EnterpriseSecurity
SecurityProNews
ITmanagement






The Latest Internet News
Add Headlines for your site

Top Articles

Enterprise 2.0: A Security Nightmare
[2008-04-30] Steve Lohr posts Enterprise 2.0: A Security Nightmare on the NY Times Bits blog. Its the kind of fear sells story that is inevitable.

Our Broken Information Security Business
[2008-04-02] 4.2 million accounts were exposed in a supermarket data hack.

G-Archiver Pulls Their Software From Distribution
[2008-03-12] G-Archiver, the software that was previously caught by coding horror and blogged about here has pulled the version of the software that captures user credentials and e-mails them to Google. From the time it was discovered by Coding Horror on the 7th through to this morning when the tainted version was pulled is about 5 days.

Enterprise CMS Fall Short on Security Demands
[2008-02-13] CMS Watch released research that finds Enterprise Content Management (ECM) products ill-equipped to meet the security requirements of Service Oriented Architectures (SOA).

Flash Vulnerabilities Discovered by Google Researchers
[2008-01-08] The Register reports that Google Researchers have documented serious vulnerabilities in Adobe Flash content which leave tens of thousands of websites susceptible to attacks that steal the personal details of visitors.

Hackers Bypassing Registration with PyCurl
[2007-12-12] Interesting hacking attack going on at a social networking site that I am working on today.

Google's Checklist Of Helpful Webmaster Security Tips
[2007-09-20] The official Webmaster blog has a helpful post has a list of Quick security checklist for webmasters.

Ajax Security Features in ColdFusion 8
[2007-08-14] There are some interesting new features in ColdFusion 8 related to security that I thought I'd share.

Firefox Automatic Update
[2007-05-30] Firefox automatic update might be something security folks need to watch out for when they automatically update.

ColdFusion Security Reminder - READ NOW
[2007-05-18] I know I've blogged this before, and it's covered in my security checklist, but folks, stop what you are doing and make these changes right now on your production server...

Unifying Fragmented Security Systems
[2007-05-09] One of the promises of Web 2.0 widgets is that it can take data from various inputs and output them into various formats, and views.

Retiring the Browser
[2007-04-25] The time when Internet Explorer, Safari, Netscape, and Firebox as your window to the internet is just about done for. What is going to replace it?

Preventing & Exposing Errors in Ajax Applications
[2007-04-23] Ajax.sys-con is running a good article on Ajax and application security that is a good read.

How Britney Spears Relates to Insider Threats
[2007-02-26] No, I am not nuts, but if you want a perfect example of personality changes that could precipitate into an insider threat to a company, look no further than people magazine.

Penetration Testing vs. Vulnerability Analysis Tools
[2007-02-13] Over the past several years I have heard people asking the question "should I use vulnerability analysis tools to assess my web based applications or should I look to penetration testing?"

Review: SpiDynamics Web Inspect
[2007-01-30] Every once in a while, you run into a tool that becomes an essential member of your tool kit, like snort for IDS, Nessus for scanning a network, the new version of Web Inspect by SpiDynamics has become just as essential.

Corporate Email Wanders
[2007-01-15] Technewsworld is running a story on company personnel who forward company e-mail to their MSN, Google, Yahoo, or other hosted e-mail accounts.

Insider Threats
[2007-01-02] Organizations in many ways contribute the actions of their employees.

Computer Security Still Damaged by Social Engineering
[2006-12-05] Interesting article out of CIO magazine about Vista, and that while it is a highly secure operating system, with some neat things it can do, it still is not invulnerable to those programs that require social engineering to get the user to do something.

Collaborative Information Security Next?
[2006-11-14] Have anyone ever been on the phone with a client after the job, where the client wants more information, needs a copy of the report, or just wants to spend some time discussing the implications of the report that the company generated for them?

eBay Launches Web Smart Guide For Safety
[2006-09-05] According to a recent survey, a lot of Australians feel the online world is becoming a safer place to shop - 76 percent, to be exact.

RSS Exposes Users to Attack
[2006-08-04] ZDNet reports from the Black Hat conference in Las Vegas that security experts are increasingly concerned about the potential for malicious attacks perpetrated through web feeds.

RFID Technology Vulnerable To Malware
[2006-07-17] RFID tags may become commonplace in the future, but not a lot of people are looking forward to widespread implementation. There was already concern that these "smart barcodes" would allow consumers' habits to be more easily tracked, and that the technology could facilitate identity theft. It turns out that RFID tags can transmit computer viruses, as well.

NSA Eyes Social Networking Sites
[2006-06-09] It was revealed last month that the National Security Agency has been tracking the phone calls of millions of Americans.

Root Kit Hunter
[2006-05-19] I had a strange problem with one of my own RedHat machines the other day. Very simply, I couldn't su to root, and I couldn't even login at the console as root.