From SECNAP Alerts:
Many companies still fail to adequately manage user privileges and protect sensitive data, exposing them to the risks of data breaches, according to a Ponemon Institute study sponsored by Hewlett-Packard.
A survey of 5,500 IT professionals around the world found that more than half the organizations were still giving employees access to sensitive, confidential [...]
Entries from December 2011
Nearly 20% of IT Pros Say Terminated Users Still Likely to Have Data Access
December 15th, 2011 · No Comments
Tags: Security
Adobe Apps Riddled with Malware Vulnerabilities
December 14th, 2011 · No Comments
From SECNAP Alerts:
Malware writers are continuing to exploit a high-profile zero-day flaw in Adobe Acrobat and Reader, using a spam attack to spread the remote code execution vulnerability in the wild. The attack arrives as an unsolicited financial report claiming to be from Barclay’s Capital. The attached PDF file launches the Reader and Acrobat attack, [...]
Tags: Security
Cross-Site Scripting Flaws Plague Two-Thirds of Web Applications
December 13th, 2011 · No Comments
Cross-site scripting flaws are the most prevalent vulnerabilities found in Web applications, posing a risk to data and intellectual property, according to a study of thousands of applications by Veracode–a company that specializes in finding vulnerabilities in code. Veracode analyzed more than 9,900 applications that were submitted to its cloud-based scanning service over the last [...]
Tags: Security
Bogus Adobe Upgrade Notices Deliver Malware That Steals Banking Info
December 12th, 2011 · No Comments
Cybercriminals have widely spammed out a malware attack posing as software upgrades for Adobe Acrobat Reader and Adobe X Suite Advanced.
The emails, which pretend to come from Adobe, have a ZIP file attached that contains a version of the Zeus Trojan, designed to steal banking information from compromised computers.
The risk is that computer users might [...]
Tags: Security
Managing Change in EMR Implementation
December 9th, 2011 · No Comments
When your medical practice makes the transition to an electronic medical record (EMR), which is inevitable, careful planning can help the change go smoothly—and careful planning, in the context of EMR implementation, can be referred to as “change management”.
Change management consists of up-front assessment and planning—but there’s much more involved than simply creating a project [...]
Tags: Business Continuity and Disaster Recovery
Changing the Default Apps on your Android Device
December 8th, 2011 · No Comments
If you, for example, install multiple media player applications on your Android device, you’ll find that Android will give you the choice of which application to launch by default when you open a media file or document. However, you may later want to change this default setting.
To do so, go to Settings > Applications > [...]
Tags: Uncategorized
Mobile Messaging Fraud is Growing at 300 Percent Annually
December 7th, 2011 · No Comments
Cybercriminals are launching more and more sophisticated attacks on U.S. wireless consumers, according to a December 5 report. Research showed financial fraud and spam via SMS (Short Message Service) texts is growing at a rate of over 300 percent, year over year. The attack techniques are becoming increasingly sophisticated and can include any combination of [...]
Tags: Security
New HTML 5 Presents Benefits, and Serious Challenges, for IT Security Pros
December 6th, 2011 · No Comments
HTML 5 is being touted as an Adobe Flash replacement that displays audio, graphics and video more efficiently, but security experts studying the technology say it poses new challenges for enterprise security professionals.
James Lyne, senior technologist at UK security vendor Sophos, said potential HTML 5 security issues could result from the rapid adoption of the technology. If [...]
Tags: Security
A Secret App on Millions of Smartphones is Logging Your Key Taps and More
December 5th, 2011 · No Comments
An Android app developer has published what he says is conclusive proof that millions of smartphones are secretly monitoring the key presses, geographic locations, and received messages of their users.
In a YouTube video posted November 28, the developer showed how software from a company known as Carrier IQ recorded in real time the keys he [...]
Tags: Security
Cybercriminals Have Begun to Exploit Holiday Shopping Season
December 2nd, 2011 · No Comments
Security experts are warning of a rapidly mutating email spam campaign using bogus messages from United Parcel Service (UPS) claiming that a package could not be delivered. The spam run began earlier this month, and is just one way security researchers believe criminals will exploit the holiday season online buying spree.
According to Cloudmark engineering director [...]
Tags: Security