Security Wire Weekly


April 8, 2010  7:28 PM

Cloud computing risks, challenges



Posted by: Jessica Scarpati
cloud computing, Security Wire Weekly

K. Scott Morrison, CTO and chief architect at Layer 7 Technologies talks about some of issues hindering adoption of cloud computing. Also, Wade Baker of Verizon on that firms new security incident framework.

March 25, 2010  5:28 PM

Pwn2Own hacker contest – DOE CISO on encryption



Posted by: Jessica Scarpati
encryption, hacking, Security Wire Weekly

A brief look at the Pwn2Own hacker contest at the CanSecWest Applied Security Conference in Vancouver, BC. Also Department of Education CISO Phil Loranger on encryption.


March 18, 2010  7:30 PM

Web application attacks security guide: Preventing attacks and flaws



Posted by: Jessica Scarpati
Cross-site scripting, Threat Monitor

Threat MonitorFrom buffer overflows to SQL injection, hackers have many techniques at their disposal to attack Web applications, and new methods constantly emerge. This week’s podcast edition of Threat Monitor highlights one of the tips from this special Web application attack security guide, entitled: Prevent cross-site scripting hacks with tools, testing.


March 16, 2010  12:13 PM

Squad: RSA Conference 2010 in review



Posted by: Jessica Scarpati
2010 RSA Conference, Security Squad

The editorial team recalls the themes and discussions that dominated the 2010 RSA Conference. Federal cybersecurity issues ruled with the debut of White House cybersecurity coordinator Howard Schmidt. Microsoft’s Scott Charney explained the legal action the software giant took to disrupt the Waledac botnet. Also, attendees showed interest in social networking security. In addition, the convergence of cloud computing and identity management was showcased.

Program links:
Check out the RSA Conference 2010 news coverage.
Social networking risks, benefits for enterprises weighed by RSA panel
White House declassifies CNCI summary, lifts veil on security initiatives


March 11, 2010  3:12 PM

Kaminsky on DNSSEC progress



Posted by: Jessica Scarpati
DNSSEC

Dan Kaminsky of IO Active explains the benefits of DNSSEC and why products and services that use the technology could take off in the next few years. Scott Rose of NIST describes the lessons learned from the deployment across the .gov domain at federal government agencies.

Program links:

Experts see DNSSEC deployments gaining traction
Increased authentication at the DNS layer will block DNS cache poisoning and create new services, experts say. The root zone should be signed and verified by July.

DNSSEC: Has the Time Come? DNSSEC brings PKI to the Domain Name System and prevents dangerous cache poisoning attacks.

VIDEOVeriSign on DNSSEC support Joe Waldron, a product manager in VeriSign’s Naming (DNS) Group, said engineers are testing and upgrading systems to support security extensions for DNS (DNSSEC).


March 8, 2010  2:58 PM

Clientless SSL VPN vulnerability and Web browser protection



Posted by: Jessica Scarpati
Threat Monitor, VPN Security

Threat MonitorIn a recent US-CERT advisory, clientless SSL VPN vulnerabilities were listed as posing serious threats to Web browser security. In this tip, learn possible actions to take for Web browser protection.


March 4, 2010  5:51 PM

RSA 2010: Microsoft’s Scott Charney



Posted by: Jessica Scarpati
botnets, Security Wire Weekly

Scott Charney, Microsoft’s vice president for Trustworthy Computing discusses the software giant’s latest legal action to take down the Waledac botnet.


February 25, 2010  1:49 PM

RSA Preview: Former ChoicePoint CISO Rich Baich



Posted by: Jessica Scarpati
2010 RSA Conference, Security Wire Weekly

Rich Baich, who heads Cyber Threat Intelligence Group at Deloitte, shares his thoughts on the 2010 RSA Conference and the current threat landscape.


February 18, 2010  6:16 PM

Defending against RAM scraper malware in the enterprise



Posted by: Jessica Scarpati
malware, Threat Monitor

Threat MonitorA new type of malware attack, RAM scraper, may pose a serious threat to enterprise security. Learn what a RAM scraper attack is, and how you can defend your organization from this potentially damaging new malware attack.


February 17, 2010  11:02 PM

Application security and Top 25 coding errors



Posted by: Jessica Scarpati
secure software development, Security Wire Weekly

Chris Wysopal, CTO of Veracode on code analysis and how the SANS/CWE Top 25 Programming Errors list can be applied effectively by software development groups.

Program Links:

SANS releases revised top 25 serious coding errors list
The latest list adds profiles to help organizations tailor the list to their needs and mitigation techniques to help software developers apply better practices to the SDL.

New York drafts language demanding secure code:
State will demand software makers certify their software does not contain the coding errors listed in the CWE/SANS Top 25 Dangerous Programming Errors.

SANS: Application threats, website flaws pose biggest security threats:
A new report from the SANS Institute calls flaws in client-side applications often the most ignored by IT professionals.