<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>Happy Holidays from Infosec Island</title><description>2011-12-24 04:02:41 - Infosec Island Latest Articles : Happy Holidays from the Infosec Island staff Anthony, Andrian, Lance and Mike wish you the best for this Holiday season Thanks to everyone for coming to this site and a special thanks to all of our authors the contributors </description><link>http://www.secuobs.com/revue/news/348865.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348865.shtml</guid></item>
<item><title>The Tao of GRC</title><description>Secuobs.com : 2011-12-23 23:42:56 - Infosec Island Latest Articles - Effective GRC management requires neither better mathematical models nor complex software It does require us to explore new threat models and go outside the organization to look for risks we ve never thought about and discover new links and interdependencies that may threaten our business </description><link>http://www.secuobs.com/revue/news/348836.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348836.shtml</guid></item>
<item><title>The Security Impact of Performance</title><description>Secuobs.com : 2011-12-23 07:04:55 - Infosec Island Latest Articles - DDoS is being used as a tool that has turned poor performing systems into weapons against their implementers It proves that no matter how big the pipe you have, it's possible to push so much traffic that the odds of handling it properly and staying available are virtually zero </description><link>http://www.secuobs.com/revue/news/348739.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348739.shtml</guid></item>
<item><title>Chinese Hack of US Chamber Undetected for Six Months</title><description>Secuobs.com : 2011-12-22 19:00:16 - Infosec Island Latest Articles -  What was unusual about it was that this was clearly somebody very sophisticated, who knew exactly who we are and who targeted specific people and used sophisticated tools to try to gather intelligence,  said the Chamber's COO David Chavern </description><link>http://www.secuobs.com/revue/news/348645.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348645.shtml</guid></item>
<item><title>SSAE 16 is NOT SOC 2</title><description>Secuobs.com : 2011-12-22 18:09:48 - Infosec Island Latest Articles - Just when I thought things were getting better, along comes a press release that is wrong on so many levels I don t even know where to begin First, SSAE 16 is not a certification Secondly, SOC 2 is totally unrelated to SSAE 16, which is specific guidance for conducting SOC 1 reviews </description><link>http://www.secuobs.com/revue/news/348636.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348636.shtml</guid></item>
<item><title>ICS-CERT  WellinTech s Kingview SCADA Vulnerability</title><description>Secuobs.com : 2011-12-22 17:23:32 - Infosec Island Latest Articles -  An attacker can exploit this vulnerability by sending a specially crafted packet to Port 777 TCP that exceeds a specified length and contains executable code Successful exploitation of the heap overflow vulnerability could allow a remote attacker to cause the service to crash  </description><link>http://www.secuobs.com/revue/news/348624.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348624.shtml</guid></item>
<item><title>NSA Launches CryptoChallenge Mobile Application</title><description>Secuobs.com : 2011-12-22 16:40:32 - Infosec Island Latest Articles - The game is the latest digital communications effort designed to educate young adults on career opportunities with NSA and recruit the best and brightest to support NSA's cybersecurity initiatives </description><link>http://www.secuobs.com/revue/news/348617.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348617.shtml</guid></item>
<item><title>Risk Management   More Than Just Risk Assessment</title><description>Secuobs.com : 2011-12-22 16:40:32 - Infosec Island Latest Articles - Risk management must be linked to the organization s purpose and goals Your company must to be disciplined It cannot simply develop a risk assessment and then not use it to look at risk generally As important as systems are, they must be practical, and linked to what your company does </description><link>http://www.secuobs.com/revue/news/348616.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348616.shtml</guid></item>
<item><title>Chrome Most Secure  Depends on Your Frame of Reference</title><description>Secuobs.com : 2011-12-22 06:04:16 - Infosec Island Latest Articles - Until recently Chrome supported SSL 20 by default  seems like a major no-no in my humble opinion  and the fact that Firefox is the only one of the big three to have OCSP checking enabled by default This aspect of  browsing security  is a  score one  for Firefox in my estimation </description><link>http://www.secuobs.com/revue/news/348553.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348553.shtml</guid></item>
<item><title>Why I Oppose the Twelve Chinese Hacker Groups Claim</title><description>Secuobs.com : 2011-12-22 06:04:16 - Infosec Island Latest Articles - Senators and Congressmen don't have enough knowledge about cybersecurity to discern truth from fiction, so what starts off as questionable analysis soon becomes terrible government policies, especially when it is advocating for civilian companies to counterattack a nation's network </description><link>http://www.secuobs.com/revue/news/348552.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348552.shtml</guid></item>
<item><title>The State of Solid State</title><description>Secuobs.com : 2011-12-22 06:04:16 - Infosec Island Latest Articles - Solid state disks are more reliable because SSDs do not contain any moving parts There are no read heads, actuator arms or spinning platters that can break down in an SSD SSDs can be moved around freely while in use and have a higher tolerance against shock and vibration than HDDs </description><link>http://www.secuobs.com/revue/news/348551.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348551.shtml</guid></item>
<item><title>HTML Tag Can Cause Windows 7 x64 Blue Screen of Death</title><description>Secuobs.com : 2011-12-21 20:11:42 - Infosec Island Latest Articles -  The vulnerability is caused due to an error in win32ksys and can be exploited to corrupt memory via a specially crafted web page containing an IFRAME with an overly large height attribute Successful exploitation may allow execution of arbitrary code with kernel-mode privileges  </description><link>http://www.secuobs.com/revue/news/348490.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348490.shtml</guid></item>
<item><title>ICS-CERT  7-Technologies IGSS Data Server Vulnerability</title><description>Secuobs.com : 2011-12-21 20:11:42 - Infosec Island Latest Articles -  This vulnerability can be exploited by sending a specially crafted packet to Port 12401 TCP A successful exploit will cause a buffer overflow that can result in a remote DoS against the 7T Data Server application on the targeted host  </description><link>http://www.secuobs.com/revue/news/348489.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348489.shtml</guid></item>
<item><title>How Not to Recruit Spies Online and Off</title><description>Secuobs.com : 2011-12-21 19:24:03 - Infosec Island Latest Articles - One must look at the range and breadth of companies and entities being broken in to by the likes of China to see that no one is exempt Know the ins and outs of the technology as well as the spook landscape, especially if you work in infosec today, lest you become the next target </description><link>http://www.secuobs.com/revue/news/348478.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348478.shtml</guid></item>
<item><title>HIPAA Security Rule Toolkit Available from NIST</title><description>Secuobs.com : 2011-12-21 18:33:14 - Infosec Island Latest Articles -  The NIST HIPAA Security Toolkit Application is intended to help organizations better understand the requirements of the HIPAA Security Rule, implement those requirements, and assess those implementations in their operational environment  </description><link>http://www.secuobs.com/revue/news/348462.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348462.shtml</guid></item>
<item><title>Illegal Movie Upload Yields Federal Prison Sentence</title><description>Secuobs.com : 2011-12-21 17:46:09 - Infosec Island Latest Articles -  The federal prison sentence handed down in this case sends a strong message of deterrence to would-be Internet pirates The Justice Department will pursue and prosecute persons who seek to steal the intellectual property of this nation  </description><link>http://www.secuobs.com/revue/news/348450.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348450.shtml</guid></item>
<item><title>The MPLS Privacy Debate Continues</title><description>Secuobs.com : 2011-12-21 17:46:09 - Infosec Island Latest Articles - Given that at some point MPLS traffic has to technically co-mingle with other customers  network traffic, how can the PCI SSC claim that MPLS is private  The answer is a bit disconcerting to some, but for those of us with an understanding of the engineering issues, it was expected </description><link>http://www.secuobs.com/revue/news/348449.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348449.shtml</guid></item>
<item><title>ENISA Report on Maritime Cyber Security</title><description>Secuobs.com : 2011-12-21 06:16:58 - Infosec Island Latest Articles - Due to the high complexity, it is major challenge to ensure adequate maritime cyber security Development of good practices for the technology development and implementation of ICT systems would therefore ensure  security by design  for all critical maritime ICT components </description><link>http://www.secuobs.com/revue/news/348357.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348357.shtml</guid></item>
<item><title>Fed CIO  Minimum Security Standards Set for Cloud Providers</title><description>Secuobs.com : 2011-12-21 06:16:58 - Infosec Island Latest Articles - The FedRAMP was established to provide a standard approach to Assessing and Authorizing cloud computing services FedRAMP allows joint authorizations and continuous security monitoring services for Government and Commercial cloud computing systems intended for multi-agency use </description><link>http://www.secuobs.com/revue/news/348356.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348356.shtml</guid></item>
<item><title>Data Loss Prevention - Step 3  Engage Physical Security</title><description>Secuobs.com : 2011-12-20 19:39:52 - Infosec Island Latest Articles - While often missed, this component of security is one of the most critical when it comes to understanding, and fighting the loss of data in your organization in a very real, tangible way There are three types of threats you want to be aware of from the physical perspective </description><link>http://www.secuobs.com/revue/news/348265.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348265.shtml</guid></item>
<item><title>Consortium Issues Baseline Requirements for SSL</title><description>Secuobs.com : 2011-12-20 18:46:39 - Infosec Island Latest Articles -  The primary goal of these Requirements is to enable efficient and secure electronic communication, while addressing user concerns about the trustworthiness of Certificates The Requirements also serve to inform users and help them to make informed decisions when relying on Certificates  </description><link>http://www.secuobs.com/revue/news/348248.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348248.shtml</guid></item>
<item><title>ICS-CERT  Invensys Wonderware InBatch ActiveX Vulnerability</title><description>Secuobs.com : 2011-12-20 17:55:52 - Infosec Island Latest Articles -  Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code or cause a denial of service  DoS  on systems with affected versions of Wonderware InBatch Runtime Client components,  the ICS-CERT advisory warns </description><link>http://www.secuobs.com/revue/news/348241.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348241.shtml</guid></item>
<item><title>Drone Hacking Claims  A Little Truthful or Bold Lies </title><description>Secuobs.com : 2011-12-20 17:55:52 - Infosec Island Latest Articles - Iran is claiming that an  electronic warfare  unit forced down an US RQ-170 Sentinel Drone through a cyber attack The Iranians are saying they are close to uncovering all the secrets contained in the drone and unlocking the software Instead of a detailed explanation, I just say BS </description><link>http://www.secuobs.com/revue/news/348240.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348240.shtml</guid></item>
<item><title>Some Facts About Carrier IQ</title><description>Secuobs.com : 2011-12-20 06:38:08 - Infosec Island Latest Articles - There is an additional configuration file  called a  Profile  that determines what information is sent from the phone to a carrier Profiles are programs in a domain-specific filtering language - they are normally written by Carrier IQ to the specifications of a telco or other client </description><link>http://www.secuobs.com/revue/news/348142.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348142.shtml</guid></item>
<item><title>Digital Content Distribution Vulnerabilities</title><description>Secuobs.com : 2011-12-20 06:38:08 - Infosec Island Latest Articles - An attack could be mounted on the STB NPVR network to steal master keys and decrypt encrypted content The cost of mounting the attack is far greater than the alternative of buying HD DVD media on the open market and producing pirated copies or ripping and putting it on a Torrent </description><link>http://www.secuobs.com/revue/news/348141.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348141.shtml</guid></item>
<item><title>Modern Encryption   So Easy a Caveman Could Do It</title><description>Secuobs.com : 2011-12-20 06:38:08 - Infosec Island Latest Articles - Adding encryption is a relatively easy and cost effective way to secure your organizations data without adding significant cost or complexity For organizations dealing with confidential information  healthcare, banking, government  it should be mandatory </description><link>http://www.secuobs.com/revue/news/348140.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348140.shtml</guid></item>
<item><title>Iran Invests Heavily in Developing Cyberwarfare Capabilities</title><description>Secuobs.com : 2011-12-19 21:38:03 - Infosec Island Latest Articles - The Jerusalem Post reports Iran has recently decided to invest somewhere near one billion dollars to increase both cyber defensive and offensive capabilities The news comes on the heels of reports that Iran may now be in possession of several advanced US military reconnaissance drones </description><link>http://www.secuobs.com/revue/news/348074.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348074.shtml</guid></item>
<item><title>Symantec Still Selling Huawei Equipment to the DoD</title><description>Secuobs.com : 2011-12-19 19:57:02 - Infosec Island Latest Articles -  In a letter to partners, North America channel chief Randy Cochran says the contract manufacturing relationship between Symantec and Huawei will remain unaffected, as will Symantec s commitment to marketing and developing appliance-based solutions  </description><link>http://www.secuobs.com/revue/news/348049.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348049.shtml</guid></item>
<item><title>Government Cyber Strategy Directs Billions for R and D</title><description>Secuobs.com : 2011-12-19 19:11:41 - Infosec Island Latest Articles -  When we look at the plan itself, it represents our visions for the research necessary to develop game changing technologies that can help neutralize today's cyber attacks and build an infrastructure to secure our systems from what may come in the future  </description><link>http://www.secuobs.com/revue/news/348039.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348039.shtml</guid></item>
<item><title>ENISA Releases Industrial Control Systems Security Report</title><description>Secuobs.com : 2011-12-19 18:23:40 - Infosec Island Latest Articles -  These systems have faced a notable number of incidents These include the Stuxnet attack, believed to have used bespoke malware to target nuclear control systems in Iran, and the recent DuQu - upgraded variant  of this malware These incidents caused great security concerns among ICS users  </description><link>http://www.secuobs.com/revue/news/348023.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348023.shtml</guid></item>
<item><title>Internet Architects Oppose SOPA and PIPA Legislation</title><description>Secuobs.com : 2011-12-19 17:35:07 - Infosec Island Latest Articles - Eighty-three innovators, inventors and engineers signed the letter that specifically calls for Congress to reject the Stop Online Piracy Act  SOPA  and the PROTECT IP Act  PIPA  in an attempt to prevent government efforts to codify broad Internet censorship powers </description><link>http://www.secuobs.com/revue/news/348013.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348013.shtml</guid></item>
<item><title>Change Management and Process Improvement</title><description>Secuobs.com : 2011-12-19 17:35:07 - Infosec Island Latest Articles - I don't know of a bigger detractor to security than a broken enterprise change management process whether you work for a million node global corporation, or a company with 100 laptops and an outsourced IT - poor change management will be the death of your security posture, period </description><link>http://www.secuobs.com/revue/news/348012.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/348012.shtml</guid></item>
<item><title>Enterprise Information Security Resolutions for 2012</title><description>Secuobs.com : 2011-12-19 06:13:04 - Infosec Island Latest Articles - Successful information security is about making progress It s not reasonable or sustainable to expect all risks to be remediated as soon as they are discovered Instead, my goal for 2012 will be to establish a positive trend, working toward improving security consistently </description><link>http://www.secuobs.com/revue/news/347940.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347940.shtml</guid></item>
<item><title>The RQ170 Affair  Spoofing, Jamming, and The GBAS</title><description>Secuobs.com : 2011-12-19 06:13:04 - Infosec Island Latest Articles - The documents show a program to  augment  the GPS environment in Iran by placing base stations with the Fajr GPS  GBAS  network hardware in specific sites throughout the country to ostensibly help with aircraft navigation In their presentation, they mention the possibility of spoofing </description><link>http://www.secuobs.com/revue/news/347939.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347939.shtml</guid></item>
<item><title>A Look at Infosec Island</title><description>Secuobs.com : 2011-12-18 19:47:37 - Infosec Island Latest Articles - Rather than giving a security roundup or predicting future security trends for 2012, I thought it a good idea to look at some of the security bloggers over at Infosec Island over the course of the year </description><link>http://www.secuobs.com/revue/news/347907.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347907.shtml</guid></item>
<item><title>Who or What Downed the RQ-170 </title><description>Secuobs.com : 2011-12-18 04:47:48 - Infosec Island Latest Articles - Cyber attack  Oh come on now This would be a highly complex operation and I doubt even the Russians have that capability First you would need to inject the proper commands into the system Then, you d have to establish a link through the CandC network from Beale or Creech Air Force Base </description><link>http://www.secuobs.com/revue/news/347853.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347853.shtml</guid></item>
<item><title>Chatting With An Auditor About Credit Union Compliance</title><description>Secuobs.com : 2011-12-17 06:15:59 - Infosec Island Latest Articles - Credit unions, by virtue of their regulatory context, have more  interpretive latitude  in how technical security controls get implemented Meaning they should try on PCI compliance before calling out merchants - especially the big ones - for having it soft </description><link>http://www.secuobs.com/revue/news/347779.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347779.shtml</guid></item>
<item><title>Transparency in Cloud Services from the Security Perspective</title><description>Secuobs.com : 2011-12-16 20:03:39 - Infosec Island Latest Articles - There is an operational perspective in terms of provider transparency We are now starting to see cases where a SaaS service offering is built on top of a PaaS service, built using multiple IaaS services and that is enough to make anyone's head spin </description><link>http://www.secuobs.com/revue/news/347645.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347645.shtml</guid></item>
<item><title>Five Biggest Security Events of 2011</title><description>Secuobs.com : 2011-12-16 19:13:27 - Infosec Island Latest Articles -  Sony went out of its way to keep customers in the dark for the majority of the outage and when it did address the issue, it presented misinformation and blamed everyone but itself  </description><link>http://www.secuobs.com/revue/news/347632.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347632.shtml</guid></item>
<item><title>NIST Revision Expands Government Authentication Options</title><description>Secuobs.com : 2011-12-16 18:27:13 - Infosec Island Latest Articles -  Changes made to the document reflect changes in the state of the art There are new techniques and tools available to government agencies, and this provides them more flexibility in choosing the best authentication methods for their individual needs, without sacrificing security  </description><link>http://www.secuobs.com/revue/news/347622.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347622.shtml</guid></item>
<item><title>Passwords  Give Them the Respect They Deserve</title><description>Secuobs.com : 2011-12-16 18:27:13 - Infosec Island Latest Articles - Passwords are everywhere on the internet You need them to log onto your banking, emails and a ton of other websites They are extremely important, yet do we give them the respect they deserve  </description><link>http://www.secuobs.com/revue/news/347621.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347621.shtml</guid></item>
<item><title>Security  Three Tips When Speaking to the Board of Directors</title><description>Secuobs.com : 2011-12-16 17:42:29 - Infosec Island Latest Articles - Many CISOs are getting questions specifically about whether they are protected from targeted attacks, malware, and data breaches And many of these questions are coming from people who don t really know what terms like  targeted attack  or  malware  actually mean - the Board of Directors </description><link>http://www.secuobs.com/revue/news/347611.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347611.shtml</guid></item>
<item><title>Exercise Tested NATO Procedures for Cyber Defense</title><description>Secuobs.com : 2011-12-16 16:46:54 - Infosec Island Latest Articles -  Effective cyber defense requires us to continually test and improve our crisis management and decision-making procedures This exercise was a great opportunity to promote the practical implementation of NATO s new Cyber Defense Policy adopted last June  </description><link>http://www.secuobs.com/revue/news/347603.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347603.shtml</guid></item>
<item><title>The Cyber Security Casino  Betting with House Money </title><description>Secuobs.com : 2011-12-16 06:27:42 - Infosec Island Latest Articles - Identifying threats is an offensive tactic It s a close monitoring of the system at hand and the cyber news media It s easier to be protective when you understand what kinds of hackers, criminal, or nation states are after your system s data Know how to handle toxic data </description><link>http://www.secuobs.com/revue/news/347523.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347523.shtml</guid></item>
<item><title>PCI Compliance  What is In-Scope </title><description>Secuobs.com : 2011-12-16 06:27:42 - Infosec Island Latest Articles - You would think this question would be easy to answer when talking about the PCI standards because all that processes, stores or transmits cardholder data is in-scope However, the nuances in the implementation of technological solutions do not always allow a black and white answer </description><link>http://www.secuobs.com/revue/news/347522.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347522.shtml</guid></item>
<item><title>How the RQ-170 Was Hijacked</title><description>Secuobs.com : 2011-12-16 06:27:42 - Infosec Island Latest Articles - While it is reported that intercepting unencrypted drone communication data streams had first been known to US military since the mid-1990's, this exploitation continued on into 2009 where militant laptops were found with drone data and unencrypted video feeds from Predator drones </description><link>http://www.secuobs.com/revue/news/347521.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347521.shtml</guid></item>
<item><title>OWWWS - The Other Form of Occupy</title><description>Secuobs.com : 2011-12-15 21:22:43 - Infosec Island Latest Articles - If we we consider the Occupy movements across the globe, demonstrating and protesting against income inequality and inequitable policies around commerce and taxation, the persistent cart vulnerability could become a seemingly benign form of occupation that could develop into a serious threat </description><link>http://www.secuobs.com/revue/news/347477.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347477.shtml</guid></item>
<item><title>Duqu Analysis Shows ICS-SCADA Networks Vulnerable</title><description>Secuobs.com : 2011-12-15 20:27:09 - Infosec Island Latest Articles -  Critical infrastructures are still not sufficiently prepared for attacks like DuQu There are no commonly adopted ICS security standards, guidelines or regulations, corporate management is not sufficiently involved, and there are numerous technical vulnerabilities  </description><link>http://www.secuobs.com/revue/news/347467.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347467.shtml</guid></item>
<item><title>Security BSides Planning Epic Phoenix Event</title><description>Secuobs.com : 2011-12-15 19:38:10 - Infosec Island Latest Articles - Bummed out after Snowmageddon  Want a nice hot  at least warmer  change of scenery  Arizona is hosting its first ever BSides during one of the best times of year We aim to provide the highest quality talks, hands on training and workshops We also have cactus </description><link>http://www.secuobs.com/revue/news/347456.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347456.shtml</guid></item>
<item><title>Top Seven Emerging Security Trends from 2011</title><description>Secuobs.com : 2011-12-15 18:52:41 - Infosec Island Latest Articles - Issues gaining attention over the past year include the weakening of the digital certificate authorities, surges in malware targeting mobile devices, designer malware, and the rash of corporate network breaches - be they by hacktivists, nation-state supported hackers, or criminal syndicates </description><link>http://www.secuobs.com/revue/news/347443.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347443.shtml</guid></item>
<item><title>Following the Trail of Web-Based Malware</title><description>Secuobs.com : 2011-12-15 18:02:19 - Infosec Island Latest Articles - The mainphp script contained javascript that attempted to exploit several potential vulnerabilities I downloaded the script and analyzed it By inserting an  alert  statement into the script prior to the actual execution of the code, we can get a good idea of what the script does </description><link>http://www.secuobs.com/revue/news/347428.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347428.shtml</guid></item>
<item><title>Congress Sanctions Offensive Military Action in Cyberspace</title><description>Secuobs.com : 2011-12-15 17:16:19 - Infosec Island Latest Articles - Section 954 of the the FY 2012 defense authorization act states that  Congress affirms that the Department of Defense has the capability, and upon direction by the President may conduct offensive operations in cyberspace to defend our Nation, allies and interests  </description><link>http://www.secuobs.com/revue/news/347411.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347411.shtml</guid></item>
<item><title>Three Things Experts Won't Tell You About Cloud Security</title><description>Secuobs.com : 2011-12-15 06:07:30 - Infosec Island Latest Articles - Carefully crafted and monitored SLAs to keep vendors in check, mandating FIPS 140-2 certification of potential vendors and benefiting from vendor technology investments  economies of scale  can add significant weight to cloud solution providers being more secure than in-house solutions </description><link>http://www.secuobs.com/revue/news/347310.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347310.shtml</guid></item>
<item><title>PenTest  Get to Know Yourself Before Others Do</title><description>Secuobs.com : 2011-12-15 06:07:30 - Infosec Island Latest Articles - With multi-tier network architectures, web services, custom applications, and heterogeneous server platform environments, keeping data assets secure is more difficult than ever Coupled with this complexity is the fact that criminal organizations have organized their hacking efforts </description><link>http://www.secuobs.com/revue/news/347309.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347309.shtml</guid></item>
<item><title>Google Wallet and the Edge of PCI s Regulatory Map</title><description>Secuobs.com : 2011-12-15 06:07:30 - Infosec Island Latest Articles - Folks might object to sensitive data being stored in cleartext within Google Wallet - I sure do - but the problem isn't so much Google Wallet but instead the fact that mobile devices are blurring the lines between what's a payment application and what's not </description><link>http://www.secuobs.com/revue/news/347308.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347308.shtml</guid></item>
<item><title>Windows Phone Denial of Service Attack Vulnerability</title><description>Secuobs.com : 2011-12-14 21:23:27 - Infosec Island Latest Articles -  The attack is not device specific and appears to be an issue with the way the Windows Phone messaging hub handles messages The bug is also triggered if a user sends a Facebook chat message or Windows Live Messenger message to a recipient  </description><link>http://www.secuobs.com/revue/news/347223.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347223.shtml</guid></item>
<item><title>Army Officially Activates First Dedicated Cyber Brigade</title><description>Secuobs.com : 2011-12-14 20:33:55 - Infosec Island Latest Articles -  This  activation  is a tribute to the belief in the notion that our nation requires assured freedom of maneuver in cyberspace in this era of persistent conflict and the advent of the increasingly more sophisticated threats to our security,  said Maj Gen Mary A Legere </description><link>http://www.secuobs.com/revue/news/347213.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347213.shtml</guid></item>
<item><title>Iranian Ambassador Discusses Cyber Attacks on US Targets</title><description>Secuobs.com : 2011-12-14 19:45:04 - Infosec Island Latest Articles - Iranian Ambassador Mohammad Hassan Ghadiri discusses the potential for state sponsored attacks on the White House, FBI, CIA, and nuclear power plant systems within the US The video shows the ambassador talking also asking about how to further the attacks by making certain contacts </description><link>http://www.secuobs.com/revue/news/347206.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347206.shtml</guid></item>
<item><title>ICS-CERT Issues New SCADA Vulnerability Advisory</title><description>Secuobs.com : 2011-12-14 18:51:53 - Infosec Island Latest Articles - Santamarta uncovered multiple hidden accounts with default passwords in the systems that could allow an attacker to remotely access the network, view and modify the module's firmware, execute arbitrary malicious code, or cause a denial of service interruption </description><link>http://www.secuobs.com/revue/news/347187.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347187.shtml</guid></item>
<item><title>Cybersecurity in Waste Water and Water Control Systems</title><description>Secuobs.com : 2011-12-14 18:03:40 - Infosec Island Latest Articles - The first of a monthly webinar series on Industrial Control System  ICS  Cybersecurity is now available for review in this video This session provides insight for those interested in ICS Cybersecurity including policy makers, asset owners, vendors, consultants and integrators </description><link>http://www.secuobs.com/revue/news/347176.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347176.shtml</guid></item>
<item><title>Anonymous Affiliate Arrested for 2010 DDoS Attack</title><description>Secuobs.com : 2011-12-14 17:14:23 - Infosec Island Latest Articles -  According to the indictment, Poe used a favorite software tool of the Anonymous collective a Low Orbit Ion Cannon, which is a computer program that is used to send extremely large numbers of  packets  or requests over a network in an attempt to overwhelm a target computer  </description><link>http://www.secuobs.com/revue/news/347169.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347169.shtml</guid></item>
<item><title>Are Your Health Records at Risk </title><description>Secuobs.com : 2011-12-14 17:14:23 - Infosec Island Latest Articles - Have we now arrived at the point in obtaining medical care that in addition to looking into the medical practitioner's experience and confirming they are compliant with HIPAA, that we now must review their data handling policies before choosing a health care provider  </description><link>http://www.secuobs.com/revue/news/347168.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347168.shtml</guid></item>
<item><title>Don't Fall Victim to Poor Network Segmentation</title><description>Secuobs.com : 2011-12-14 07:47:12 - Infosec Island Latest Articles - If an attacker compromises the DMZ, it is important to stop them there Firewalls and segmentation is the key to this Should a user have unlimited access to the internal network from a Citrix server or VPN  Or be able to connect to file shares, internal web applications, and databases  </description><link>http://www.secuobs.com/revue/news/347077.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347077.shtml</guid></item>
<item><title>Data Loss Prevention  Step 2 - Manage Privileges</title><description>Secuobs.com : 2011-12-14 07:47:12 - Infosec Island Latest Articles - Getting back to basics is critical, and one of the most basic of basics is managing the rights to your data, your systems, and your critical operations Let's take a critical, step-by-step look at how managing privileges can greatly decrease your likelihood of leaking data </description><link>http://www.secuobs.com/revue/news/347076.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347076.shtml</guid></item>
<item><title>Case Study  A Cloud Security Assessment</title><description>Secuobs.com : 2011-12-14 06:56:29 - Infosec Island Latest Articles - A client asked us to find a way to reduce risk exposure at the lowest cost Using the Business Threat Modeling methodology and Practical Threat Analysis software, we were able to mitigate 80pourcents of the total risk exposure in dollars at half the security budget proposed by the vendor </description><link>http://www.secuobs.com/revue/news/347071.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/347071.shtml</guid></item>
<item><title>DHS Releases Blueprint for a Secure Cyber Future</title><description>Secuobs.com : 2011-12-13 19:21:34 - Infosec Island Latest Articles - The document is meant to provide a road map for cybersecurity efforts while observing the the need to preserve civil liberties, protect privacy, bolster national security, and provide the ability for the private sector to effectively operate and innovate in cyberspace </description><link>http://www.secuobs.com/revue/news/346903.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346903.shtml</guid></item>
<item><title>Compliance  Is Water Wet or is Jack Webb Still the Man </title><description>Secuobs.com : 2011-12-13 18:29:27 - Infosec Island Latest Articles - One of the constant refrains for any compliance officer is responding to employees  inquiries Questions come in all shapes and sizes and from all over the world The compliance professional must try to ascertain the facts to give an intelligent, coherent and, hopefully correct response </description><link>http://www.secuobs.com/revue/news/346889.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346889.shtml</guid></item>
<item><title>ENISA on Cyber Security  Future Challenges and Opportunities</title><description>Secuobs.com : 2011-12-13 16:44:40 - Infosec Island Latest Articles - Our society has become irreversibly dependent on Information and Communication Technologies  ICTs  Unfortunately, the adoption of them has been accompanied by the development of a new set of cyber threats which are developing in ever more rapid, sophisticated and sinister ways </description><link>http://www.secuobs.com/revue/news/346852.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346852.shtml</guid></item>
<item><title>Cyber Security and Illegal Information Operations</title><description>Secuobs.com : 2011-12-13 16:44:40 - Infosec Island Latest Articles - The Concept of Convention on International Information Security was released in 2011 by the Shanghai Cooperative Organization, consisting of China, Kazakhstan, Kyrgyzstan, Russia, Tajikistan, and Uzbekistan This concept was floated to the UN as a construct for international cybersecurity </description><link>http://www.secuobs.com/revue/news/346851.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346851.shtml</guid></item>
<item><title>Data Loss Prevention - Step 1  Know What's Important</title><description>Secuobs.com : 2011-12-13 06:42:55 - Infosec Island Latest Articles - It's important to understand what your company does and then figure out what the critical bits are Sometimes it's your customer lists, or a secret ultra-high efficiency engine design, or the next big thing in stealth bombers The point is that you simply need to know your business </description><link>http://www.secuobs.com/revue/news/346792.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346792.shtml</guid></item>
<item><title>Debating Cyber Warfare Part III - Still More Questions from GOV</title><description>Secuobs.com : 2011-12-13 06:42:55 - Infosec Island Latest Articles - As for cyber warfare, there are various internationally accepted legal frameworks and that can provide some help Consider the Law of Armed Conflict or Universal Human Rights, both of which have received wide adoption and have led to increased cooperation among nation states </description><link>http://www.secuobs.com/revue/news/346791.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346791.shtml</guid></item>
<item><title>PCI DSS Risk SIG Announced  Results Will Be Interesting</title><description>Secuobs.com : 2011-12-13 05:58:52 - Infosec Island Latest Articles - The one that I am most interested in seeing is the results of is the Risk Assessment SIG Although IT Risk Assessments has been a term that has been used for decades now, they are still rarely performed and almost always poorly when they are in regard to effectively considering threats </description><link>http://www.secuobs.com/revue/news/346783.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346783.shtml</guid></item>
<item><title>ICS-SCADA Security Concerns Spur Increased Funding</title><description>Secuobs.com : 2011-12-12 20:59:12 - Infosec Island Latest Articles -  Many SCADA systems were deployed without security in the belief that SCADA would always be isolated from the Internet But it s not, and even when it is, attacks such as Stuxnet can circumvent the isolation by using USB memory sticks to spread  </description><link>http://www.secuobs.com/revue/news/346715.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346715.shtml</guid></item>
<item><title>Handful of Chinese Hackers Responsible for Majority of Attacks</title><description>Secuobs.com : 2011-12-12 20:07:56 - Infosec Island Latest Articles -  Right now we have the worst of worlds If you want to attack me you can do it all you want, because I can't do anything about it It's risk free, and you're willing to take almost any risk to come after me,  said James Cartwright, a former vice chairman of the Joint Chiefs of Staff </description><link>http://www.secuobs.com/revue/news/346706.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346706.shtml</guid></item>
<item><title>Restaurant Depot Customers Alerted of Data Breach</title><description>Secuobs.com : 2011-12-12 18:24:57 - Infosec Island Latest Articles -  Trustwave found that that the thieves inserted malicious software or 'malware' into the credit and debit card processing systems used in Restaurant Depot stores The malware collected card information as it was processed, stored it temporarily, and then sent it to a computer server in Russia  </description><link>http://www.secuobs.com/revue/news/346676.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346676.shtml</guid></item>
<item><title>Merchant Beware   New Mobile Payment Solution in the Wild</title><description>Secuobs.com : 2011-12-12 18:24:57 - Infosec Island Latest Articles - Even if Square s software encrypts the data, the underlying OS will also collect the data in cleartext Forensic examinations of these devices have shown time and again that regardless of what the software vendor did, the data still existed in memory unencrypted </description><link>http://www.secuobs.com/revue/news/346675.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346675.shtml</guid></item>
<item><title>ICS-CERT Warns Facilities of Exposure via SHODAN</title><description>Secuobs.com : 2011-12-12 17:34:18 - Infosec Island Latest Articles -  The use of readily available and generally free search tools significantly reduces time and resources required to identify Internet facing control systems In turn, hackers can use these tools to easily identify exposed control systems, posing an increased risk of attack  </description><link>http://www.secuobs.com/revue/news/346657.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346657.shtml</guid></item>
<item><title>Closing the Gate Before the Horse Bolts   On Passwords for the Cloud</title><description>Secuobs.com : 2011-12-12 17:34:18 - Infosec Island Latest Articles - Passwords it seems are both the bane of our existence and, apparently, the most important thing in our lives Unfortunately the Cloud doesn t really change this, good password protocols are as important in the Cloud as they were in an on-premise world and potentially even more so </description><link>http://www.secuobs.com/revue/news/346656.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346656.shtml</guid></item>
<item><title>Measuring Information Security Effectiveness</title><description>Secuobs.com : 2011-12-12 06:31:02 - Infosec Island Latest Articles -  The face of cyber threats has rapidly evolved from curious college kids taking their hand at hacking to an enormous global ecosystem of cyber-crime Companies need a comprehensive approach to security technology, education and awareness and a very small number have truly mastered all three  </description><link>http://www.secuobs.com/revue/news/346586.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346586.shtml</guid></item>
<item><title>Top Ten Mistakes Made By Linux Developers</title><description>Secuobs.com : 2011-12-12 06:31:02 - Infosec Island Latest Articles - My colleague, Dr Joel Isaacson talks about the top ten mistakes made by Linux developers It s a great article and great read from one of the top embedded Linux programmers in the world </description><link>http://www.secuobs.com/revue/news/346585.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346585.shtml</guid></item>
<item><title>The Control Systems Community and Cyber Warfare</title><description>Secuobs.com : 2011-12-12 06:31:02 - Infosec Island Latest Articles - Cyber warfare took place long before the release of Stuxnet, but its release caused the world to realize the benefits of using a domain of warfare with limited entry costs and the possibility of non-attribution, which is the ability to operate without positively being connected to an operation </description><link>http://www.secuobs.com/revue/news/346584.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346584.shtml</guid></item>
<item><title>Cyber Crime Creates More Victims Per Hour than Babies Born</title><description>Secuobs.com : 2011-12-11 07:25:55 - Infosec Island Latest Articles - As more shoppers turn to their laptop, iPads and mobile phones to get items crossed off their list, thieves are on the prowl to hack into systems to obtain customer information   email addresses, passwords, credit card data, PayPal account info, etc </description><link>http://www.secuobs.com/revue/news/346515.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346515.shtml</guid></item>
<item><title>Plagiarism in IT Security - Walking a Fine Line</title><description>Secuobs.com : 2011-12-10 07:29:48 - Infosec Island Latest Articles - At the end of the day, shouldn't we all be professionals  I know it's nice to think that everyone is honest - but as the infosec world expands and there is a massive influx of people trying to make a name for themselves - there will be dishonesty This is where the community comes in </description><link>http://www.secuobs.com/revue/news/346442.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346442.shtml</guid></item>
<item><title>Santa Gets Hacked - Naughty List Leaked  video </title><description>Secuobs.com : 2011-12-09 20:36:48 - Infosec Island Latest Articles - Breaking News  video  Networks at the North Pole have been breached by unidentified hackers leading to the disclosure of sensitive data - Santa's naughty list Don t worry   your secrets are safe  Included is a list of the things we really think are just that - a little bit naughty </description><link>http://www.secuobs.com/revue/news/346375.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346375.shtml</guid></item>
<item><title>Top Ten HTML5 Attack Vectors</title><description>Secuobs.com : 2011-12-09 19:46:23 - Infosec Island Latest Articles -  HTML 5 applications use DOM extensively and dynamically change content via XHR calls DOM manipulation is done by several different DOM-based calls and poor implementation allows DOM-based injections These injections can lead to a set of possible attacks and exploits  </description><link>http://www.secuobs.com/revue/news/346366.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346366.shtml</guid></item>
<item><title>Photo Shows Stuxnet as Perfect Match to Iranian Network</title><description>Secuobs.com : 2011-12-09 18:52:11 - Infosec Island Latest Articles -  When viewed closely, the photo reveals green dots distributed in columns of increasing length Each column contains four dots that represent uranium centrifuges Multiplying these together produces a cascade structure sequence identical to that in Stuxnet  </description><link>http://www.secuobs.com/revue/news/346354.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346354.shtml</guid></item>
<item><title>The Visible Hand  A New Compliance Model</title><description>Secuobs.com : 2011-12-09 18:52:11 - Infosec Island Latest Articles - A company should look for small ways to expand employee autonomy in the compliance area This does not mean a complete abdication of the role of the Compliance Department, but it does mean a notch-by-notch transfer of authority to persons in the field </description><link>http://www.secuobs.com/revue/news/346353.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346353.shtml</guid></item>
<item><title>ENISA Report  Proactive Detection of Network Security Incidents</title><description>Secuobs.com : 2011-12-09 17:02:36 - Infosec Island Latest Articles - The report reveals that not all available tools are used by the  digital fire-brigades , the Computer Emergency Response Teams  CERTs  to effectively fight cyber threats Therefore, the Agency issues 35 recommendations to data providers and consumers to mitigate the shortcomings </description><link>http://www.secuobs.com/revue/news/346336.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346336.shtml</guid></item>
<item><title>SEC Calls for Cohesive Incident Response and Reporting</title><description>Secuobs.com : 2011-12-09 17:02:36 - Infosec Island Latest Articles - This guidance is designed to  elicit disclosure of timely, comprehensive, and accurate information about risks and events that a reasonable investor would consider important to an investment decision,  including those related to information security breaches </description><link>http://www.secuobs.com/revue/news/346335.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346335.shtml</guid></item>
<item><title>PCI Compliance  On Redirects and Reposts</title><description>Secuobs.com : 2011-12-09 06:34:07 - Infosec Island Latest Articles - A number of clients recently prompted me on my take regarding Redirects and Reposts as they attempt to shrink their PCI compliance footprint as small as possible A lot of them like the idea of the repost because it requires only a simple change to their existing e-Commerce sites </description><link>http://www.secuobs.com/revue/news/346246.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346246.shtml</guid></item>
<item><title>Fraudsters Defeat Poor Risk Management - Not Two-Factor Authentication</title><description>Secuobs.com : 2011-12-09 06:34:07 - Infosec Island Latest Articles - Carriers are not incentivized to secure their users accounts SMS is really just an email sent to a phone over a provider that barely cares about security 99pourcents of SMS messages don't require security so don't expect the carriers to add any soon </description><link>http://www.secuobs.com/revue/news/346245.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346245.shtml</guid></item>
<item><title>Network Security in the Age of Social Media</title><description>Secuobs.com : 2011-12-09 06:34:07 - Infosec Island Latest Articles - Social media is now mainstream in corporate America, and the security and privacy issues around it are hot In the past, many firms simply said no to social media at the corporate level But that will no longer work, as social media isn t a choice anymore, it s a business transformation tool </description><link>http://www.secuobs.com/revue/news/346244.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346244.shtml</guid></item>
<item><title>Data Loss Prevention - Without the New Blinky Boxes</title><description>Secuobs.com : 2011-12-08 20:10:24 - Infosec Island Latest Articles - The glut of blinking lights and devices that require time and effort to manage has gotten out of control or so I'm being told I've not manged a security team in 4 years now, but even back then the glut of boxes, products and solutions was becoming too much to bear I can only imagine it now </description><link>http://www.secuobs.com/revue/news/346154.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346154.shtml</guid></item>
<item><title>The Detection in Depth Focus Model</title><description>Secuobs.com : 2011-12-08 20:10:24 - Infosec Island Latest Articles - As explained in the maturity model post before, the closer the detection control is to the asset, the higher the signal to noise ratio it should be and the higher the relevance o the data should be to the asset being protected  Huston s Postulate  </description><link>http://www.secuobs.com/revue/news/346153.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346153.shtml</guid></item>
<item><title>Smart Grid  There Will be a Successful Attack</title><description>Secuobs.com : 2011-12-08 19:20:15 - Infosec Island Latest Articles -  Interfacing so many different hardware and software components introduces vulnerabilities especially when new and legacy hardware and software need to operate together Perfect protection from cyber attacks is not possible There will be a successful attack at some point  </description><link>http://www.secuobs.com/revue/news/346146.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346146.shtml</guid></item>
<item><title>The Top Cyber Criminal Busts of 2011</title><description>Secuobs.com : 2011-12-08 17:35:31 - Infosec Island Latest Articles -  A torrent of attacks from groups like Anonymous, LulzSec, Goatse Security, and Antisec has made it a busy year for cybercrime investigators While there are plenty of elusive hackers that will forever manage to outrun the law, the good guys scored some impressive arrests  </description><link>http://www.secuobs.com/revue/news/346124.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346124.shtml</guid></item>
<item><title>The Nature of Infosec  A Zero Sum Game</title><description>Secuobs.com : 2011-12-08 17:35:31 - Infosec Island Latest Articles - Security is a  Zero Sum Game  - no matter what you do, no matter how many policies you have or blinking lights on an appliance that is alleged to keep out APT, in the end you really have not won the day In fact, if you have not been hacked or abused that day, it was really just a fluke </description><link>http://www.secuobs.com/revue/news/346123.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346123.shtml</guid></item>
<item><title>Is Al Qaeda s Internet Strategy Working </title><description>Secuobs.com : 2011-12-08 06:12:20 - Infosec Island Latest Articles - While almost all terrorist organizations have websites, al Qaeda is the first to fully exploit the Internet This reflects al Qaeda s unique characteristics It regards itself as a global movement and therefore depends on a global communications network to reach its perceived constituents </description><link>http://www.secuobs.com/revue/news/346035.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346035.shtml</guid></item>
<item><title>Printer Hack  Researchers Can Set Media s Pants on Fire</title><description>Secuobs.com : 2011-12-08 06:12:20 - Infosec Island Latest Articles - What was most irresponsible in this case was that the researchers took their exploit of one model of printer from one manufacturer and without even a cursory investigation extrapolated the threat to  hundreds of millions  of printers and fed it to a media hungry for sensational headlines </description><link>http://www.secuobs.com/revue/news/346034.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346034.shtml</guid></item>
<item><title>Importance of a Secure Supply Chain in Selecting IT Vendors</title><description>Secuobs.com : 2011-12-08 06:12:20 - Infosec Island Latest Articles - There have been numerous reports of rootkits and trojans that have been installed on component level chips designed to infiltrate networks from the inside Government agencies have stepped up their diligence regarding what products are allowed to protect infrastructure at high security levels </description><link>http://www.secuobs.com/revue/news/346033.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/346033.shtml</guid></item>
<item><title>Lockheed Warns Adobe of New Exploit in the Wild</title><description>Secuobs.com : 2011-12-07 21:39:51 - Infosec Island Latest Articles -  This U3D memory corruption vulnerability could cause a crash and potentially allow an attacker to take control of the affected system There are reports that the vulnerability is being actively exploited in the wild in limited, targeted attacks against Adobe Reader 9x on Windows  </description><link>http://www.secuobs.com/revue/news/345947.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345947.shtml</guid></item>
<item><title>Malware Infection Rates   Who Has the Most Viruses </title><description>Secuobs.com : 2011-12-07 20:41:53 - Infosec Island Latest Articles - A look at the top viruses for each country shows a lot of cookie based viruses Which may or may not be real viruses, but the rates are high none the less But how does this compare to what other vendors are finding  </description><link>http://www.secuobs.com/revue/news/345928.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345928.shtml</guid></item>
<item><title>NATO  Cybercrime Drains One Trillion Dollars from Economy Yearly</title><description>Secuobs.com : 2011-12-07 19:51:33 - Infosec Island Latest Articles -  One trillion dollars disappears annually from the global economy because of cybercrime Industrial secrets, copyright, intellectual property, state secrets become increasingly difficult to protect Economies are running on these complex systems, which can be easily destroyed,  Shea said </description><link>http://www.secuobs.com/revue/news/345919.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345919.shtml</guid></item>
<item><title>ENISA Smartphone Secure Development Guidelines</title><description>Secuobs.com : 2011-12-07 18:59:15 - Infosec Island Latest Articles - This document was produced jointly with the OWASP mobile security project It is also published as an ENISA deliverable in accordance with our work programme 2011 It is written for developers of smartphone apps as a guide to developing secure applications </description><link>http://www.secuobs.com/revue/news/345903.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345903.shtml</guid></item>
<item><title>Paradigm Shifts  The Network as a Battle Space for Jihad</title><description>Secuobs.com : 2011-12-07 18:03:34 - Infosec Island Latest Articles - Recent events with ICS and SCADA system vulnerabilities has shown that there is a potential for online mischief that AQ could leverage These types of attacks would further the tenets that OBL laid out with regard to a  Death of a Thousand Cuts  type of warfare against the US </description><link>http://www.secuobs.com/revue/news/345883.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345883.shtml</guid></item>
<item><title>Federal Cyber Security R and D Strategy Released</title><description>Secuobs.com : 2011-12-07 17:12:03 - Infosec Island Latest Articles -  Sustained efforts in these areas will result in a more secure and trustworthy cyberspace We invite researchers and innovators in industry and academia to join us in this effort Together, we can maximize the benefits of research and accelerate their transition into the marketplace  </description><link>http://www.secuobs.com/revue/news/345869.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345869.shtml</guid></item>
<item><title>FTC Takes on Super Cookies</title><description>Secuobs.com : 2011-12-07 06:06:25 - Infosec Island Latest Articles - The FTC is an increasingly nimble enforcer, with ever shorter news story-to-enforcement action cycles This approach is consistent with the FTC's stated commitment to take enforcement actions in the areas where the agency believes there is significant non-compliance </description><link>http://www.secuobs.com/revue/news/345765.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345765.shtml</guid></item>
<item><title>Common Errors in Firewall Configurations</title><description>Secuobs.com : 2011-12-07 06:06:25 - Infosec Island Latest Articles - With the  ANY  port accessible vulnerability, clear text protocols could be used when both a secure and less secure clear text service are running on the same system, and vulnerabilities found for specific services such as SMB could be launched against vulnerable machines </description><link>http://www.secuobs.com/revue/news/345764.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345764.shtml</guid></item>
<item><title>Cracking the Code of Silence on Meaningful Security Metrics</title><description>Secuobs.com : 2011-12-07 06:06:25 - Infosec Island Latest Articles - It s ironic, but security policies themselves make it difficult for management to understand the relative value of various security investments, to pinpoint areas of risk, and to translate that information into continuous security improvements </description><link>http://www.secuobs.com/revue/news/345763.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345763.shtml</guid></item>
<item><title>India's ISAC to Recruit Army of White Hat Hackers</title><description>Secuobs.com : 2011-12-06 21:59:13 - Infosec Island Latest Articles -  Less than 15 percent of Indians use the internet, but we are already No 1 when it comes to virus infections and No 2 in cyber crimes As the government is trying to spread its reach through financial inclusion and e-governance projects, it's crucial that we are able to handle cyber crime  </description><link>http://www.secuobs.com/revue/news/345706.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345706.shtml</guid></item>
<item><title>CERT Warns of Holiday Phishing and Malware Campaigns</title><description>Secuobs.com : 2011-12-06 20:13:44 - Infosec Island Latest Articles -  US-CERT encourages users and administrators to use caution when encountering email messages and take the following preventative measures to protect themselves from phishing scams and malware campaigns  </description><link>http://www.secuobs.com/revue/news/345673.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345673.shtml</guid></item>
<item><title>ENISA Releases DigiNotar Report  Operation Black Tulip</title><description>Secuobs.com : 2011-12-06 19:21:47 - Infosec Island Latest Articles -  The Diginotar attack was an attack on the foundations of secure electronic communications  email, web browsing, web services  The above-mentioned issues should be addressed by industry and governments, to guarantee the security of service in the digital society  </description><link>http://www.secuobs.com/revue/news/345658.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345658.shtml</guid></item>
<item><title>A Checklist for Customer Cloud Security</title><description>Secuobs.com : 2011-12-06 19:21:47 - Infosec Island Latest Articles - In our cloud security whitepaper we spent time talking about why Cloud Computing is potentially more secure than traditional models of IT delivery while at the same time pointing out the fact that there s still security issues that organizations need to think about when using Cloud </description><link>http://www.secuobs.com/revue/news/345657.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345657.shtml</guid></item>
<item><title>RSA Hack Analysis  Windows DEP Not Enabled</title><description>Secuobs.com : 2011-12-06 17:39:44 - Infosec Island Latest Articles - New analysis from researchers at Qualys suggests that the success of the attack may have hinged on RSA's use of the older Windows XP operating system and the failure to enable the DEP  data execution prevention  security option </description><link>http://www.secuobs.com/revue/news/345626.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345626.shtml</guid></item>
<item><title>Android Apps Violate Permissions - But Who Cares, Right </title><description>Secuobs.com : 2011-12-06 17:39:44 - Infosec Island Latest Articles - These guys built a tool called  woodpecker  that snakes around inside popular Android phone platforms looking for places where the phone is configured so as to violate the Android permission enforcement model Go read it - you'd be surprised what they've found </description><link>http://www.secuobs.com/revue/news/345625.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345625.shtml</guid></item>
<item><title>Run POST Modules On All Sessions</title><description>Secuobs.com : 2011-12-06 08:55:55 - Infosec Island Latest Articles - You use the POST module, drop to IRB and run those 4 lines, and bam, you win With resource files we can automate this a bit more and have it so that we do this effortlessly with any post module We know we can run ruby inside of resource files with the tag </description><link>http://www.secuobs.com/revue/news/345532.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345532.shtml</guid></item>
<item><title>HP Printer Hack Video Shows Sensitive Data Tweet Too</title><description>Secuobs.com : 2011-12-06 06:38:33 - Infosec Island Latest Articles - The researchers showed how a maliciously formed print job could cause an HP printer s firmware to be reprogrammed so it acts like a copy machine   sending an exact print job to any place in the world, and the attackers also get a tweet showing sensitive information parsed from the print job </description><link>http://www.secuobs.com/revue/news/345516.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345516.shtml</guid></item>
<item><title>Getting Past Security's Fuzzy Math ROI</title><description>Secuobs.com : 2011-12-06 06:38:33 - Infosec Island Latest Articles - It seems that we're using statistics, metrics, surveys and 'studies' to demonstrate what we can't otherwise adequately explain That would be all well and good, if the math wasn't all fuzzy Numbers can't fib, only the people that manipulate them can be accused of that trespass </description><link>http://www.secuobs.com/revue/news/345515.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345515.shtml</guid></item>
<item><title>From Cyber Warfare to Cyber Resistance  A Check on Israel </title><description>Secuobs.com : 2011-12-06 06:38:33 - Infosec Island Latest Articles - Successful operations are defined as those that intrude upon the enemy s virtual space to compromise, degrade, disrupt or impair activity and undermine trust The disadvantage is that effectiveness may only be measured in minutes whereas conventional weapons can remain effective for years </description><link>http://www.secuobs.com/revue/news/345514.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345514.shtml</guid></item>
<item><title>Is the Security Response System for SCADA-ICS Broken </title><description>Secuobs.com : 2011-12-05 21:31:24 - Infosec Island Latest Articles -  Publicly disclosing affected identity names and incident information is highly unusual and not part of ICS-CERT's normal incident reporting and triage procedures In this particular case, because unconfirmed information had already been leaked to the public  </description><link>http://www.secuobs.com/revue/news/345446.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345446.shtml</guid></item>
<item><title>NICE Seeks Feedback on Cybersecurity Workforce Framework</title><description>Secuobs.com : 2011-12-05 19:51:35 - Infosec Island Latest Articles -  Establishing and using a unified framework for cybersecurity work and workers is not merely practical but vital to the nation's cybersecurity Much as other professions have defined their specialties, it is now time to forge a common set of definitions for the cybersecurity workforce  </description><link>http://www.secuobs.com/revue/news/345431.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345431.shtml</guid></item>
<item><title>Top Ten Password Cracking Methods</title><description>Secuobs.com : 2011-12-05 19:05:48 - Infosec Island Latest Articles -  A rainbow table is a list of pre-computed hashes - the numerical value of an encrypted password, used by most systems today - and that s the hashes of all possible password combinations for any given hashing algorithm mind  </description><link>http://www.secuobs.com/revue/news/345413.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345413.shtml</guid></item>
<item><title>US Drone Probably Experienced Mechanical Failure</title><description>Secuobs.com : 2011-12-05 18:17:38 - Infosec Island Latest Articles -  US and NATO officials wouldn t say what kind of American drone had disappeared, but US officials said there was no indication that the aircraft had been shot down by the Iranians One American official said the drone likely suffered from a mechanical failure  </description><link>http://www.secuobs.com/revue/news/345404.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345404.shtml</guid></item>
<item><title>Gleg Releases Version 18 of the SCADA  Exploit Pack</title><description>Secuobs.com : 2011-12-05 18:17:38 - Infosec Island Latest Articles - In SCADA  18 there are modules for several public SCADA ICS vulnerabilities, most of which were recently disclosed by Luigi Auriemma Many of these exploits appear to be denial-of-service  DoS  exploits, so this really is not something that I think is worth the money at this time </description><link>http://www.secuobs.com/revue/news/345403.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345403.shtml</guid></item>
<item><title>Russian Cyber Crime - Pride or Prejudice </title><description>Secuobs.com : 2011-12-05 06:16:59 - Infosec Island Latest Articles -  Why does every hacking and cyberscam story   real or fictional   seem to have a Russia connection  In part, it is prejudice and laziness The stereotype of the Russian hacker has become such a common media trope that it gets recycled again and again  </description><link>http://www.secuobs.com/revue/news/345298.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345298.shtml</guid></item>
<item><title>Controls Have to be Executed Perfectly Every Day</title><description>Secuobs.com : 2011-12-05 06:16:59 - Infosec Island Latest Articles - Security is not perfect, and controls have to be executed perfectly every day, every year - else that is where things always go awry If you execute controls consistently, your organization should be very difficult to compromise and the bad guys will find an easier target </description><link>http://www.secuobs.com/revue/news/345297.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345297.shtml</guid></item>
<item><title>Executives Lack Confidence in Infosec Strategies</title><description>Secuobs.com : 2011-12-05 06:16:59 - Infosec Island Latest Articles - Cyber attacks grow as corporations and governments amass information on individuals in complex networks across the Web, and cyber activists - some motivated by money, others by the desire to destabilize corporations and governments, continue to hack into organizational secrets </description><link>http://www.secuobs.com/revue/news/345296.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345296.shtml</guid></item>
<item><title>Was Iran's Downing of RQ-170 Related to the Malware Infection at Creech AFB </title><description>Secuobs.com : 2011-12-04 22:29:01 - Infosec Island Latest Articles - Iran took over the controls of a Lockheed Martin RQ-170 Sentinel stealth drone and landed it with minimal damage As of this writing, the US Air Force hasn't yet confirmed or denied the attack I've left a message with the on-call PA officer at Creech Air Force Base </description><link>http://www.secuobs.com/revue/news/345275.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345275.shtml</guid></item>
<item><title>Key Sessions at the CISO Executive Summit 2011</title><description>Secuobs.com : 2011-12-04 08:37:06 - Infosec Island Latest Articles - As information assurance matures, its identity in the organizational culture is merging with the business units it supports Practitioners are challenged to adapt their skills to the evolution of an infosec business function separate from its legacy association with the IT department </description><link>http://www.secuobs.com/revue/news/345232.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345232.shtml</guid></item>
<item><title>HIT Security  Conclusions in a Contradictory Report-Sandwich </title><description>Secuobs.com : 2011-12-03 07:55:08 - Infosec Island Latest Articles - The barometer that the Ponemon study uses  ie breach disclosures, breach impact  could actually be an indicator of better security instead of worse It could be the case that breaches are on the rise because we're finding them more because not looking for them so violates federal law </description><link>http://www.secuobs.com/revue/news/345160.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345160.shtml</guid></item>
<item><title>How to Recover a Hacked Facebook Account</title><description>Secuobs.com : 2011-12-02 21:29:47 - Infosec Island Latest Articles - At least weekly some stressed out victim of a Facebook hack aka  account takeover , contacts me to help them get their account back in order While I do have a connection or two at Facebook, the victim of the hack is in the best position to fix it themselves </description><link>http://www.secuobs.com/revue/news/345096.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345096.shtml</guid></item>
<item><title>GAO Blasts Federal Management of Cyber Security Work Force</title><description>Secuobs.com : 2011-12-02 20:42:36 - Infosec Island Latest Articles -  In an era of limited financial resources, better coordinated efforts to address both cybersecurity-specific and broader federal workforce challenges are crucial to cost-effectively ensuring that the government has the people it needs to continue to deal with evolving cyber threats  </description><link>http://www.secuobs.com/revue/news/345090.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345090.shtml</guid></item>
<item><title>TeamPoison Hacks UN Development Program Servers</title><description>Secuobs.com : 2011-12-02 19:54:32 - Infosec Island Latest Articles -  The UN has said that the information exposed is old data, but if you look at the YouTube video released by the hackers on Monday it shows account details and usernames as well as personal email addresses so these people could well be compromised at work and at home  </description><link>http://www.secuobs.com/revue/news/345083.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345083.shtml</guid></item>
<item><title>Researcher Traces Stuxnet Duqu Timeline Back to 2006</title><description>Secuobs.com : 2011-12-02 18:21:34 - Infosec Island Latest Articles -  May 2006 - Engineers compile code for a component of Stuxnet that will allow them to attack programmable logic controllers, or PLCs, manufactured by Siemens of Germany Iran's nuclear program uses Siemens PLCs to control the gas centrifuges in its uranium enrichment facilities  </description><link>http://www.secuobs.com/revue/news/345058.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345058.shtml</guid></item>
<item><title>Challenges for Software Security Professionals</title><description>Secuobs.com : 2011-12-02 18:21:34 - Infosec Island Latest Articles - So what catches your attention  What conclusions can you draw here that may be insight into how we can improve the state of software security in the enterprise  My eye gets caught on  politics  and TOOLS in big bold letters then UPHILL and APATHY Dang, we're a cynical bunch aren't we </description><link>http://www.secuobs.com/revue/news/345057.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/345057.shtml</guid></item>
<item><title>What Facebook s FTC Settlement Means for Businesses</title><description>Secuobs.com : 2011-12-02 06:37:06 - Infosec Island Latest Articles - The basic concept is actually quite simple  Companies should include privacy concepts and controls into new products and services during their development stage rather than treating privacy as an afterthought or ignoring it altogether </description><link>http://www.secuobs.com/revue/news/344964.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344964.shtml</guid></item>
<item><title>Case Study  SOX IT Compliance</title><description>Secuobs.com : 2011-12-02 06:37:06 - Infosec Island Latest Articles - We performed a Sarbanes-Oxley IT top down security assessment for a NASDAQ-traded advanced technology company to evaluate internal and external threats that impact the company s information assets Using Business Threat Modeling, a practical threat analysis model was constructed </description><link>http://www.secuobs.com/revue/news/344963.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344963.shtml</guid></item>
<item><title>Duqu Servers Included Hacked Linux Systems</title><description>Secuobs.com : 2011-12-02 06:37:06 - Infosec Island Latest Articles - Be it brute force password hacking or another Stuxnet 0-Day, Duqu shows that Linux is vulnerable to hackers With a growing install base, supplanting Windows in many facilities, expect it to become even more of a target </description><link>http://www.secuobs.com/revue/news/344962.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344962.shtml</guid></item>
<item><title>Holiday Headaches Coming for Consumers</title><description>Secuobs.com : 2011-12-01 20:51:11 - Infosec Island Latest Articles - When handing your card to a clerk or cashier, pay close attention The card should be swiped through a point of sale terminal or keyboard card reader once, maybe twice If your card is swiped through an additional reader, the card number may have been stolen </description><link>http://www.secuobs.com/revue/news/344904.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344904.shtml</guid></item>
<item><title>US Military Chief Warns of Economic Cyber Threat</title><description>Secuobs.com : 2011-12-01 19:57:07 - Infosec Island Latest Articles -  We lose enormous intellectual property rights We're under constant attack every day And it's going to take a whole government approach,  said General Martin Dempsey, Chairman of the Joint Chiefs of Staff </description><link>http://www.secuobs.com/revue/news/344891.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344891.shtml</guid></item>
<item><title>Anonymous and AntiSec  Mixing Metaphors Can Lead to Trouble</title><description>Secuobs.com : 2011-12-01 19:00:16 - Infosec Island Latest Articles - It seems that much of the recent OP s like Robin Hood are just dysfunctional ideas And the videos are getting closer to the jihadi videos that AQ has been putting out over the years The same graphics, the same music, the same metaphor and rhetoric with a tinge of threat </description><link>http://www.secuobs.com/revue/news/344846.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344846.shtml</guid></item>
<item><title>Obama Designates December as Critical Infrastructure Protection Month</title><description>Secuobs.com : 2011-12-01 18:14:10 - Infosec Island Latest Articles -  As we navigate new and uncertain challenges in the digital age, we must also address the growing threat cyberattacks present to our transportation networks, electricity grid, financial systems and other assets we are committed to protecting our critical infrastructure  </description><link>http://www.secuobs.com/revue/news/344829.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344829.shtml</guid></item>
<item><title>Bank Executive Pleads Guilty to Stealing Nearly  2 Million</title><description>Secuobs.com : 2011-12-01 17:25:51 - Infosec Island Latest Articles -  Walker withdrew money from a line of credit in the name of a trust that held an account at Farmers and Merchants To cover up the scheme, Walker made interest payments on the money supposedly loaned to the trust Walker will face a maximum sentence of 30 years in federal prison  </description><link>http://www.secuobs.com/revue/news/344816.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344816.shtml</guid></item>
<item><title> Almost  All Your  BASE  Are Belong to Us </title><description>Secuobs.com : 2011-12-01 17:25:51 - Infosec Island Latest Articles - The HTML element Cross Site Scripting  XSS  I will discuss abuses the  best practice  among web developers to use relative links and the tendency of web browsers to parse incorrect HTML HTML tags are often used in XSS attacks to an attacker inject dangerous javascript or html content </description><link>http://www.secuobs.com/revue/news/344815.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344815.shtml</guid></item>
<item><title>From Russia with Malice  The REAL Issue Behind the Illinois 'Attack'</title><description>Secuobs.com : 2011-12-01 06:14:00 - Infosec Island Latest Articles - It s an all too familiar story  something doesn t feel right, but confirming whether something has happened, if it is something you should be concerned about, what the vector of the potential attack might be, and what you can do to mitigate the damage is very difficult to pinpoint </description><link>http://www.secuobs.com/revue/news/344729.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344729.shtml</guid></item>
<item><title>Security 2012  Blood in the Water</title><description>Secuobs.com : 2011-12-01 06:14:00 - Infosec Island Latest Articles - CEOs refuse to act to protect their companies if it cuts into profit, the government has refused to protect our nation s critical infrastructure because it's 90pourcents privately owned, and our laws have enabled this massive malfeasance so that everyone responsible can claim absence of malice </description><link>http://www.secuobs.com/revue/news/344728.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344728.shtml</guid></item>
<item><title>The Evolution of Holiday Thievery</title><description>Secuobs.com : 2011-11-30 21:08:25 - Infosec Island Latest Articles - As far back as I can remember, police have been warning of thieves who target cars in parking lots, smashing windows to steal shopping bags left in plain sight Now the warnings are different  no longer so focused on crime in the physical world, but instead, on threats in the virtual world </description><link>http://www.secuobs.com/revue/news/344664.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344664.shtml</guid></item>
<item><title>FBI  Three Cities Compromised via SCADA Networks</title><description>Secuobs.com : 2011-11-30 20:17:05 - Infosec Island Latest Articles -  Essentially it was an ego trip for the hacker because he had control of that city s systems and he could dump raw sewage into the lake, he could shut down the power plant at the mall   a wide array of things  </description><link>http://www.secuobs.com/revue/news/344653.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344653.shtml</guid></item>
<item><title>Webinar to Examine ICS Security in Water Control Systems</title><description>Secuobs.com : 2011-11-30 20:17:05 - Infosec Island Latest Articles - Trusted Metrics is hosting a monthly webinar series on Industrial Control System  ICS  Cybersecurity Each session will speak to the issues faced by those operating and building industrial facilities This next session will be addressing Cybersecurity in Water and Wastewater Control Systems </description><link>http://www.secuobs.com/revue/news/344652.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344652.shtml</guid></item>
<item><title>Collision of Physical and Digital Defenses</title><description>Secuobs.com : 2011-11-30 19:25:50 - Infosec Island Latest Articles - With all the SCADA hacking lately we have to let reason guide us, and emphasize temperance while we develop our own defensive capability in the digital age It's too easy to just say  strike the attacker  but much harder when that attacker is a virtual ghost in the fabric of cyberspace </description><link>http://www.secuobs.com/revue/news/344636.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344636.shtml</guid></item>
<item><title>PwC s Economic Crime Survey Focuses on Cybercrime</title><description>Secuobs.com : 2011-11-30 18:30:49 - Infosec Island Latest Articles -  Many executives have yet to seize upon the serious nature of the cybercrime threat Cybercrime has emerged as a formidable threat, thanks to deeply determined, highly skilled, and well-organized cybercriminals, from nation states to hacktivists, from criminal gangs to lone-wolf perpetrators  </description><link>http://www.secuobs.com/revue/news/344624.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344624.shtml</guid></item>
<item><title>HIPAA Tool Helps Organizations Meet Security Requirements</title><description>Secuobs.com : 2011-11-30 17:42:12 - Infosec Island Latest Articles - A new tool, developed by the NIST is intended to be a resource that organizations can use to support their risk assessment processes by identifying areas where security safeguards may be needed to protect EPHI, or where existing security safeguards may need to be improved </description><link>http://www.secuobs.com/revue/news/344608.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344608.shtml</guid></item>
<item><title>Implementing or Enhancing a Compliance Program</title><description>Secuobs.com : 2011-11-30 06:05:29 - Infosec Island Latest Articles - Many companies are still in the infancy of creating their compliance programs with their General Counsel or perhaps hiring an initial Compliance Officer This person or persons may be somewhat overwhelmed about how to even get started </description><link>http://www.secuobs.com/revue/news/344508.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344508.shtml</guid></item>
<item><title>Debating Cyber Warfare   More Questions from GOV</title><description>Secuobs.com : 2011-11-30 06:05:29 - Infosec Island Latest Articles - The problem of Attribution  Not knowing who will attack, is attacking or has attacked you complicates the situation considerably It makes all action and reaction susceptible to a fair margin of error and so any response should be carefully considered before execution </description><link>http://www.secuobs.com/revue/news/344507.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344507.shtml</guid></item>
<item><title>Medical Devices and Electromagnetic Interference</title><description>Secuobs.com : 2011-11-30 06:05:29 - Infosec Island Latest Articles - Enamored by technology, we tend to place tremendous faith in electronic gadgets that  just seem to work    perhaps we are lulled into a sense of technical complacency by the general reliability of technology around us  Do we even have insight into the potential EMI problems  </description><link>http://www.secuobs.com/revue/news/344506.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344506.shtml</guid></item>
<item><title>FCC's Ten Cyber Security Tips for Small Businesses</title><description>Secuobs.com : 2011-11-29 23:06:01 - Infosec Island Latest Articles -  Broadband and information technology are powerful factors in small businesses reaching new markets and increasing productivity and efficiency However, businesses need cybersecurity tools and tactics to protect themselves, their customers, and their data from growing cyber threats  </description><link>http://www.secuobs.com/revue/news/344442.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344442.shtml</guid></item>
<item><title>The Hezbollah Cyber Army  War in Hyperspace </title><description>Secuobs.com : 2011-11-29 23:06:01 - Infosec Island Latest Articles - The whole idea of a Cyber Jihad is a notion that should not just be sloughed off as rhetoric I do think that if the VEVAK are involved  and they would want a hand in this I am sure  they could in fact get some real talent and reign in the ranks to do some real damage down the road </description><link>http://www.secuobs.com/revue/news/344441.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344441.shtml</guid></item>
<item><title>Millions of Printers Vulnerable to Hacking Attacks</title><description>Secuobs.com : 2011-11-29 21:21:06 - Infosec Island Latest Articles -  How many of those printers are out there  It could be much more than 100 million It may ultimately lead to telling everyone they just have to throw their printers out and start over Fixing this is going to require a very coordinated effort by the industry  </description><link>http://www.secuobs.com/revue/news/344417.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344417.shtml</guid></item>
<item><title>Memory Forensics  Analyzing a Stuxnet Memory Dump</title><description>Secuobs.com : 2011-11-29 19:38:52 - Infosec Island Latest Articles - Take a look at a memory dump from a system with Stuxnet - this code has execute and read write permissions We could go on and find Stuxnet registry key settings, hidden Dll s, file objects and numerous other artifacts in this memory sample all with using Volatility </description><link>http://www.secuobs.com/revue/news/344398.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344398.shtml</guid></item>
<item><title>Feds Seize 150 Websites in Massive Holiday Sting</title><description>Secuobs.com : 2011-11-29 18:52:13 - Infosec Island Latest Articles -  We are aggressively targeting those who are selling counterfeit goods for their own personal gain while costing our economy much-needed revenue and jobs Intellectual property crimes harm businesses and consumers, alike, threatening economic opportunity and financial stability  </description><link>http://www.secuobs.com/revue/news/344387.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344387.shtml</guid></item>
<item><title>NIST Improves Tool for Hardening Software Security</title><description>Secuobs.com : 2011-11-29 18:05:23 - Infosec Island Latest Articles -  The SRD is for companies that build static analyzers It will help their products catch the most common errors in the software they are supposed to check It brings rigor into software assurance, so that the public can be more confident that there are fewer dangerous weaknesses  </description><link>http://www.secuobs.com/revue/news/344373.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344373.shtml</guid></item>
<item><title>Security BSides is Coming to Iowa</title><description>Secuobs.com : 2011-11-29 18:05:23 - Infosec Island Latest Articles - Each BSides is a community-driven framework for building events for and by information security community members It is an intense event with discussions, demos, and interaction from participants It is where conversations for the next-big-thing are happening You don t want to miss it </description><link>http://www.secuobs.com/revue/news/344372.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344372.shtml</guid></item>
<item><title>Cloud Security   It s All About Partnership</title><description>Secuobs.com : 2011-11-29 06:36:04 - Infosec Island Latest Articles - Cloud security is a two way street   both vendors and customers have a part to play in keeping it safe, and both parties need to bring something to the table But, notwithstanding this fact, Cloud is still the best option for a number of SMB use cases </description><link>http://www.secuobs.com/revue/news/344264.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344264.shtml</guid></item>
<item><title>Infosec  Homer Simpson or George Washington </title><description>Secuobs.com : 2011-11-29 06:36:04 - Infosec Island Latest Articles - Consider three fields when pondering infosec strategies  Defense, Economics, and Healthcare All three have grasped nonlinear preventative and swarm tactics in a way we would be wise to consider And like infosec, all three also have snake oil salesmen and demons to satiate </description><link>http://www.secuobs.com/revue/news/344263.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344263.shtml</guid></item>
<item><title>Iranian Cyber-Jihadi Cells Plot Western Destruction</title><description>Secuobs.com : 2011-11-28 20:44:57 - Infosec Island Latest Articles -  The first state to appropriate the strategy of asymmetric war itself was the Islamic Republic of Iran Because in  cyberspace  one can destroy the laws that have been created by the security apparatus of the enemy, and one can attack their strategies  </description><link>http://www.secuobs.com/revue/news/344160.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344160.shtml</guid></item>
<item><title>McAfee  The Twelve Scams of Christmas</title><description>Secuobs.com : 2011-11-28 20:44:57 - Infosec Island Latest Articles - Whether you like it or not, the Christmas machine arrived well before Thanksgiving   at least as far as stores and advertisers are concerned And there s no question that scammers, identity thieves, and criminal hackers have already begun setting traps for holiday shoppers </description><link>http://www.secuobs.com/revue/news/344159.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344159.shtml</guid></item>
<item><title>Protecting and Promoting the UK in a Digital World</title><description>Secuobs.com : 2011-11-28 19:01:05 - Infosec Island Latest Articles -  With greater openness, interconnection and dependency comes greater vulnerability The threat to our national security from cyber attacks is real and growing Organised criminals, terrorists, hostile states, and  hacktivists  are all seeking to exploit cyber space to their own ends  </description><link>http://www.secuobs.com/revue/news/344130.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344130.shtml</guid></item>
<item><title>e-Commerce Risks for Cyber Monday and the Holidays</title><description>Secuobs.com : 2011-11-28 19:01:05 - Infosec Island Latest Articles - To deal with the potential volume, they can turn to cloud-based services to add capacity and prevent the site from crashing, but as we'll discuss below, the availability commitments made by many cloud services create their own risks </description><link>http://www.secuobs.com/revue/news/344129.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344129.shtml</guid></item>
<item><title>AT T Hackers Funded Terrorist Group that Struck India</title><description>Secuobs.com : 2011-11-28 17:22:11 - Infosec Island Latest Articles -  The hackers were working on commission for a terrorist group linked to Muhammad Zamir, according to the Philippine police Zamir, a Pakistani, was arrested in Italy in 2007, where he was running a call center and allegedly buying information from Filipino hackers  </description><link>http://www.secuobs.com/revue/news/344100.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344100.shtml</guid></item>
<item><title>GovCloudcom  New Hub for Government Cloud Computing </title><description>Secuobs.com : 2011-11-28 17:22:11 - Infosec Island Latest Articles - GovCoud is the  go to  place for everything related to federal cloud computing Our mission is to help federal organizations learn about, try and securely adopt cloud computing technologies This site will provide a community hub for information dissemination and GovCloud best practices </description><link>http://www.secuobs.com/revue/news/344099.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344099.shtml</guid></item>
<item><title>Plagiarism is Bad - Oh Look, A New Song to Download</title><description>Secuobs.com : 2011-11-28 06:59:15 - Infosec Island Latest Articles - I fully sided with Corelan in the fact that they have put effort into producing so much good quality material only for Infosec Institute to steal it and try to make a profit from it I picked up my cyber pitchfork with every intention to storm the castle However, I ve been thinking </description><link>http://www.secuobs.com/revue/news/344030.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344030.shtml</guid></item>
<item><title>Skype in the Enterprise   Is Your Security Program Ready to Chat </title><description>Secuobs.com : 2011-11-28 06:59:15 - Infosec Island Latest Articles - Beside the fact that it's possible to have a bit more confidence in how Skype traffic is encrypted, is there enough information now to make a fully-formed risk decision on whether or not to use Skype  It's useful to step back and evaluate the fuller picture in the context of your existing operations </description><link>http://www.secuobs.com/revue/news/344029.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344029.shtml</guid></item>
<item><title>The War Over SCADA - An Insider's Perspective</title><description>Secuobs.com : 2011-11-27 04:58:01 - Infosec Island Latest Articles - Media reports would lead the outside observer to believe that nothing is being done to improve the state of cybersecurity for our critical infrastructure, and this is completely false A significant amount of effort is being expended in both improving the security of existing systems </description><link>http://www.secuobs.com/revue/news/343953.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/343953.shtml</guid></item>
<item><title>Five Key Aspects of a Good Infosec Risk Assessment</title><description>Secuobs.com : 2011-11-26 06:53:44 - Infosec Island Latest Articles - Because they are consistent and repeatable, current risk assessment results can be compared to previous years  results to see if there was any growth You can also compare the client s status to other companies of similar size and stature to show them where they stand </description><link>http://www.secuobs.com/revue/news/343888.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/343888.shtml</guid></item>
<item><title>Nearly 80pourcents of Retailers' Data at High Risk</title><description>Secuobs.com : 2011-11-25 06:32:33 - Infosec Island Latest Articles - Now, after five years of pushing standards out to merchants and retailers, a Verizon study has found that 79pourcents of retailers are noncompliant No matter how you slice it, retailers are a target and must employ multiple layers of fraud protection to thwart cyber criminals </description><link>http://www.secuobs.com/revue/news/343769.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/343769.shtml</guid></item>
<item><title>ICS-CERT Issues Illinois Water Pump Failure Report</title><description>Secuobs.com : 2011-11-24 21:32:25 - Infosec Island Latest Articles - ICS-CERT and the FBI found no evidence of a cyber intrusion In addition, there is no evidence to support claims made in the initial Illinois STIC report that any credentials were stolen, or that the vendor was involved in any malicious activity that led to a pump failure </description><link>http://www.secuobs.com/revue/news/343724.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/343724.shtml</guid></item>
<item><title>Ineffective CISOs Foster Shady Vendor Practices</title><description>Secuobs.com : 2011-11-24 12:39:24 - Infosec Island Latest Articles - The question remains how much faith is too much to put in the hands of your vendors  Without a thorough analysis of the inner workings of your organization, it is impossible for any external entity to make recommendations on where your reactionary dollars are best spent </description><link>http://www.secuobs.com/revue/news/343650.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/343650.shtml</guid></item>
<item><title>Espionage  Protecting American Innovation in Cyberspace</title><description>Secuobs.com : 2011-11-23 19:42:27 - Infosec Island Latest Articles -  The Chinese are aggressively hacking into our nation s networks, threatening our critical infrastructure and stealing secrets worth millions of dollars in intellectual property This jeopardizes our national security and hurts US competitiveness in the world market  </description><link>http://www.secuobs.com/revue/news/342280.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342280.shtml</guid></item>
<item><title>Memory Forensics  Pull Process and Network Connections from a Memory Dump</title><description>Secuobs.com : 2011-11-23 18:49:41 - Infosec Island Latest Articles - From the output of the command, we see the physical memory location, process name and the PID number of all processes that were running This helps deduce if something was running that should not have been and allows you to view programs that may be running under the process </description><link>http://www.secuobs.com/revue/news/342264.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342264.shtml</guid></item>
<item><title>DHS Officials Deny Hack of Illinois Water Systems</title><description>Secuobs.com : 2011-11-23 18:01:25 - Infosec Island Latest Articles - While news that there was not a systems breach at the facility is certainly welcome, the conclusions of ICS-CERT and the FBI fail to provide an explanation as to why the Illinois Statewide Terrorism and Intelligence Center initially believed the facility had been compromised </description><link>http://www.secuobs.com/revue/news/342252.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342252.shtml</guid></item>
<item><title>Webinar  ICS Cyber Security in Water Control Systems</title><description>Secuobs.com : 2011-11-23 08:31:55 - Infosec Island Latest Articles - Trusted Metrics is hosting a monthly webinar series on Industrial Control System  ICS  Cybersecurity Each session will speak to the issues faced by those operating and building industrial facilities This session will be addressing Cybersecurity in Water and Wastewater Control Systems </description><link>http://www.secuobs.com/revue/news/342178.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342178.shtml</guid></item>
<item><title>Free From Defect Software License</title><description>Secuobs.com : 2011-11-23 06:12:50 - Infosec Island Latest Articles - This is a question that I would like to pose to the open-source software community  Assuming that we can ignore the lawyers for a second, what amount of effort would you be willing to put to produce software that is free of defect from workmanship  How will you go about making sure  </description><link>http://www.secuobs.com/revue/news/342169.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342169.shtml</guid></item>
<item><title>DDoS  The Message is Often Lost in the Noise</title><description>Secuobs.com : 2011-11-23 06:12:50 - Infosec Island Latest Articles - Most in the security industry frown upon botnet-for-hire operators that sell their stolen bandwidth for illicit purposes Personally, while I don't like or agree with it, I understand it They are no different than any other person selling questionable or illicit services or goods in our society </description><link>http://www.secuobs.com/revue/news/342168.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342168.shtml</guid></item>
<item><title>The Cloud of Clouds  Amazon Web Services</title><description>Secuobs.com : 2011-11-23 00:17:38 - Infosec Island Latest Articles - Security is paramount Amazon states   In order to provide end-to-end security and end-to-end privacy, AWS builds services in accordance with security best practices, provides appropriate security features in those services, and documents how to use those features  </description><link>http://www.secuobs.com/revue/news/342118.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342118.shtml</guid></item>
<item><title>Remote Deposit Capture  RDC  Could Escalate Fraud</title><description>Secuobs.com : 2011-11-22 22:36:14 - Infosec Island Latest Articles -  With banks and financial institutions expanding this service to a retail customer base that often undergoes less stringent due diligence than do their commercial customers, is the potential for fraud increasing  </description><link>http://www.secuobs.com/revue/news/342099.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342099.shtml</guid></item>
<item><title>Wanted  Software Security Specialists Are There Any </title><description>Secuobs.com : 2011-11-22 19:58:54 - Infosec Island Latest Articles - You don't just go to college, get a degree in 'software security' and walk into a job being great at it - mostly because that degree doesn't exist, but also because the days of being able to walk into a job like this are probably long behind us </description><link>http://www.secuobs.com/revue/news/342060.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342060.shtml</guid></item>
<item><title>Mass Disclosure of Vulnerabilities in SAP</title><description>Secuobs.com : 2011-11-22 19:11:47 - Infosec Island Latest Articles - This month ERPScan specialists published eight vulnerabilities of different criticality found in SAP products The vulnerabilities represented almost all risks from the OWASP Top 10, from path traversal and XSS to authorization bypass and code injection </description><link>http://www.secuobs.com/revue/news/342041.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342041.shtml</guid></item>
<item><title>ICS-CERT and FBI Statements on Water System Attacks</title><description>Secuobs.com : 2011-11-22 19:11:47 - Infosec Island Latest Articles - ICS-CERT has not received any additional reports of impacted manufacturers of ICS or other ICS related stakeholders related to these events any information about possible impacts to additional entities, it will disseminate timely mitigation information as it becomes available </description><link>http://www.secuobs.com/revue/news/342040.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342040.shtml</guid></item>
<item><title>Report Details China's Electronic Espionage Apparatus</title><description>Secuobs.com : 2011-11-22 18:23:26 - Infosec Island Latest Articles -  In Senate testimony in 2011, Director of National Intelligence James Clapper outlined concerns about Chinese cyber surveillance, highlighting that the  Chinese have made a substantial investment in this area, they have a very large organization devoted to it and they re pretty aggressive  </description><link>http://www.secuobs.com/revue/news/342028.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342028.shtml</guid></item>
<item><title>Mass Disclose of Vulnerabilities in SAP</title><description>Secuobs.com : 2011-11-22 18:23:26 - Infosec Island Latest Articles - This month ERPScan specialists published eight vulnerabilities of different criticality found in SAP products The vulnerabilities represented almost all risks from the OWASP Top 10, from path traversal and XSS to authorization bypass and code injection </description><link>http://www.secuobs.com/revue/news/342027.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/342027.shtml</guid></item>
<item><title>ACL Complexity and Unknown Vulnerabilities</title><description>Secuobs.com : 2011-11-22 07:13:38 - Infosec Island Latest Articles - If the only way to tell if the ACLs are properly configured is to use another detection mechanism that is capable of identifying improper traffic and nobody had anything like that on their networks, then how many networks are completely vulnerable and do not know it  </description><link>http://www.secuobs.com/revue/news/341900.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341900.shtml</guid></item>
<item><title>The Importance of Software Updating</title><description>Secuobs.com : 2011-11-22 07:13:38 - Infosec Island Latest Articles - There is software that can scan your network and check for these un-patched systems The software can report back exactly which software updates are missing, and then use another tool to actually exploit those vulnerabilities An attacker could take complete control of your computer </description><link>http://www.secuobs.com/revue/news/341899.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341899.shtml</guid></item>
<item><title>Decrypting QSA Qualifications in a Diluted Market Place</title><description>Secuobs.com : 2011-11-22 06:26:14 - Infosec Island Latest Articles - One of the biggest challenges is how to determine which 3rd party QSA company to use With 120  QSA companies certified to perform On-Site Assessments in the USA, there is not an easy answer, unless of course price is the only consideration Unfortunately, sometimes this is the case </description><link>http://www.secuobs.com/revue/news/341895.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341895.shtml</guid></item>
<item><title>ICS Cybersecurity  Water, Water Everywhere</title><description>Secuobs.com : 2011-11-21 20:55:48 - Infosec Island Latest Articles - Monitoring of water treatment networks using common SIEM or log management tools offers the kind of capability that can address the ineed for visibility into control system behavior The ICS networks found in water facilities are deterministic systems with highly predictable behavior </description><link>http://www.secuobs.com/revue/news/341831.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341831.shtml</guid></item>
<item><title>TakeDownCon Las Vegas  Big Discounts and Freebies</title><description>Secuobs.com : 2011-11-21 20:06:39 - Infosec Island Latest Articles - Seriously Sign up for TakeDownCon trainings and enjoy a 15pourcents discount, three complimentary TakeDownCon passes, a 'Test Pass Guarantee', a  300 discount voucher for training at any Hacker Halted, and CHOICE OF a free iPad 2, or a  500 Tiffany   Co Gift Card, or four nights hotel accommodations </description><link>http://www.secuobs.com/revue/news/341823.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341823.shtml</guid></item>
<item><title>Affiliate Marketing Scam</title><description>Secuobs.com : 2011-11-21 19:19:07 - Infosec Island Latest Articles - Just about every adult website has an affiliate program and it is not uncommon for scammers to look for ways to take advantage of these programs I was recently informed by a large payment gateway operator of a scam that is currently in operation Here is how it works </description><link>http://www.secuobs.com/revue/news/341812.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341812.shtml</guid></item>
<item><title>Malicious Cyber Activities Directed Against US Satellites</title><description>Secuobs.com : 2011-11-21 18:28:32 - Infosec Island Latest Articles -  Two US government satellites have each experienced at least two separate instances of interference apparently consistent with cyber activities against their command and control systems The techniques appear consistent with authoritative Chinese military writings  </description><link>http://www.secuobs.com/revue/news/341799.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341799.shtml</guid></item>
<item><title>Top Ten Most Easily Guessed Passwords</title><description>Secuobs.com : 2011-11-21 17:38:40 - Infosec Island Latest Articles - Are you using the password  password  or  123456  If so congratulations, you are using one of the top two worst and easiest to guess passwords on the internet Splashdata creates an annual list of the worst passwords to use on the net, and here are the top 10 for 2011 </description><link>http://www.secuobs.com/revue/news/341781.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341781.shtml</guid></item>
<item><title>Getting Smacked in the Face Over TCP</title><description>Secuobs.com : 2011-11-21 17:38:40 - Infosec Island Latest Articles - Those who see concerted nation-state cyber attacks in every compromised system are like the little boy who cried  Stuxnet  whenever a control system is hacked and those who poo-poo the vulnerabilities that come to light are like the little pig who built his house of straw and said  I'm safe  </description><link>http://www.secuobs.com/revue/news/341780.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341780.shtml</guid></item>
<item><title>The Urgent Need for Mobile Device Security Policies</title><description>Secuobs.com : 2011-11-21 06:39:28 - Infosec Island Latest Articles - When gaps are uncovered in an environment, they must be augmented with new policies, as is the case with mobile devices The need for businesses and government to establish strong policies for mobile environments and the protection of information used with mobile devices is immediate </description><link>http://www.secuobs.com/revue/news/341690.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341690.shtml</guid></item>
</channel>
</rss>
 
