Latest security news.
Study: Businesses don’t understand Web application security threats, 03/20/07
Businesses may unwittingly leave themselves open to application-layer attacks because they don’t understand their networks lack defenses to deflect them, according to a study by Forrester Research.
How to make a honeypot network security system pay off, 03/21/07
Honeypots have largely been relegated to use by academia and antivirus vendors because most enterprise IT teams figure they’re too expensive to run and could land their companies in legal trouble. But honeypots aren’t as scary as all that, according to an expert on the topic who spoke at the InfoSec World Conference & Expo in Orlando Tuesday.
Liberty Alliance releases client specifications for identity, 03/21/07
The Liberty Alliance, a consortium of users and vendors developing identity standards, Wednesday released a set of specifications that define new ways for clients to present identity information.
Gozi Trojan leads to Russian data hoard, 03/20/07
A Russian Trojan program named Gozi that remained largely undetected for more than 50 days earlier this year has stolen more than 10,000 records containing confidential information belonging to about 5,200 home users.
Sunbelt upgrades security software for Microsoft Exchange, 03/21/07
Sunbelt Software last week announced an upgrade to its e-mail security software for Microsoft Exchange that features more protection against spam, a new disclaimer feature and enhancements to the software’s management console.
Oracle, Sun fixing J2SE bug with E-Business Suite, 03/20/07
Oracle is working with Sun to fix a bug affecting how the E-Business Suite runs on Windows Vista.
CISO inner circle, 03/19/07
Michael Barrett, CISO of PayPal in San Jose; Joseph Moorcones, vice president for worldwide information security at Johnson & Johnson in New Brunswick, N.J.; and Lynn Mattice, vice president and CSO for Boston Scientific in Natick, Mass., are among the industry’s most outstanding CISOs. Here these well-respected security executives offer their insights on New Data Center-style, next-generation security, as well as give tips for securing everything from budgets to WANs.
From Cisco Subnet: Cisco confirms IP phone DoS vulnerability
Cisco has confirmed that its IP Phone 7940/7960 firmware is vulnerable to denial-of-service attacks.




