Friday, February 20, 2009

Friday 02/20/09

Permanent fix needed for DNS security issues, Kaminsky warns at Black Hat Dan Kaminsky, the security researcher who discovered a major flaw in the DNS protocol last year, said this week that broad adoption of DNS Security Extensions technology may be needed to protect systems, despite its complexity. Read more...

----------

Hackers exploit unpatched Adobe Reader bug
Hackers have been exploiting a critical bug in Adobe Reader, the popular PDF-viewing software, for at least nine days, researchers said Friday, but a patch may not be ready for another three weeks.

"We reported this to Adobe on Feb. 12," said Kevin Haley, a director in Symantec Corp.'s security response group. "That was the same day that we had a sample of the exploit."

Attacks have been spotted in Asia, primarily in Japan, said Haley, as well as in a few other countries. But their small number led him to characterize them as "targeted," meaning the victims had been specially selected.

----------

Conficker worm gets an evil twin
The criminals behind the widespread Conficker worm have released a new version of the malware that could signal a major shift in the way the worm operates.

----------

DHS names privacy chief
... "Homeland security and privacy are not mutually exclusive, and having a seasoned professional like Mary Ellen on the team further ensures that privacy is built into everything we do," said DHS Secretary Janet Napolitano in a statement. (See also: "Why your company needs a chief privacy officer")

----------

Laptop face-recognition tech easy to hack, warns Black Hat researcher
...
Nguyen Minh Duc, a researcher at Bach Khoa Internetwork Security Centre, a Hanoi-based security firm that is commonly known as Bkis, showed how attackers could break into laptops from Lenovo, Toshiba and Asus featuring face-recognition technologies, simply by using digitized images of the actual user of the systems in each case. The attacks were conducted on a Lenovo system with its Veriface III technology, an Asus system featuring its Smart Logon software and a laptop using Toshiba's Face Recognition technology.

----------

VeriSign: Internet Domain Names Grow To 177 Million In 2008

----------

Security Challenges of Electronic Medical Records
President Obama has made the widespread deployment of Electronic Medical Records (EMRs) a priority in his latest stimulus plan. Feisal Nanji, Executive Director at Techumen, gives an overview of the security challenges involved.
Read more

----------

Symbian-based mobile worm circulating in the wild
Dancho Danchev: F-Secure and Fortinet are investigating a newly discovered mobile malware identified as SymbOS/Yxes.A!worm or "Sexy View."

----------

No comments: