the recipient is on the 'Prism' watch list, according to researchers.
 

Denial-of-service attacks often used as a smokescreen for data theft

June 18, 2013

The concept of the 'diverse, distributed denial-of-service' (3DoS) attack is the next threat for businesses that take their eye off the ball when a DoS attack occurs.
 

Call for vendors to share incident data to better help users

June 18, 2013

Vendors with vast incident data repositories could help users if they shared what threat data they had with their competitors.
 

Security disconnect in business shows differences between executives and technicians

June 18, 2013

There is a disconnect between executives and technicians when assessing how secure a company is from cyber threats that reveals differing views on the challenges and successes.
 

Detection times of breaches vary across businesses

June 17, 2013

Only a third of businesses have the ability to detect data breaches within minutes.
 

Women's Security Society enjoys successful launch event

June 17, 2013

A total of 165 people attended the inaugural member's conference of the Women's Security Society (WSS).
 

Accumuli to boost authentication offering with the acquisition of Signify

June 17, 2013

IT security service provider Accumuli has announced the acquisition of managed authentication provider Signify for a net consideration of £2.6 million.
 

OWASP Top 10 released for 2013

June 14, 2013

The Open Web Application Security Project (OWASP) has released its well-referenced Top 10 risks list facing developers.
 

Fraud detection technology launched to offer automated and manual checks

June 13, 2013

Payment service provider Ogone has launched an online payment fraud protection tool that it said aims to reduce false positives relating to automatic or manual checks.
 

Risk manager scoops Infosec prize

June 13, 2013

Exhibiting at Infosecurity Europe for the second year, consultancy CS Risk Management gave away a pair of tickets to the British Grand Prix.
 

New security functions added to Fortinet OS

June 13, 2013

Fortinet has added a variety of security configuration options to the latest version of its FortiOS operating system.
 

Media Group deploys ForeScout solution

June 13, 2013

Omnicom Media Group has deployed ForeScout CounterAct to enable mobile connectivity and network visibility and analytics.
 

Microsoft releases five patches with one critical fix for Internet Explorer

June 12, 2013

Microsoft released five bulletins on its June Patch Tuesday, fixing one critical vulnerability in Internet Explorer.
 

Bit9: A lack of insight into endpoint threats requires greater intelligence for users

June 12, 2013

Users are blind to threats that occur on the endpoint and require intelligence to understand the threat, according to Bit9.
 

SMBs see benefits from the cloud for security and availability

June 12, 2013

Ninety-four per cent of small and medium sized businesses (SMBs) have gained unexpected security benefits due to moving to a cloud environment.
 

RandomStorm launches log analysis and intrusion detection platform

June 11, 2013

RandomStorm has announced the launch of an integrated log analysis, host-based intrusion detection system and file integrity platform.
 

McAfee says it got Koobface infection rates wrong

June 11, 2013

McAfee has said that detections of the Koobface worm have declined, after previously claiming that it had seen a resurgence.
 

Veracode launches mobile application reputation service

June 10, 2013

Veracode has announced the launch of its Mobile Application Reputation Service (Mars) that it claims includes mobile application intelligence and helps prevent inadvertent data leakage on risky mobile applications.
 

Qualys announces QualysGuard enhancements

June 10, 2013

Qualys has announced a series of product launches and enhancements, spearheaded by a small business version of the company's suite of integrated security and compliance solutions.
 

Big Data analysis described as a major skill shortage in security

June 10, 2013

A shortage of capable Big Data analysts is a major challenge for businesses.
 

Security engineer revealed to be source of Prism whistleblowing

June 10, 2013

A former US government IT security engineer has revealed himself to be the whistleblower at the heart of the Prism controversy.
 

Users do not apply Java patch despite its availability

June 07, 2013

A recent Java update was only downloaded by seven per cent of users.
 

ICO fines Glasgow City Council over multiple unencrypted laptop losses

June 07, 2013

The Information Commissioner's Office (ICO) has issued Glasgow City Council with a monetary penalty of £150,000 following the loss of two unencrypted laptops.
 

Microsoft to release one critical bulletin on June Patch Tuesday

June 07, 2013

Microsoft has announced that it is to release five bulletins next week on its June Patch Tuesday.
 

Cyber Security Challenge and UK Cabinet Office take code breaking into the classroom

June 07, 2013

The Cyber Security Challenge has joined with the UK Cabinet Office to take its security talent search into the classroom.
 

Google engineer posts exploit for Windows kernel bug

June 06, 2013

A Google security engineer posted a working exploit for a Windows kernel privilege escalation vulnerability on Sunday that he publicly disclosed last month.
 

Mobile incidents increase, as UK sees adware as main threat

June 06, 2013

More than three-quarters of businesses experienced a mobile security incident in the past year.
 

The FBI, Microsoft and other companies have joined forces to disrupt the Citadel botnet

June 06, 2013

Microsoft, Nominum and other companies have joined with the FBI to disrupt a global cyber crime operation using the Citadel botnet.
 

Axway integrates DLP into new version of file sharing solution

June 05, 2013

Axway has announced the launch of version 5.3 of its DropZone and MailGate SC 5.3 to offer file sharing with integrated data loss prevention (DLP).
 

BeyondTrust launches solution to combine session monitoring with vulnerability and identity management

June 05, 2013

BeyondTrust has announced the launch of version 6.0 of its PowerBroker for Windows solution, to offer session and file integrity monitoring capabilities.
 

Nato announces plans for quick-reaction cyber defence teams

June 05, 2013

Nato has announced plans to form 'quick-reaction cyber defence teams' to protect its and allies' networks.
 

Corporate data loss seen to be a collective responsibility

June 05, 2013

Three-quarters of respondents to a recent poll believe that data loss is a collective responsibility.
 

NetTraveler attacks compromise private sector and embassies

June 05, 2013

A series of advanced attacks have been detected against more than 350 high profile victims in 40 countries.
 

Cost of a data breach tops £2 million

June 05, 2013

The total cost of a data breach to UK organisations has risen to over £2 million, according to research.
 

Deloitte completes acquisition of Vigilant

June 04, 2013

Consultancy Deloitte has acquired the security monitoring and cyber threat intelligence services provider Vigilant.
 

Zscaler announces new mobile security solution

June 04, 2013

Zscaler has launched a security solution to extend its threat protection capabilities to mobile devices.
 

Oracle makes plans for Java security

June 04, 2013

Oracle has said that making Java more secure is a priority, as it lines up regular patch updates.
 

Palo Alto Networks launches private cloud appliance for better detection of APTs

June 04, 2013

Palo Alto Networks has announced the launch of the WildFire WF-500 appliance that it aims will deliver a private cloud solution for timely and thorough detection, analysis and prevention of advanced persistent threats (APTs).
 

Former Barclaycard head of payment security Neira Jones joins consultancy Accourt

June 03, 2013

Former SC Magazine information security person of the year Neira Jones has joined financial services consultancy Accourt.
 

ICO fines former primary care trust £100,000

June 03, 2013

Stockport Primary Care Trust has been issued a £100,000 monetary fine by the Information Commissioner's Office (ICO) after patient records were found at an unused facility.
 

Forrester forum predicts future of cloud delivery and end of central IT

June 03, 2013

In seven years the information security industry will see more cloud delivery and no central IT.
 

Drupal confirms credential breach following third party application vulnerability

May 31, 2013

Hackers have hit the open source content management platform Drupal and captured nearly one million accounts.
 

Google believes zero-day vulnerabilities should be responded to within a week

May 31, 2013

Google researchers have announced a significantly shortened vendor response deadline that they hope others will adopt to spur quicker fixes.
 

Underground talk on large DDoS threats increases following Spamhaus attack

May 30, 2013

There has been online chat around large scale distributed denial-of-service (DDoS) threats following the Spamhaus attack in March.
 

Microsoft to offer threat data in 'near real-time' to Certs and ISPs

May 30, 2013

Microsoft has announced a new initiative aimed at sharing information about botnets, malware and other threat data.
 

Minimum education requirements are needed for an IT security career

May 30, 2013

If the IT security industry is going to be recognised as a profession, we must learn lessons from more established industries.
 

Anonymous UK sets target on English Defence League

May 29, 2013

Hacktivists Anonymous has published the details of members of the far right English Defence League after a warning video was posted online.
 

Stratfor hacker charged, expected to face sentencing in September

May 29, 2013

Former LulzSec and Anonymous member Jeremy Hammond has pleaded guilty to hacking intelligence firm Stratfor to expose millions of emails.
 

Secunia apologises over vulnerabilty disclosure on mailing list

May 29, 2013

Vulnerability management firm Secunia has apologised after an undisclosed vulnerability was sent to a public emailing list.
 

Work with users on password security rather than forcing it on them

May 29, 2013

Password policies should work with what a user is most comfortable with, not deemed by IT or technology.
 

McAfee adds security functions to new endpoint protection solutions

May 29, 2013

McAfee has announced the launch of two new suites in its McAfee Complete Endpoint Protection range: Enterprise and Business.
 

Understand the consequences of human error for corporate security

May 29, 2013

Understanding the human factor in security can be easier if consequences are understood.
 

Masters-level opportunity presented by UK universities and Cyber Security Challenge

May 28, 2013

The Cyber Security Challenge has partnered with 15 UK universities to find ideas from masters' students to discover new ways to improve trust in the online world.
 

ITV and Sky both hit by the Syrian Electronic Army

May 28, 2013

Fresh from Twitter implementing two-factor authentication last week, accounts for ITV news and Sky were hacked over the weekend.
 

Kemp adds authentication features to security technology

May 28, 2013

Kemp Technologies has added authentication and log capabilities to its security offering.
 

Google announces deployment of 2048-bit SSL certificates

May 24, 2013

Google has announced that it is to strengthen its SSL certificates, implementing 2048-bit certificates.
 

CNS Group launches educational PenTest Portal

May 23, 2013

CNS Group's information assurance division CNS Hut3 has launched a PenTest Portal to teach companies how to carry out basic penetration testing techniques on their own systems.
 

Calls made for better synchronisation between solutions and open architecture

May 23, 2013

Vendors should work to an open architecture to ensure that different technologies can work together.
 

Twitter offers two-factor authentication for stronger logins

May 23, 2013

Twitter said it has enabled two-factor authentication.
 

Next-generation firewalls provide protection but add to workload

May 23, 2013

A third of organisations have implemented a next-generation firewall to improve protection from attacks.
 

Blue Coat is to acquire Solera Networks

May 22, 2013

Blue Coat Systems has announced its planned acquisition of Solera Networks.
 

Egynte launches mobile data management solution

May 21, 2013

Egnyte has announced the launch of a mobile data management suite for enterprise.
 

Bit9 announces connectors for Palo Alto Network and FireEye analysis technologies

May 21, 2013

Bit9 has announced the launch of connectors for Palo Alto Networks and FireEye, providing real-time endpoint and network security.
 

Marble Security introduces secure mobile defence technology

May 21, 2013

Marble Security has announced the launch of an enterprise mobile security service.
 

Websense to be acquired by private equity firm for $1 billion

May 21, 2013

Websense is to be acquired by private equity firm Vista Equity Partners for around $1 billion.
 

Research reveals reality of password sniffing over HTTP connections

May 20, 2013

When you load in a login form over HTTP, 'anything you do after that is a little bit pointless'.
 

Sourcefire boosts remediation technology with trajectory and indictators of compromise features

May 20, 2013

Sourcefire has added file detection and trajectory software to allow visibility of threats for remediation.
 

APT infrastructure infecting a wide range of sectors detected in India

May 20, 2013

A large attack infrastructure has been detected as having originated in India.
 

FT suspends Twitter feed after apparent Syrian Electronic Army attack

May 17, 2013

A Twitter feed of the Financial Times has been suspended after it was hacked and malicious links posted.
 

Sandboxed virtual execution space predicted to trickle down to SMB

May 17, 2013

The sandboxed 'virtual execution' space is predicted to grow and be more available to mid-sized businesses.
 

Mobile device management offered free to SMBs

May 17, 2013

Mobile device management (MDM) start-up vendor AppTec has announced the launch of its Enterprise Mobile Manager technology with a small business offering of 25 free licences.
 

LulzSec members sentenced to total of six years, accessory to 32 months

May 16, 2013

Three members of the hacktivist group LulzSec have been sentenced to a total of six years in prison.
 

Indian computer authorities to investigate what led to ATM heist

May 15, 2013

The two payment processors that were attacked to pull off a daring global ATM heist have been named, according to a report.
 

Patch Tuesday sees zero-days in Internet Explorer and Adobe products fixed

May 15, 2013

Microsoft released ten bulletins yesterday fixing 33 vulnerabilities, including the zero-day in Internet Explorer 8.
 

Royal Holloway collects new grant for cyber security training

May 15, 2013

Royal Holloway University has been given a £3.8 million grant to host a new cyber security training centre.
 

ICO research finds lack of understanding around EC data protection proposals

May 14, 2013

Around 87 per cent of businesses are unable to estimate the costs of the draft EC proposals to their business.
 

User engagement can help with training, but accidental breaches are hard to prevent

May 14, 2013

User ignorance is a bigger concern than outsider or internal attacks.
 

Visibility, security and access drives NHS to NAC solution

May 13, 2013

Around 2,000 of the 36,000 users who accessed Sussex's Health Informatics Service (HIS) were doing so from unmanaged mobile devices.
 

Tool reveals Apple user locations

May 13, 2013

An Australian researcher has created a tool that uses Apple's location services to potentially reveal where users live.
 

Microsoft to address IE8 zero-day vulnerability in next Patch Tuesday

May 10, 2013

Microsoft is to address the vulnerability in Internet Explorer 8 that could potentially lead to zero-day attacks in its May Patch Tuesday next week.
 

Get people, privacy and policy correct before allowing collaborative working via mobiles

May 09, 2013

Managing control and compliance of mobile is key to collaborative working.
 

Failure to share information and work collaboratively can cripple a business

May 09, 2013

Collaborative working and information is needed to keep a business working, although security has to be built in.
 

Spain refuses to extradite former HSBC employee who accessed accounts

May 09, 2013

Spain has ruled against extraditing a former HSBC employee who is wanted in Switzerland on charges of stealing bank account data.
 

Privileged account details are often shared and can be a weak entry point for attackers

May 09, 2013

Privileged user accounts can be a way for attackers to infiltrate an entire network.
 

SpyEye Trojan developer and marketer extradited to US

May 08, 2013

One of the masterminds behind the pernicious SpyEye banking Trojan has been extradited to the United States, where he will face charges for computer and wire fraud.
 

Responsibility should be a consideration when it comes to fines for data losses

May 07, 2013

Regulatory fines from the Information Commissioner's Office are 'intelligent', but more responsibility needs to be taken in public sector incidents.
 

Check Point launches small business specific technology

May 07, 2013

Check Point has released an entry-level security appliance for smaller businesses.
 

Microsoft faces IE8 zero-day, after US department serves watering hole attack

, May 07, 2013

A watering hole attack targeting the US Department of Labor (DoL) website served an exploit that took advantage of a previously unknown vulnerability in Internet Explorer 8.
 

McAfee to acquire Stonesoft for £249 million

May 07, 2013

Stonesoft is to be purchased by McAfee in a deal worth £249 million.
 

Security and legal professionals claim 24-hour breach notification will not be a complete burden

May 03, 2013

The proposed 24-hour breach notification law will be a challenge for smaller businesses, but not for enterprises.
 

Former information commissioner claims that data protection has not kept up with technology

May 03, 2013

Technology and data storage developments have left the data protection regulatory model outdated.
 

Vulnerability data shows majority of websites are susceptible to a serious flaw

May 03, 2013

Despite the average number of serious vulnerabilities per website declining in 2012, 86 per cent of all websites tested were found to have at least one serious vulnerability that exposed it to attack.
 

Insider and mobile threats worry IT managers when it comes to data security

May 02, 2013

More than three-quarters of organisations had experienced some form of data security incident in the last year.
 

Fixing the security skills gap is 'in every organisation's best interest'

May 01, 2013

The skills gap will not be solved in the near future while security is not a national topic.
 

FinFisher command-and-control hubs turn up in 11 new countries

, May 01, 2013

Researchers from a Canadian academic institution plan to release new findings pointing to the continued global spread of cyber surveillance software.
 

Awareness programmes should be engaging and allow users to learn

May 01, 2013

Employees should be able to apply a level of risk management in order to protect the business and themselves.
 

Reputation.com attacked and user details are breached

May 01, 2013

Hackers have hit the database of online 'reputation management' company Reputation.com, exposing names, email and physical addresses, phone numbers and personal details.
 

Key and certificate challenges could end up costing UK businesses £247 million

May 01, 2013

A lack of control over cryptographic keys and certificates could leave large UK businesses open to attack.
 

Trustwave launches three mobile-specific services

May 01, 2013

Trustwave has launched a mobile security practice to offer enterprise compliance and risk services to address the challenges and complexities of mobility.
 

SC Webcasts

Security beyond the (fire)wall

Streaming live on 19th June at 3pm BST

This webcast addresses the technological challenges of maintaining full control of your most sensitive information - even once it goes beyond the firewall - while maintaining the freedom and flexibility necessary to allow your staff and other stakeholders to work as efficiently as possible. Tune in for free to hear from our regular and popular guest speaker, Bola Rotibi from (ISC)2 application security advisory board. To secure your place, please click here.


The truth about vulnerability management: Compliance checkbox or real protection?

Streaming live 2nd July at 3pm BST

How often are you assessing network vulnerabilties? Is your current vulnerability management program merely a compliance checkbox for auditors? Tune into this webcast live to hear from Joerg Weber, head of attack monitoring, Barclays, Lee Barney, an information risk consultant, and Skybox's Michelle Cobb on how you can prioritise vulnerabilities in a way that makes sense for your specific threat posture. Secure your free place here.

SC Whitepapers

Ponemon 2012 Global Encryption Trends Study

In Ponemon's recent Global Encryption Study, the organisation surveyed 4,205 information security professionals across seven countries to examine how encryption has evolved over the last eight years. The study focused on data protection priorities, budgeted expenditures for encryption and the types of encryption technologies involved, with the findings revealing some interesting insight into the relationship between encryption and its impact on the security position of organisations. To read the full report for free, please download it here.


Home | News | Products | Whitepapers | Jobs | Subscribe | Contact Us | About Us | Advertising | Sitemap | Editorial | Subscribe to our RSS feeds RSS

This material may not be published, broadcast, rewritten or redistributed in any form without prior authorization.

Your use of this website constitutes acceptance of Haymarket Media's Privacy Policy and Terms & Conditions