Google, Adobe, and Big Oil Under Attack!
From the Infosec Island Network
The work of protecting information is becoming more difficult with time. The recently discovered attacks on Google, Adobe, Marathon Oil, ExxonMobil, and ConocoPhillips illustrate an alarming trend. The attacks even gave rise to a new attack model, the Advanced Persistent Threat (APT)…
Building your OWN Malware Lab (Part 2)
From the Infosec Island Network
Some are using encryption to make it difficult for any security software product to add any an AutoRun to the registry entries to defend itself against anti-malware software, or just by adding a line to the host file to prevent the antivirus from updating their definition. The report by ThreatExpert includes very important information regarding any file and is divided to two parts…
How Twitter Spam Steals From Google, Yahoo!
From the Infosec Island Network
Scammers have been devising ways to ride on someone else’s coattails since the dawn of time. With every new technology they find another way to make money from nothing. I was innocently monitoring my Twitter feed last night when I saw someone tweet “Sophos acquires anti-spam specialist ActiveState.: An article from: Software Industry Report hxxp://censored”. Interesting… I used to work at ActiveState and know we were acquired in 2003. Something was fishy…
Tech Stocks Week in Review Featuring iPad
From Trefis.com
Apple Stock: iPad Business More Valuable Than Mac Desktops - We estimate that Apple’s iPad business accounts for 4% of the $267 Trefis price estimate for Apple’s stock compared to about 3% for Apple’s Mac desktop business…
DoD Endorses Certification for Hackers
From the Infosec Island Network
The U.S. Department of Defense (DoD) announces the official approval of the EC-Council Certified Ethical Hacker (CEH) certification program as a new baseline skills requirement for U.S.cyber defenders. Specifically, the new Certified Ethical Hacker program is required for the DoD’s computer network defenders (CND’s), a specialized personnel classification within the DoD’s information assurance workforce.
Risk Based Enterprise Compliance Programs
By Thomas R. Fox, Attorney at Tom Fox Law
A recent benchmarking survey of Third Party Codes of Conduct was conducted by the Society of Corporate Compliance and Ethics (SCCE) and reported on by Rebecca Walker. The findings indicated that a majority of companies with an otherwise robust compliance program do not extend this to third parties with which they conduct business. For those companies who now desire to evaluate their third party business partners for Foreign Corrupt Practices Act (FCPA) compliance, how and where do they begin?
Data Loss Prevention Has Jumped the Shark
By Robert Siciliano, ID Theft Expert and Security Consultant to Intelius.com
The FTC sending a warning to 100 companies and agencies that their employees are leaking client and sensitive data on the web via Peer to Peer file sharing (P2P) is the single most pathetic and embarrassing communication to come across the desk of an IT professional. It’s over, Johnny IT’S OVER…
File-Sharing Software Threat to Health Privacy
From the Infosec Island Network
There is a real risk of inadvertent disclosure of PHI through peer-to-peer file sharing networks, although the risk is not as large as for PFI. Anyone keeping PHI on their computers should avoid installing file sharing applications on their computers, or if they have to use such tools, actively manage the risks of inadvertent disclosure of their, their family’s, their clients’, or patients’ PHI…
Leveraging Open Source for Business Intel
By Bozidar Spirovski, CISSP, MCSA, MCP
Open source intelligence (OSINT) is a form of intelligence collection management that involves finding, selecting, and acquiring information from publicly available sources and analyzing it to produce actionable intelligence…
Outsourcing Breach Response Lowers Costs
By Doug Pollack, Chief Marketing Officer for ID Experts
The Ponemon Institute last month released their 5th annual 2009 Annual Study: Cost of Data Breach. This year, the report explored several new areas and came up with some interesting and in some cases surprising conclusions…


