<?xml version="1.0"?>
<rss version="2.0">
<channel><title>ISN</title>
<description>InfoSecurity News</description>
<item>
<title>[ISN] Ford Motor Rolls Out New Security Features To Prevent Car-Hacking</title>
<link>http://lists.jammed.com/ISN/2010/03/0032.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Ford%20Motor%20Rolls%20Out%20New%20Security%20Features%20To%20Prevent%20Car-Hacking">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Tue, 9 Mar 2010 10:50:08 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.darkreading.com/vulnerability_management/security/client/showArticle.jhtml?articleID=223200163">http://www.darkreading.com/vulnerability_management/security/client/showArticle.jhtml?articleID=223200163</a><BR />
<BR />
By Kelly Jackson Higgins<BR />
DarkReading<BR />
March 08, 2010 <BR />
<BR />
Automobile giant Ford Motor this year will debut vehicles with built-in <BR />
WiFi -- along with enhanced security features to prevent data breaches <BR />
via its new cars.<BR />
<BR />
Ford has offered the so-called Sync technology service it co-developed <BR />
with Microsoft in most of its Ford, Lincoln, and Mercury vehicles since <BR />
2008. The technology lets drivers run their Bluetooth-enabled mobile <BR />
phones and digital media players via their vehicles and use voice <BR />
commands to operate them, for instance.<BR />
<BR />
The automaker announced today that the second generation of its Sync <BR />
technology -- due out later this year and to include a full Windows CE <BR />
operating system with a new driver interface called MyFordTouch -- will <BR />
come with a built-in browser and secured WiFi access. It will first <BR />
debut in the 2011 Ford Edge and 2011 MKX Lincoln, and later, in the 2010 <BR />
Ford Focus.<BR />
<BR />
&quot;We really began to focus on the security side when we began launching <BR />
Sync, and it was [originally] for working with phones and media <BR />
players,&quot; says Jim Buczkowski, director of Ford electronics and <BR />
electrical systems engineering. &quot;Now we're extending that system <BR />
connectivity to include WiFi as another data path for customers in their <BR />
vehicles ... and we're extending that security model for protecting <BR />
WiFi.&quot;<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Tue Mar 09 2010 - 08:50:08 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Tue, 9 Mar 2010 10:50:08 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] WhitePages.com halts ad networks over malware</title>
<link>http://lists.jammed.com/ISN/2010/03/0036.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20WhitePages.com%20halts%20ad%20networks%20over%20malware">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Thu, 11 Mar 2010 00:20:57 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://news.cnet.com/8301-27080_3-10466753-245.html">http://news.cnet.com/8301-27080_3-10466753-245.html</a><BR />
<BR />
By Elinor Mills<BR />
InSecurity Complex<BR />
CNet News<BR />
March 10, 2010<BR />
<BR />
WhitePages.com has stopped ad networks from delivering ads to its site <BR />
after they were found to contain fake antivirus malware.<BR />
<BR />
&quot;On Monday morning WhitePages received reports from users [about] <BR />
malware in the form of a fake antivirus upsell program that we believe <BR />
originated (against our terms) from a third-party advertising network <BR />
serving ads on our website, in addition to other websites,&quot; a WhitePages <BR />
spokeswoman said in an e-mail late Tuesday.<BR />
<BR />
&quot;We immediately suspended the networks in question at which time the <BR />
reports from users subsided,&quot; she wrote. &quot;We are working diligently to <BR />
prevent this from happening in the future.&quot;<BR />
<BR />
A representative for the Senate's Committee on Environment and Public <BR />
Works said on Tuesday that officials were looking at WhitePages.com and <BR />
Drudge Report as possible sources of malware that had affected Senate <BR />
computers the day before.<BR />
<BR />
Matt Drudge denied the accusation on his site and accused the committee <BR />
of politicking. But several CNET readers reported that they too had been <BR />
hit with the malware when they visited the Drudge Report Web site, a <BR />
conservative news aggregator that sometimes authors stories too.<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Wed Mar 10 2010 - 22:20:57 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Thu, 11 Mar 2010 00:20:57 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] Why Bob Maley's Firing is Bad for All of Us</title>
<link>http://lists.jammed.com/ISN/2010/03/0041.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Why%20Bob%20Maley's%20Firing%20is%20Bad%20for%20All%20of%20Us">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Fri, 12 Mar 2010 00:12:15 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://threatpost.com/en_us/blogs/why-bob-maleys-firing-bad-all-us-031110">http://threatpost.com/en_us/blogs/why-bob-maleys-firing-bad-all-us-031110</a><BR />
<BR />
By Dennis Fisher<BR />
Threatpost<BR />
March 11, 2010<BR />
<BR />
The news that Pennsylvania CISO Bob Maley lost his job for publicly <BR />
discussing a security incident at last week's RSA Conference really <BR />
shouldn't come as a surprise, but it does. Even for a government agency, <BR />
this kind of lack of understanding of what actually matters is appalling <BR />
and it is a glaring example of the sickness of secrecy that's infected <BR />
far too much of the security community.<BR />
<BR />
Maley was the Pennsylvania CISO for four years and essentially started <BR />
the state's information security program from scratch when he took the <BR />
job. He brought the dozens of state agencies and thousands of employees <BR />
into the 21st century with a massive project to install intrusion <BR />
prevention and an identity and access-management system. When he got <BR />
there, Pennsylvania didn't even have a standard desktop OS image. And <BR />
this is a network that was seeing more than a billion security events a <BR />
month in 2007.<BR />
<BR />
As a result of his success in transforming the state's infrastructure, <BR />
Maley became a sought-after speaker and interview subject, a fact that <BR />
led directly to his firing. At RSA, Maley was on a panel that discussed <BR />
security issues facing state governments. During the session he talked <BR />
about a recent incident in which the owner of a driving school in <BR />
Pennsylvania allegedly figured out a way to game the state's motor <BR />
vehicle exam scheduling system in order to get his students to the head <BR />
of the line.<BR />
<BR />
That's it.<BR />
<BR />
Maley didn't give explicit details on the problem and didn't even really <BR />
describe it as a security issue, according to news reports. He simply <BR />
cited it as an example of the issues he deals with every day. And as a <BR />
result he no longer has a job because, as Jaikumar Vijayan reports in <BR />
Computerworld, Pennsylvania has a policy requiring employees to get <BR />
explicit permission to discuss state business publicly.<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Thu Mar 11 2010 - 22:12:15 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Fri, 12 Mar 2010 00:12:15 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] State Web site breach tied to foreign attacker</title>
<link>http://lists.jammed.com/ISN/2010/03/0044.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20State%20Web%20site%20breach%20tied%20to%20foreign%20attacker">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Fri, 12 Mar 2010 00:14:22 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.desmoinesregister.com/article/20100311/NEWS10/3110351/-1/networking/State-Web-site-breach-tied-to-foreign-attacker">http://www.desmoinesregister.com/article/20100311/NEWS10/3110351/-1/networking/State-Web-site-breach-tied-to-foreign-attacker</a><BR />
<BR />
By William Petroski<BR />
The Des Moines Register<BR />
March 11, 2010 <BR />
<BR />
A hacking incident on an Iowa homeland security Web site last week has <BR />
been linked to a foreign attacker who gained access through a security <BR />
vulnerability, a state official said Wednesday.<BR />
<BR />
This hacker used an &quot;abstract, colorful&quot; image to deface the site <BR />
operated by the Iowa Division of Homeland Security and Emergency <BR />
Management, said Robert Bailey, communications director for the Iowa <BR />
Department of Administrative Services. Access was gained by exploiting <BR />
software that lacked a security patch, he said.<BR />
<BR />
The breach was limited to an Iowa Department of Public Defense server, <BR />
and no sensitive data were compromised, Bailey said. Investigators have <BR />
concluded the attack occurred from outside North America, but they <BR />
haven't identified a perpetrator, he added.<BR />
<BR />
A total of six state Web sites were shut down temporarily because of the <BR />
March 3 incident, including a Web site that advises the public about <BR />
family and individual preparedness for emergencies. Only a bare-bones <BR />
version of the homeland security Web site was back online as of <BR />
Wednesday. The breach did not compromise any computer systems of the <BR />
Iowa National Guard, said Maj. Michael Wunn, a Guard spokesman.<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Thu Mar 11 2010 - 22:14:22 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Fri, 12 Mar 2010 00:14:22 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] Pennsylvania's Web security officer leaves post a week after talking about PennDOT hacking incident</title>
<link>http://lists.jammed.com/ISN/2010/03/0040.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Pennsylvania's%20Web%20security%20officer%20leaves%20post%20a%20week%20after%20talking%20about%20PennDOT%20hacking%20incident">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Thu, 11 Mar 2010 00:21:44 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.pennlive.com/midstate/index.ssf/2010/03/pennsylvanias_web_security_off.html">http://www.pennlive.com/midstate/index.ssf/2010/03/pennsylvanias_web_security_off.html</a><BR />
<BR />
By JAN MURPHY<BR />
The Patriot-News<BR />
March 10, 2010<BR />
<BR />
Last week, Pennsylvania's chief information security officer Robert <BR />
Maley was at an information security conference in San Francisco talking <BR />
about a hacking incident involving PennDOT's computers. This week, Maley <BR />
is gone.<BR />
<BR />
Gary Tuma, Gov. Ed Rendell's press secretary, confirmed that Maley is no <BR />
longer employed by the state, but he declined to comment further, saying <BR />
it is a personnel matter.<BR />
<BR />
Attempts to contact Maley yesterday were unsuccessful.<BR />
<BR />
Danielle Klinger, a spokeswoman for the state Department of <BR />
Transportation, said the agency is not aware of any hacking or breach <BR />
that occurred involving scheduling system for its driving test. However, <BR />
she said that a few weeks ago, &quot;we did discover an anomaly and we have <BR />
actually turned that over to [the state police] for further <BR />
investigation. We're not sure what that anomaly is, but it is being <BR />
investigated. Unfortunately, I can't provide any more details on it.&quot;<BR />
<BR />
Maley is listed on LinkedIn, an online networking site, as having worked <BR />
as a former Swatara Twp. police sergeant before entering the information <BR />
security field more than 24 years ago. It states he worked in <BR />
information technology for the state in a variety of capacities as well <BR />
as in the private and nonprofit sectors.<BR />
<BR />
On the agenda for the RSA Conference at which Maley appeared as a <BR />
presenter last week, he was listed as a top-rated speaker and described <BR />
as &quot;one of the most high-profile experts in the field of securing the <BR />
data of American citizens today.&quot;<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Wed Mar 10 2010 - 22:21:44 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Thu, 11 Mar 2010 00:21:44 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] FDIC: Hackers took more than $120M in three months</title>
<link>http://lists.jammed.com/ISN/2010/03/0030.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20FDIC:%20Hackers%20took%20more%20than%20$120M%20in%20three%20months">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Tue, 9 Mar 2010 10:49:47 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.computerworld.com/s/article/9167598/FDIC_Hackers_took_more_than_120M_in_three_months?taxonomyId=17">http://www.computerworld.com/s/article/9167598/FDIC_Hackers_took_more_than_120M_in_three_months?taxonomyId=17</a><BR />
<BR />
By Robert McMillan<BR />
IDG News Service<BR />
March 8, 2010<BR />
<BR />
Ongoing computer scams targeting small businesses cost U.S. companies <BR />
$25 million in the third quarter of 2009, according to the U.S. Federal <BR />
Deposit Insurance Corporation.<BR />
<BR />
Online banking fraud involving the electronic transfer of funds has been <BR />
on the rise since 2007 and rose to over $120 million in the third <BR />
quarter of 2009, according to estimates presented Friday at the RSA <BR />
Conference in San Francisco, by David Nelson, an examination specialist <BR />
with the FDIC.<BR />
<BR />
The FDIC receives a variety of confidential reports from financial <BR />
institutions, which allow it to generate the estimates, Nelson said.<BR />
<BR />
Almost all of the incidents reported to the FDIC &quot;related to malware on <BR />
online banking customers' PCs,&quot; he said. Typically a victim is tricked <BR />
into visiting a malicious Web site or downloading a Trojan horse program <BR />
that gives hackers access to their banking passwords. Money is then <BR />
transferred out of the account using the Automated Clearing House (ACH) <BR />
system that banks use to process payments between institutions.<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Tue Mar 09 2010 - 08:49:47 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Tue, 9 Mar 2010 10:49:47 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] Backdoor found in Energizer Duo USB battery charger</title>
<link>http://lists.jammed.com/ISN/2010/03/0031.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Backdoor%20found%20in%20Energizer%20Duo%20USB%20battery%20charger">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Tue, 9 Mar 2010 10:49:58 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://news.cnet.com/8301-27080_3-10465429-245.html">http://news.cnet.com/8301-27080_3-10465429-245.html</a><BR />
<BR />
By Elinor Mills<BR />
InSecurity Complex<BR />
CNet News<BR />
March 8, 2010<BR />
<BR />
Software that can be downloaded for use with the Energizer Duo USB <BR />
battery charger contains a backdoor that could allow an attacker to <BR />
remotely take control of a Windows-based PC, Energizer and US-CERT is <BR />
warning.<BR />
<BR />
&quot;The installer for the Energizer Duo software places the file <BR />
UsbCharger.dll in the application's directory and Arucer.dll in the <BR />
Windows system32 directory,&quot; the U.S. Computer Emergency Readiness Team <BR />
said in an advisory on Friday. &quot;Arucer.dll is a backdoor that allows <BR />
unauthorized remote system access via accepting connections on 7777/tcp. <BR />
Its capabilities include the ability to list directories, send and <BR />
receive files, and execute programs.&quot;<BR />
<BR />
The Windows software was made available via a download with the <BR />
Energizer Duo Charger, Model CHUSB, Energizer said in a statement.<BR />
<BR />
The battery maker said it does not know how the Trojan got into the <BR />
software. &quot;Energizer has discontinued sale of this product and has <BR />
removed the site to download the software,&quot; the statement said. <BR />
&quot;Energizer is currently working with both CERT and U.S. government <BR />
officials to understand how the code was inserted in the software.&quot;<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Tue Mar 09 2010 - 08:49:58 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Tue, 9 Mar 2010 10:49:58 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] Cybersecurity program has serious defects, GAO says</title>
<link>http://lists.jammed.com/ISN/2010/03/0033.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Cybersecurity%20program%20has%20serious%20defects,%20GAO%20says">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Tue, 9 Mar 2010 10:50:22 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://gcn.com/articles/2010/03/08/cnci-assessment-030810.aspx">http://gcn.com/articles/2010/03/08/cnci-assessment-030810.aspx</a><BR />
<BR />
By William Jackson<BR />
GCN.com<BR />
March 08, 2010<BR />
<BR />
Implementing the Comprehensive National Cybersecurity Initiative, a <BR />
broad program intended to protect the nation.s cyber infrastructure, has <BR />
been hampered by a lack of coordination and transparency, according to <BR />
the Government Accountability Office.<BR />
<BR />
&quot;CNCI is unlikely to fully achieve its goal of reducing potential <BR />
vulnerabilities, protecting against intrusion attempts, and anticipating <BR />
future threats to federal information systems unless roles and <BR />
responsibilities for cybersecurity activities across the federal <BR />
government are more clearly defined and coordinated,&quot; the GAO concluded <BR />
in a November briefing to the staff of the House Armed Services <BR />
subcommittee on Terrorism, Unconventional Threats and Capabilities.<BR />
<BR />
The GAO also concluded that too much of the initiative, which was <BR />
spelled out in National Security Presidential Directive 54 and Homeland <BR />
Security Presidential Directive 23, has remained classified.<BR />
<BR />
&quot;Since the approval of NSPD-54/HSPD-23, few elements of CNCI have been <BR />
made public,&quot; the GAO briefing said. &quot;While certain aspects and details <BR />
of CNCI must necessarily remain classified, the lack of transparency <BR />
regarding CNCI projects hinders accountability to Congress and the <BR />
public. In addition, current classification may make it difficult for <BR />
some agencies, as well as the private sector, to interact and contribute <BR />
to the success of CNCI projects.&quot;<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Tue Mar 09 2010 - 08:50:22 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Tue, 9 Mar 2010 10:50:22 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] Change in Focus</title>
<link>http://lists.jammed.com/ISN/2010/03/0047.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Change%20in%20Focus">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Fri, 12 Mar 2010 00:15:20 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.securityfocus.com/news/11582">http://www.securityfocus.com/news/11582</a><BR />
<BR />
By SecurityFocus Staff<BR />
SecurityFocus <BR />
2010-03-10<BR />
<BR />
Since its inception in 1999, SecurityFocus has been a mainstay in the <BR />
security community. From original news content to detailed technical <BR />
papers and guest columnists, we've strived to be the community's source <BR />
for all things security related. SecurityFocus was formed with the idea <BR />
that the community needed a place to come together and share its <BR />
collected wisdom and knowledge.<BR />
<BR />
At the time, the security community was fairly fragmented with <BR />
mainstream security information in its infancy. If you worked in <BR />
security, it was difficult and frustrating to find the information you <BR />
were looking for because it was scattered across a small number of <BR />
mailing lists, sites and publications. There was no single place where a <BR />
community of security professionals could go to get the information they <BR />
needed and there was a unique opportunity to build a community portal <BR />
that would provide its users with a destination and voice.<BR />
<BR />
At SecurityFocus, the community has always been our primary focus. We <BR />
knew then as we know now that providing the community with a place to <BR />
share information, discuss new ideas and share technologies was critical <BR />
to staying in touch with the constantly evolving threat landscape. With <BR />
its purchase of SecurityFocus in 2002, Symantec became one of the first <BR />
vendors to recognize the importance of maintaining a close relationship <BR />
with the security community to the point where they made a commitment to <BR />
its founders to continue to operate SecurityFocus as an independent <BR />
company with the same mandate -- &quot;It's all here - and it's all free.&quot;<BR />
<BR />
The threat landscape has changed significantly over the past 10 years <BR />
and so has the community. What was once a dispersed though vocal <BR />
collection of users, researchers and analysts has become a much larger <BR />
and more cohesive community of experts who have endeavored to make <BR />
security more than just an after-thought. Vendors have also changed <BR />
significantly, to the point where entire divisions are devoted to <BR />
security research and education. Today, more information is shared <BR />
openly within the community than ever before through the use of blogs, <BR />
threat analysis, and whitepapers as vendors increasingly work with the <BR />
community to solve today's security challenges. The enormous growth in <BR />
dedicated portals and alternative news sources such as social networking <BR />
sites allows us to get our security news and information from a variety <BR />
of sources and as a result, it makes sense for SecurityFocus to evaluate <BR />
how best to serve its readers.<BR />
<BR />
With this in mind, the time is right for SecurityFocus to focus more on <BR />
its core components. Beginning March 15, 2010 SecurityFocus will begin a <BR />
transition of its content to Symantec Connect. As part of its continued <BR />
commitment to the community, all of SecurityFocus. mailing lists <BR />
including Bugtraq and its Vulnerability Database will remain online at <BR />
www.securityfocus.com There will not be any changes to any of the list <BR />
charters or policies and the same teams who have moderated list traffic <BR />
will continue to do so. The vulnerability database will continue to be <BR />
updated and made available as it is currently. DeepSight and other <BR />
security intelligence related offerings will remain unchanged while <BR />
Infocus articles, whitepapers, and other SecurityFocus content will be <BR />
available off of the main Symantec website in the coming months.<BR />
<BR />
While the news portal section of SecurityFocus will no longer be <BR />
offered, we think our readers will be better served by this change as we <BR />
combine our efforts with Symantec Connect and continue to provide a <BR />
valuable service to the community. As always, if you have any questions <BR />
or concerns you can reach us at editor-at-securityfocus-dot-com.<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Thu Mar 11 2010 - 22:15:20 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Fri, 12 Mar 2010 00:15:20 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] Zeus botnets suffer mighty blow after ISP taken offline</title>
<link>http://lists.jammed.com/ISN/2010/03/0037.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Zeus%20botnets%20suffer%20mighty%20blow%20after%20ISP%20taken%20offline">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Thu, 11 Mar 2010 00:21:08 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.theregister.co.uk/2010/03/10/massive_zeus_takedown/">http://www.theregister.co.uk/2010/03/10/massive_zeus_takedown/</a><BR />
<BR />
By Dan Goodin in San Francisco<BR />
The Register<BR />
10th March 2010<BR />
<BR />
At least a quarter of the command and control servers linked to <BR />
Zeus-related botnets have suddenly gone quiet, continuing a recent trend <BR />
of takedowns hitting some of the world's most nefarious cyber <BR />
operations.<BR />
<BR />
The massive drop is the result of actions taken by two Eastern European <BR />
network providers. On Tuesday, they pulled the plug on their downstream <BR />
customers, including an ISP known a Troyak, according to Mary Landesman, <BR />
a senior researcher with ScanSafe, a web security firm recently acquired <BR />
by Cisco Systems. That in turn severed the connections of servers used <BR />
to control large numbers of computers infected by a do-it-yourself crime <BR />
kit known as Zeus.<BR />
<BR />
Landesman said she was able to confirm figures provided by Zeus Tracker <BR />
that found the number of active control servers related to Zeus had <BR />
dropped from 249 to 181. The takedown came on Tuesday around 10:22 am <BR />
GMT and was heralded by a sudden drop off in the number of malware <BR />
attacks ScanSafe blocks from affected IP addresses.<BR />
<BR />
The takedown is the result of two network service providers, <BR />
Ukraine-based Ihome and Russia-based Oversun Mercury, severing their <BR />
ties with Troyak, said Landesman, who cited data returned by <BR />
Robotex.com. The move meant that all the ISP's customers, law-abiding or <BR />
otherwise, were immediately unable to connect to the outside world.<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Wed Mar 10 2010 - 22:21:08 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Thu, 11 Mar 2010 00:21:08 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] Final CFP: TrustBus'10&ndash;&ndash; Deadline Extended</title>
<link>http://lists.jammed.com/ISN/2010/03/0045.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Final%20CFP:%20TrustBus'10--%20Deadline%20Extended">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Fri, 12 Mar 2010 00:14:44 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a>Forwarded from: &quot;M. Carmen Fernández Gago&quot; &lt;mcgago&#64; (at) cc&#46;<!--nospam-->uma.es&gt;<BR />
<BR />
** Apologies for multiple copies **<BR />
<BR />
*Final Call for Papers*<BR />
<BR />
7th International Conference on<BR />
<BR />
*TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS (TrustBus'10)<BR />
*<BR />
Bilbao, Spain<BR />
<BR />
30 August -- 3 September 2010<BR />
<BR />
<BR />
<BR />
<a href="http://www.isac.uma.es/trustbus10">http://www.isac.uma.es/trustbus10</a><BR />
<BR />
<BR />
<BR />
/in conjunction with the 21st International Conference on Databse and <BR />
Expert Systems Applications (DEXA 2010)/<BR />
<BR />
<BR />
<BR />
The advances in the Information and Communication Technologies (ICT) <BR />
have raised new opportunities for the implementation of novel <BR />
applications and the provision of high quality services over global <BR />
networks. The aim is to utilize this 'information society era' for <BR />
improving the quality of life for all citizens, disseminating knowledge, <BR />
strengthening social cohesion, generating earnings and finally ensuring <BR />
that organizations and public bodies remain competitive in the global <BR />
electronic marketplace.<BR />
<BR />
Unfortunately, such a rapid technological evolution cannot be problem <BR />
free. Concerns are raised regarding the 'lack of trust' in electronic <BR />
procedures and the extent to which 'information security' and 'user <BR />
privacy' can be ensured.<BR />
<BR />
In answer to these concerns, the 7th International Conference on Trust, <BR />
Privacy and Security in Digital Business (TrustBus'10) will provide an <BR />
international forum for researchers and practitioners to exchange <BR />
information regarding advancements in the state of the art and practice <BR />
of trust and privacy in digital business.<BR />
<BR />
TrustBus'10 will bring together researchers from different disciplines, <BR />
developers, and users all interested in the critical success factors of <BR />
digital business systems. We are interested in papers, work-in-progress <BR />
reports, and industrial experiences describing advances in all areas of <BR />
digital business applications related to trust and privacy.<BR />
<BR />
*<BR />
Topics*<BR />
<BR />
- Anonymity and pseudonymity in business transactions<BR />
<BR />
- Business architectures and underlying infrastructures<BR />
<BR />
- Common practice, legal and regulatory issues<BR />
<BR />
- Cryptographic protocols<BR />
<BR />
- Delivery technologies and scheduling protocols<BR />
<BR />
- Design of businesses models with security requirements<BR />
<BR />
- Economics of Information Systems Security<BR />
<BR />
- Electronic cash, wallets and pay-per-view systems<BR />
<BR />
- Enterprise management and consumer protection<BR />
<BR />
- Identity and Trust Management<BR />
<BR />
- Intellectual property and digital rights management<BR />
<BR />
- Intrusion detection and information filtering<BR />
<BR />
- Languages for description of services and contracts<BR />
<BR />
- Management of privacy &amp; confidentiality<BR />
<BR />
- Models for access control and authentication<BR />
<BR />
- Multimedia web services<BR />
<BR />
- New cryptographic building-blocks for e-business applications<BR />
<BR />
- Online transaction processing<BR />
<BR />
- PKI &amp; PMI<BR />
<BR />
- Public administration, governmental services<BR />
<BR />
- P2P transactions and scenarios<BR />
<BR />
- Real-time Internet E-Services<BR />
<BR />
- Reliability and security of content and data<BR />
<BR />
- Reliable auction, e-procurement and negotiation technology<BR />
<BR />
- Reputation in services provision<BR />
<BR />
- Secure process integration and management<BR />
<BR />
- Security and Privacy models for Pervasive Information Systems<BR />
<BR />
- Security Policies<BR />
<BR />
- Shopping, trading, and contract management tools<BR />
<BR />
- Smartcard technology<BR />
<BR />
- Transactional Models<BR />
<BR />
- Trust and privacy issues in social networks environments<BR />
<BR />
- Usability of security technologies and services<BR />
<BR />
<BR />
*Instructions for paper submission*<BR />
<BR />
Authors are invited to submit original papers not previously published <BR />
nor submitted in parallel for publication to any other conference, <BR />
workshop or journal. Papers should be limited to 12 pages of 11pt type <BR />
including title page, figures and bibliography.<BR />
<BR />
Accepted papers will be included in the Conference proceedings, to be <BR />
published by Springer in their LNCS series. Camera-ready versions of the <BR />
papers should not exceed 12 pages and must comply with the &quot;Authors <BR />
Instructions&quot; that can be found at: <BR />
<a href="http://www.springer.de/comp/lncs/authors.html">http://www.springer.de/comp/lncs/authors.html</a><BR />
<BR />
*Important dates*<BR />
<BR />
Submission deadline:       March 12th, 2010, *extended deadline March 26th*<BR />
<BR />
Notification to authors:   April 30th, 2010<BR />
<BR />
Camera-ready version:      May 24th, 2010<BR />
<BR />
<BR />
*Program Committee co-Chairs*<BR />
<BR />
Katsikas, Sokratis                   University of Pireaus (Greece)<BR />
<BR />
Lopez, Javier                        University of Malaga (Spain)<BR />
<BR />
*<BR />
General Chair*<BR />
<BR />
Soriano, Miguel                      UPC (Spain)<BR />
<BR />
<BR />
*Publication Chair*<BR />
<BR />
Fernandez-Gago, Carmen               University of Malaga (Spain)<BR />
<BR />
*<BR />
Publicity Chair*<BR />
<BR />
Agudo, Isaac                         University of Malaga (Spain)<BR />
<BR />
<BR />
*Program Committee Members*<BR />
<BR />
Acquisti, Alessandro    Carnegie Mellon University (US)<BR />
<BR />
Alcaraz, Cristina       University of Malaga (Spain)<BR />
<BR />
Atluri, Vijay           Rutgers University (US)<BR />
<BR />
Casassa Mont, Marco     HP Labs Bristol (UK)<BR />
<BR />
Chadwick, David         University of Kent (UK)<BR />
<BR />
Clarke, Nathan          University of Plymouth (UK)<BR />
<BR />
Cuppens, Frederic       ENST Bretagne (France)<BR />
<BR />
Damiani, Ernesto        Universit degli Studi di Milano (Italy)<BR />
<BR />
De Capitani di<BR />
<BR />
Vimercati, Sabrina      University of Milan (Italy)<BR />
<BR />
Domingo-Ferrer, Josep   University Rovira i Virgili (Spain)<BR />
<BR />
Fernandez, Eduardo      University of Castilla la Mancha (Spain)<BR />
<BR />
Fernandez, Eduardo B.   Florida Atlantic University (USA)<BR />
<BR />
Ferrer, Josep L.        University Islas Baleares (Spain)<BR />
<BR />
Fischer-Huebner, Simone Karlstad University (Sweden)<BR />
<BR />
Foresti, Sara           University of Milan (Italy)<BR />
<BR />
Forne, Jordi            UPC (Spain)<BR />
<BR />
Furnell, Steven         University of Plymouth (UK)<BR />
<BR />
Fuss, Juergen           University of Applied Science in Hagenberg (Austria)<BR />
<BR />
Gonzalez-Nieto, Juan M. Queensland Univ. of Technology (Australia)<BR />
<BR />
Gritzalis, Dimitris     Athens Univ. of Economics and Business (Greece)<BR />
<BR />
Gritzalis, Stefanos     University of the Aegean (Greece)<BR />
<BR />
Hansen, Marit           Independent Center for Privacy Protection (Germany)<BR />
<BR />
Herrera, Jordi          UAB (Spain)<BR />
<BR />
Jsang, Audun           Oslo University (Norway)<BR />
<BR />
Karabulut, Yuecel       SAP Labs (US)<BR />
<BR />
Kesdogan, Dogan         University of Siegen (Germany)<BR />
<BR />
Kokolakis, Spyros       University of the Aegean (Greece)<BR />
<BR />
Lioy, Antonio           Politecnico di Torino (Italy)<BR />
<BR />
Markowitch, Olivier     Universite Libre de Bruxelles (Belgium)<BR />
<BR />
Marsh, Stephen          Communications Research Centre (Canada)<BR />
<BR />
Martinelli, Fabio       CNR (Italy)<BR />
<BR />
Matyas, Vashek          Masaryk University (Czech Rep.)<BR />
<BR />
Mitchell, Chris         Royal Holloway, University of London (UK)<BR />
<BR />
Mouratidis, Haris       University of East London (UK)<BR />
<BR />
Murayama, Yuko          Iwate Prefectural University (Japan)<BR />
<BR />
Najera, Pablo           University of Malaga (Spain)<BR />
<BR />
Okamoto, Eiji           University of Tsubuka (Japan)<BR />
<BR />
Olivier, Martin S.      University of Pretoria (South Africa)<BR />
<BR />
Oppliger, Rolf          eSecurity Technologies (Switzerland)<BR />
<BR />
Papadaki, Maria         University of Plymouth (UK)<BR />
<BR />
Patel, Ahmed            Kingston University (UK) - University Kebangsaan (Malaysia)<BR />
<BR />
Pernul, Guenther        University of Regensburg (Germany)<BR />
<BR />
Pfitzmann, Andreas      Dresden University of Technology (Germany)<BR />
<BR />
Piattini, Mario         University Castilla-La Mancha (Spain)<BR />
<BR />
Pohl, Hartmut           FH Bonn-Rhein-Sieg (Germany)<BR />
<BR />
Posegga, Joachim        University of Passau (Germany)<BR />
<BR />
Rannenberg, Kai         Goethe University Frankfurt (Germany)<BR />
<BR />
Ribagorda, Arturo       University Carlos III Madrid (Spain)<BR />
<BR />
Rudolph, Carsten        Fraunhofer Institute for Secure Information Technology (Germany)<BR />
<BR />
Ruland, Christoph       University of Siegen (Germany)<BR />
<BR />
Samarati, Pierangela    University of Milan (Italy)<BR />
<BR />
Schaumueller-Bichl,<BR />
<BR />
Ingrid                  University of Applied Science in Hagenberg (Austria)<BR />
<BR />
Schunter, Matthias      IBM Zurich Research Lab (Switzerland)<BR />
<BR />
Skarmeta, Antonio F.    University of Murcia (Spain)<BR />
<BR />
Teufel, Stephanie       University of Fribourg (Switzerland)<BR />
<BR />
Tjoa, A Min             Technical University of Vienna (Austria)<BR />
<BR />
Tomlinson, Allan        Royal Holloway, University of London (UK)<BR />
<BR />
Weipl, Edgar            SBA (Austria)<BR />
<BR />
Xenakis, Christos       University of Piraeus (Greece)<BR />
<BR />
Zhou, Jianying          I2R (Singapore)<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Thu Mar 11 2010 - 22:14:44 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Fri, 12 Mar 2010 00:14:44 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] Thailand approves extradition of credit card hack suspect</title>
<link>http://lists.jammed.com/ISN/2010/03/0035.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Thailand%20approves%20extradition%20of%20credit%20card%20hack%20suspect">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Tue, 9 Mar 2010 10:50:45 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.theregister.co.uk/2010/03/08/thailand_extradites_hacking_suspect/">http://www.theregister.co.uk/2010/03/08/thailand_extradites_hacking_suspect/</a><BR />
<BR />
By Dan Goodin in San Francisco <BR />
The Register<BR />
8th March 2010 <BR />
<BR />
A criminal court in Thailand has approved the extradition to the US of a <BR />
Malaysian man suspected of participating in credit card thefts of more <BR />
than $152m, according to a local news report.<BR />
<BR />
Gooi Kokseng, 44, was arrested on January 30 after being accused of <BR />
causing more than 5 billion baht, or $152.9m, in damage by accessing <BR />
credit card information in the US and Southeast Asia, according to The <BR />
Bangkok Post. He was charged with violating computer crime and credit <BR />
card business laws.<BR />
<BR />
The order was approved at the request of the foreign affairs section of <BR />
the Office of the Attorney General, which sought extradition under a <BR />
treaty signed between the Thailand and the US. Kokseng will be remanded <BR />
in Thailand for 30 days before being transferred to the US.<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Tue Mar 09 2010 - 08:50:45 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Tue, 9 Mar 2010 10:50:45 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] The FBI supply chain illustrated</title>
<link>http://lists.jammed.com/ISN/2010/03/0039.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20The%20FBI%20supply%20chain%20illustrated">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Thu, 11 Mar 2010 00:21:31 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://blogs.csoonline.com/the_fbi_supply_chain_illustrated">http://blogs.csoonline.com/the_fbi_supply_chain_illustrated</a><BR />
<BR />
By Robert McMillan<BR />
Security Blanket<BR />
2010-03-09<BR />
<BR />
While FBI Director Robert Mueller was talking about possible threats to <BR />
the U.S. supply chain at the RSA Conference last week, staffers at the <BR />
first-ever FBI RSA booth were getting ribbed about the pens they were <BR />
giving out.<BR />
<BR />
<a href="http://blogs.csoonline.com/sites/blogs.csoonline.com/files/pensm.jpg">http://blogs.csoonline.com/sites/blogs.csoonline.com/files/pensm.jpg</a><BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Wed Mar 10 2010 - 22:21:31 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Thu, 11 Mar 2010 00:21:31 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] Secunia Weekly Summary - Issue: 2010-10</title>
<link>http://lists.jammed.com/ISN/2010/03/0042.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Secunia%20Weekly%20Summary%20-%20Issue:%202010-10">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Fri, 12 Mar 2010 00:12:54 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a>========================================================================<BR />
<BR />
                  The Secunia Weekly Advisory Summary                  <BR />
                        2010-03-04 - 2010-03-11                        <BR />
<BR />
                       This week: 63 advisories                        <BR />
<BR />
========================================================================<BR />
Table of Contents:<BR />
<BR />
1.....................................................Word From Secunia<BR />
2....................................................This Week In Brief<BR />
3...............................This Weeks Top Ten Most Read Advisories<BR />
4..................................................This Week in Numbers<BR />
<BR />
========================================================================<BR />
1) Word From Secunia:<BR />
<BR />
Patching redefined - Free &amp; Automatic Updating for every single PC user<BR />
<BR />
Unpatched programs are a primary source of IT insecurity. But due to<BR />
the complex and immeasurable scope of patching, it is neglected by the<BR />
majority of private users. Not a viable approach to ensure online<BR />
safety - Secunia has set out aggressively to change this!<BR />
<BR />
Read more:<BR />
<a href="http://secunia.com/blog/80/">http://secunia.com/blog/80/</a><BR />
<BR />
 --<BR />
<BR />
Use WSUS to deploy 3rd party patches<BR />
<BR />
Public BETA<BR />
<a href="http://secunia.com/vulnerability_scanning/corporate/wsus_3rd_third_party_patching/">http://secunia.com/vulnerability_scanning/corporate/wsus_3rd_third_party_patching/</a><BR />
<BR />
========================================================================<BR />
2) This Week in Brief:<BR />
<BR />
A vulnerability has been reported in Internet Explorer, which can be<BR />
exploited by malicious people to compromise a user's system.<BR />
<BR />
NOTE: The vulnerability is currently being actively exploited.<BR />
<BR />
For more information:<BR />
<a href="http://secunia.com/advisories/38860/">http://secunia.com/advisories/38860/</a><BR />
<BR />
 --<BR />
<BR />
A vulnerability has been reported in Microsoft Windows, which can be<BR />
exploited by malicious people to compromise a user's system.<BR />
<BR />
For more information:<BR />
<a href="http://secunia.com/advisories/38791/">http://secunia.com/advisories/38791/</a><BR />
<BR />
 --<BR />
<BR />
Multiple vulnerabilities have been reported in Microsoft Office Excel,<BR />
which can be exploited by malicious people to compromise a user's<BR />
system.<BR />
<BR />
For more information:<BR />
<a href="http://secunia.com/advisories/38805/">http://secunia.com/advisories/38805/</a><BR />
<BR />
 --<BR />
<BR />
Paul Craig has reported a vulnerability in Skype, which can be<BR />
exploited by malicious people to bypass certain security restrictions<BR />
and potentially disclose certain sensitive information.<BR />
<BR />
For more information:<BR />
<a href="http://secunia.com/advisories/38908/">http://secunia.com/advisories/38908/</a><BR />
<BR />
========================================================================<BR />
3) This Weeks Top Ten Most Read Advisories:<BR />
<BR />
For more information on how to receive alerts on these vulnerabilities,<BR />
subscribe to the Secunia business solutions:<BR />
<a href="http://secunia.com/advisories/business_solutions/">http://secunia.com/advisories/business_solutions/</a><BR />
<BR />
1.  [SA38416] Microsoft Internet Explorer Local File Disclosure<BR />
              Vulnerabilities<BR />
2.  [SA37584] Adobe Flash Player Multiple Vulnerabilities<BR />
3.  [SA37231] Sun Java JDK / JRE Multiple Vulnerabilities<BR />
4.  [SA38511] Microsoft DirectShow AVI File Parsing Buffer Overflow<BR />
              Vulnerability<BR />
5.  [SA37690] Adobe Reader/Acrobat Multiple Vulnerabilities<BR />
6.  [SA37769] Google Chrome Multiple Vulnerabilities<BR />
7.  [SA38209] Microsoft Internet Explorer Multiple Vulnerabilities<BR />
8.  [SA38061] Google Chrome Stylesheet Redirection Information<BR />
              Disclosure<BR />
9.  [SA38265] Microsoft Windows Two Privilege Escalation<BR />
              Vulnerabilities<BR />
10. [SA38506] Microsoft Windows TCP/IP Implementation Vulnerabilities<BR />
<BR />
========================================================================<BR />
4) This Week in Numbers<BR />
<BR />
During the past week 63 Secunia Advisories have been released. All<BR />
Secunia customers have received immediate notification on the alerts<BR />
that affect their business.<BR />
<BR />
This weeks Secunia Advisories had the following spread across platforms<BR />
and criticality ratings:<BR />
<BR />
Platforms:<BR />
  Windows             :     17 Secunia Advisories<BR />
  Unix/Linux          :     24 Secunia Advisories<BR />
  Other               :      1 Secunia Advisory  <BR />
  Cross platform      :     21 Secunia Advisories<BR />
<BR />
Criticality Ratings:<BR />
  Extremely Critical  :      1 Secunia Advisory  <BR />
  Highly Critical     :     10 Secunia Advisories<BR />
  Moderately Critical :     22 Secunia Advisories<BR />
  Less Critical       :     27 Secunia Advisories<BR />
  Not Critical        :      3 Secunia Advisories<BR />
<BR />
========================================================================<BR />
<BR />
Secunia recommends that you verify all advisories you receive,<BR />
by clicking the link.<BR />
Secunia NEVER sends attached files with advisories.<BR />
Secunia does not advise people to install third party patches, only use<BR />
those supplied by the vendor.<BR />
<BR />
Definitions: (Criticality, Where etc.)<BR />
<a href="http://secunia.com/advisories/about_secunia_advisories/">http://secunia.com/advisories/about_secunia_advisories/</a><BR />
<BR />
Subscribe:<BR />
<a href="http://secunia.com/advisories/weekly_summary/">http://secunia.com/advisories/weekly_summary/</a><BR />
<BR />
Contact details:<BR />
Web	: <a href="http://secunia.com/">http://secunia.com/</a><BR />
E-mail	: support_at_private<BR />
Tel	: +45 70 20 51 44<BR />
Fax	: +45 70 20 51 45<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Thu Mar 11 2010 - 22:12:54 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Fri, 12 Mar 2010 00:12:54 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] TJX Hacking Conspirator Gets 4 Years</title>
<link>http://lists.jammed.com/ISN/2010/03/0046.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20TJX%20Hacking%20Conspirator%20Gets%204%20Years">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Fri, 12 Mar 2010 00:15:03 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.wired.com/threatlevel/2010/03/tjx-conspirator-sentenced-to-46-month/">http://www.wired.com/threatlevel/2010/03/tjx-conspirator-sentenced-to-46-month/</a><BR />
<BR />
By Kim Zetter  <BR />
Threat Level<BR />
Wired.com<BR />
March 11, 2010<BR />
<BR />
Humza Zaman, a co-conspirator in the hack of TJX and other companies, <BR />
was sentenced Thursday in Boston to 46 months in prison and fined <BR />
$75,000 for his role in the conspiracy. The sentence matches what <BR />
prosecutors were seeking.<BR />
<BR />
Zaman, a 33-year-old former programmer at Barclays Bank, was charged <BR />
with laundering between $600,000 and $800,000 for hacker Albert <BR />
Gonzalez, who is currently awaiting sentencing on charges that he and <BR />
others hacked into TJX, Office Max, Heartland Payment Systems and <BR />
numerous other companies to steal data on more than 100 million credit <BR />
and debit card accounts.<BR />
<BR />
Zaman pleaded guilty in April to one count of conspiracy. His sentence <BR />
includes three years of supervised release with the condition that Zaman <BR />
must disclose his conviction to any future employer. Upon release, Zaman <BR />
will not be barred from using computers.<BR />
<BR />
Zaman is the second conspirator in the TJX case to be charged. Former <BR />
Morgan Stanley coder, Stephen Watt, was sentenced in December to two <BR />
years in prison for his role in the TJX case, which involved supplying <BR />
Gonzalez with a sniffer program used to siphon card data from the TJX <BR />
network.<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Thu Mar 11 2010 - 22:15:03 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Fri, 12 Mar 2010 00:15:03 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] Colorado Springs man allegedly sabotaged TSA computers</title>
<link>http://lists.jammed.com/ISN/2010/03/0038.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20Colorado%20Springs%20man%20allegedly%20sabotaged%20TSA%20computers">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Thu, 11 Mar 2010 00:21:20 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.denverpost.com/ci_14648083">http://www.denverpost.com/ci_14648083</a><BR />
<BR />
By Howard Pankratz<BR />
The Denver Post<BR />
03/10/2010<BR />
<BR />
A former employee of the Transportation Security Administration has been <BR />
indicted by the Denver federal grand jury for attempting to sabotage TSA <BR />
computers that enable TSA airport personnel to spot potential terrorists <BR />
before they board airliners.<BR />
<BR />
Douglas James Duchak, 46, of Colorado Springs, worked for the TSA from <BR />
August 2004 through October 2009.<BR />
<BR />
According to the indictment, Duchak sent a code or virus into computers <BR />
at the TSA's Colorado Springs Operations Center in the attempt to <BR />
disable the TSA computer system, which receives information from the <BR />
government's Terrorist Screening Database and the U.S. Marshal's Service <BR />
Warrant Information Network.<BR />
<BR />
The indictment said that the TSA computer system is critical in &quot;vetting <BR />
of individuals&quot; who are attempting to gain access to &quot;secure areas of <BR />
the nation's transportation system.&quot;<BR />
<BR />
The indictment said that Duchak's duties included updating the databases <BR />
with new information.<BR />
<BR />
He allegedly inserted a virus programmed to spread on a specific date to <BR />
destroy the computer system.<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Wed Mar 10 2010 - 22:21:20 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Thu, 11 Mar 2010 00:21:20 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] ZeuS botnet code keeps getting better... for criminals</title>
<link>http://lists.jammed.com/ISN/2010/03/0043.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20ZeuS%20botnet%20code%20keeps%20getting%20better...%20for%20criminals">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Fri, 12 Mar 2010 00:13:22 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.networkworld.com/news/2010/031110-zeus-botnet.html">http://www.networkworld.com/news/2010/031110-zeus-botnet.html</a><BR />
<BR />
By Ellen Messmer<BR />
Network World<BR />
March 11, 2010 <BR />
<BR />
New capabilities are strengthening the ZeuS botnet, which criminals use <BR />
to steal financial credentials and execute unauthorized transactions in <BR />
online banking, automated clearing house (ACH) networks and payroll <BR />
systems. The latest version of this cybercrime toolkit, which starts at <BR />
about $3,000, offers a $10,000 module that can let attackers completely <BR />
take control of a compromised PC.<BR />
<BR />
Zeus v.1.3.4.x (code changes are always underway by the author and <BR />
owner, who is believed to be one individual in Eastern Europe) has <BR />
integrated a powerful remote-control function into the botnet so that <BR />
the attacker can now &quot;take complete control of the person's PC,&quot; says <BR />
Don Jackson, director of threat intelligence at SecureWorks, which <BR />
released an in-depth report on ZeuS this week.<BR />
<BR />
This new ZeuS feature, which was picked up from an older public-domain <BR />
project from AT&amp;T Bell Labs known as &quot;Virtual Network Computing,&quot; gives <BR />
ZeuS the kind of remote-control capability that might be found in a <BR />
legitimate product like GoToMyPC, Jackson says. SecureWorks calls this a <BR />
&quot;total presence proxy,&quot; and it's so useful to criminals, just this one <BR />
VNC module for ZeuS costs $10,000.<BR />
<BR />
The Windows-based ZeuS Trojan software, which takes up about 50,000 <BR />
bytes on a compromised Windows-based computer, is designed to plunder <BR />
accounts in North American and United Kingdom banking systems via the <BR />
victim's computer. The criminal might be located a continent away, <BR />
directing unauthorized transfers of funds to accounts through elaborate <BR />
command-and-control systems.<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Thu Mar 11 2010 - 22:13:22 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Fri, 12 Mar 2010 00:13:22 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
<item>
<title>[ISN] RSA: Cybersecurity A Joint Fed, Industry Effort</title>
<link>http://lists.jammed.com/ISN/2010/03/0034.html</link>
<description><![CDATA[<div class="mail"><BR />
<address class="headers"><BR />
<span id="from"><BR />
<dfn>From</dfn>: InfoSec News &lt;<a href="mailto:alerts_at_private?Subject=Re:%20[ISN]%20RSA:%20Cybersecurity%20A%20Joint%20Fed,%20Industry%20Effort">alerts_at_private</a>&gt;<BR />
</span><br /><BR />
<span id="date"><dfn>Date</dfn>: Tue, 9 Mar 2010 10:50:33 -0600 (CST)</span><br /><BR />
</address><BR />
<pre id="body"><BR />
<a name="start" accesskey="j" id="start"></a><a href="http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=223200125">http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=223200125</a><BR />
<BR />
By J. Nicholas Hoover<BR />
InformationWeek<BR />
March 8, 2010<BR />
<BR />
Government officials played a starring role at the annual RSA Conference <BR />
last week, laying out their plans for government cybersecurity, <BR />
particularly the need for increased cooperation with industry, in <BR />
keynotes and panel sessions throughout the week.<BR />
<BR />
White House cybersecurity coordinator Howard Schmidt set the tone in his <BR />
Tuesday keynote address, focusing heavily on increasing partnerships and <BR />
transparency when it comes to the federal government's role in <BR />
cybersecurity.<BR />
<BR />
In his remarks, Schmidt announced that the White House is declassifying <BR />
part of its 12-part cybersecurity strategy, the Comprehensive National <BR />
Cybersecurity Initiative, making note of its calls for increased <BR />
co-operation between government and industry.<BR />
<BR />
Schmidt dedicated most of his talk to giving an update on the progress <BR />
of near-term action items the Cyber Policy Review completed last year. <BR />
Schmidt noted the development of new Federal Information Security <BR />
Management Act metrics, the development of formal cybersecurity <BR />
education and awareness programs, and other ongoing efforts.<BR />
<BR />
[...]<BR />
<BR />
<BR />
___________________________________________________________<BR />
Register now for HITBSecConf2010 - Dubai, the premier <BR />
deep-knowledge network security event in the GCC, <BR />
featuring keynote speakers John Viega and Matt Watchinski! <BR />
<a href="http://conference.hitb.org/hitbsecconf2010dxb/">http://conference.hitb.org/hitbsecconf2010dxb/</a><BR />
<BR />
<span id="received"><dfn>Received on</dfn> Tue Mar 09 2010 - 08:50:33 PST</span><BR />
</div><BR />
<!-- body="end" --><BR />
]]></description>
<pubDate>Tue, 9 Mar 2010 10:50:33 -0600 (CST)</pubDate>
<author>InfoSec News</author>
</item>
</channel></rss>
