Symantec: Web Threats 2010

Came across this great report on the state of Web Threats this year. One of the key lessons from this report shows how cybercriminals are now focused on compromising existing web servers rather than bringing their own online. In fact, they found 90% of malicious websites are compromised sites. Key reason for this, as explained by Symantec analyst Dan Bleaken: The attraction of knowing that legitimate sites often come fully furnished...
Read rest of entry

News Storm

Here's some key stories that unfolded this week in security: YouTube Victim of XSS Attack On Sunday YouTube fell victim to a XSS attack redirecting users to different sites from fake anti-virus pages to porn to Canadian pharmacy. Google patched up the problem relatively quickly but the backlash on Twitter was tremendous. Here's some great posts by SecTechno, The Register, and the SunBelt Blog. Adobe Launch Function...
Read rest of entry

Global Spam Rate 89.3% According to Latest Symantec Report

Symantec recently released their Message Labs Intelligence report, highlighting some key stats in email and web based threats. According to the report the global spam rate is now 89.3%, with 80% of these being pharmaceutical spam. The report also goes into depth on the rash of World Cup threats that amassed in the months before the start of the World Cup. Check out the full report below... http://www.messagelabs.com/mlirepo...
Read rest of entry

Firefox 4 Beta 1 Released!

The long awaited Firefox 4 Beta 1 has been released. This includes tons of changes, including tab placement and other enhancements for CSS and HTML5. Download link and release notes are linked below...check it out! http://www.mozilla.com/en-US/firefox/all-beta.html http://www.mozilla.com/en-US/firefox/4.0b1/releasenot...
Read rest of entry

Launch Action Still Vulnerable

Adobe release a patch last week to finally patch to limit the vulnerable Launch action that could be used to run script from Adobe Reader. Turns out the patch is not really complete and the Bkis Blog has found ways around this.  It took Adobe 3 months to issue a patch for this to begin with, are we going to have to wait another 3 months? In the meantime Didier Stevens, who originally found the problem has done some research...
Read rest of entry

Adding Twitter Updates with Style

Getting back into things, some things just weren't lining up in the blog template any longer, so we decided to scrap the whole thing and rebuild using the same template. Strangely enough though, the Twitter widget provided by Blogger doesn't allow any styling, which made the Twitter updates almost impossible to read. After a while of tinkering with the widgets and trying to find the right one to let me do this I finally found...
Read rest of entry

We're Back!

Green Cloud Security is back after a long layoff, mostly working on other projects. It's exciting to dig back into the site, and security in general. You can expect more of the same posts, coverage on the latest threats, threat reports, security tips and more.  Have a great day everyo...
Read rest of entry

Banking and Virus Scanning with a Live CD

Last week, Brian Krebs of the Washington Post blogged here advising business owners to perform online banking using a live CD. This excellent advice (IMHO) created quite a stir over the last week. Essentially, banking on a live CD prevents you from becoming susceptible to Windows viruses, while at the same time loading a fresh, non-compromised...
Read rest of entry

Obama Stresses Cybersecurity Awareness

"The lesson is clear, this cyberthreat is one of the most serious economic and national security challenges we face as a nation" (Obama). This is the message that Obama recently declared in a short video on the White House website. He makes it very clear, in the midst of cybersecurity awareness month, that all Americans need to be aware and secure in their online activities. "As consumers we use the internet to pay our bills,...
Read rest of entry

New Zeus Scam Emails and Download Domains

There are some new Zeus emails going around that folks should be aware of. These emails, as reported by the Securosis blog, pretend to be from a system administrator. The administrator asks them to "run SSl updates procedure" as belo...
Read rest of entry
 

Green Cloud Security

Web security and converged threats are among the biggest issues in network security. Green Cloud Security provides the latest information on these threats.

Follow us on Twitter and RSS!

twitter / greencloudsec



Term of Use

My Blog List

SANS ISC SecNewsFeed

Security Bloggers Network

Copyright © 2009 Black Nero is Designed by Ipietoon Sponsored by Online Business Journal