Tuesday, November 23, 2010

Microsoft just doesn’t get it…. Security is about diversity

What do you think here ? are you with this report or you have another ideas ?
let me know what do you think

Microsoft recently started installing its Microsoft Security Essentials (MSE) free antivirus product via the Operating System update mechanism to computers which don’t already have an antivirus installed. Basically Microsoft is saying they are worried about the security of its users and they need to make sure they are protected. Perhaps Microsoft is trying to position itself as a provider of secure Operating Systems given the market perception of Linux, Apple and potentially Google as having more secure alternatives to Windows OS, but that’s a different story.

Read the full Report

Saturday, November 20, 2010

Cyber crime: The rats that gain access by the click of a mouse

When Iran took the unusual step of announcing that its Bushehr nuclear power plant had been infected by a piece of malicious software,

Concern had been growing for months over the potential impact of Stuxnet, a new highly sophisticated computer worm that had been targeting the programs at the heart of core industrial operating systems around the world. What particularly worried the security community was that Stuxnet was the first example of a computer program designed to cause serious damage to the physical world.

Read More

Friday, November 19, 2010

Nearly Two-Thirds Of Companies Have Been Breached In The Past Year, Study Says

IT security becoming a higher priority in many organizations, CompTIA reports

Sixty-three percent of U.S. organizations have experienced at least one security incident or breach during the past year, according to a new study released today.

Almost half of the breached organizations classified the situation as "serious" -- meaning there was a financial threat, potential damage to the organization's reputation, or other business-critical problem, according to the Computing Technology Industry Association's (CompTIA's) 8th Annual Global Security Trends Study.

ReadMore

Wednesday, November 10, 2010

Monday, September 27, 2010

Iran confirms Stuxnet worm hit nuclear plant

Iranian sources appear to have confirmed that the Stuxnet worm has infected PCs at the country's Bushehr nuclear power facility, but maintain that it has not disrupted the plant's operations. First discovered in July, the sophisticated Stuxnet threat has been designed to disrupt the supervisory control and data acquisition systems that control manufacturing processes in factories and plants around the world.

Read More

Wednesday, September 15, 2010

Attacks on power systems: Hackers, malware

Criminal Hackers and Malware vs Power Systems

Criminal hackers take advantage of both technical vulnerabilities[1] and human failings[2] to penetrate insecure systems.

Read More

Thursday, July 22, 2010

Dell warns of malware on server motherboards

Dell is apparently warning customers that "a small number" of its PowerEdge R410 server motherboards may contain malicious software.

"The potential issue involves a small number of PowerEdge server motherboards sent out through service dispatches that may contain malware," according to post on a Dell support forum. "This malware code has been detected on the embedded server management firmware."

Read More

Tuesday, July 13, 2010

Apple Ranks First In Vulnerabilities

Ten technology vendors account for 38% of all vulnerabilities disclosed over the past five years, a percentage that has remained relatively stable during this period.

Yet, the number of vulnerabilities affecting PC users has been rising rapidly, thanks largely to increasingly vulnerable third-party applications.

Read More

Monday, July 05, 2010

Reports of 'App Store Hacked' Greatly Exaggerated

Earlier today a report on TheNextWeb claimed that the App Store had been hacked and that a rogue developer had gamed the system by artificially driving sales to their eBooks. The rise in ranks were noted by competing developers who thought the rise strange given that the books all represented poorly coded Vietnamese-based books.

Read More

Tuesday, June 22, 2010

Securing 4G smartphones

Because smartphones have typically had both limited storage and connection speeds, they traditionally haven't been as vulnerable to some of the security threats that have long plagued PCs.

But with the advent of super-powered smartphones and 4G mobile networks, this might be changing. Today's high-end smartphones have storage capacities in the 32GB range and processing speeds that go 1GHz or higher. And once 4G technologies such as WiMAX and LTE become more widely available, smartphones will have average connection speeds of 3Gbps or higher, giving them speeds that approach the average U.S. wireline broadband speed.

Read More

Tuesday, May 11, 2010

New Microsoft Forefront Software Runs Five Antivirus Vendors' Engines

Forefront Protection 2010 for SharePoint supports AV from Authentium, Kaspersky Lab, Norman, and VirusBuster as well as Microsoft

Read More

Wednesday, April 28, 2010

Linux machines linked to spam

symantec Studay shows Linux machines linked to spam
Although Linux holds only a small market share, Linux computers appear to send a disproportionate amount of spam compared to other operating systems, according to new research from Symantec's MessageLabs messaging security division. Symantec looked at spam from November 2009 through March and broke down what kind of operating system is on the computer that sent the spam.

Read More

Thursday, April 22, 2010

Flawed McAfee update paralyzes corporate PCs

A flawed McAfee antivirus update sent enterprise administrators scrambling today as the new signatures quarantined a crucial Windows system file, crippling an unknown number of Windows XP computers, according to messages on the company's support forum.

The forum has since gone offline.

Read More

Tuesday, February 02, 2010

New AV- Test Resulut

Microsoft Forefront Still beating the top Av Vendors
February 2009 saw the introduction of RAP testing to VB's VB100 comparative reviews, measuring products' reactive and proactive detection abilities against the most recent malware that has emerged around the world.


Thursday, January 07, 2010

Y2K all over again in 2010?

A decade after the Y2K crisis, date changes still pose technology problems, making some security software upgrades difficult and locking millions of bank ATM users out of their accounts. Chips used in bank cards to identify account numbers could not read the year 2010 properly, making it impossible for ATMs and point of sale machines in Germany to read debit cards of 30 million people since New Year's Day, according to published reports. The workaround is to reprogram the machines so the chips don't have to deal with the number

Read More

Thursday, December 24, 2009

Smartphone attacks, rogue antivirus, cloud breaches top 2010 security concerns

The rise of the Conficker worm and Heartland Payment Systems' enormous data breach were two defining security events in 2009. What's in store for 2010?

"It's going to get worse," says Patrik Runald, senior manager of security and research at Websense, who argues there has not yet been a year when things got better in terms of security and the wider Internet. Criminals have been mastering botnets, phishing scams and fake antivirus software sales, and 2010 will bring new waves of attacks that exploit fresh targets. Specifically, smartphones such as the Apple iPhone and those based on Google's Android operating system will be in attackers' line of sight for 2010, Runald says.

Read More

Thursday, December 03, 2009

Clientless SSL VPN products break web browser domain-based security models

Clientless SSL VPN products from multiple vendors like Cisco ,Juniper and others operate in a way that breaks fundamental browser security mechanisms. An attacker could use these devices to bypass authentication or conduct other web-based attacks.

Read More

Tuesday, November 24, 2009

Microsoft: 'TaterF' Worm Top Malware Threat So Far This Month

Microsoft's Malicious Software Removal Tool (MSRT) removed malware from more than 1.5 million machines just three days after it was updated on November's Patch Tuesday, and the software giant has detected two new fake antivirus threats on more than 110,000 machines.

Read More

Sunday, November 22, 2009

Microsoft delaying the release Forefront Endpoint Protection 2010

Microsoft are announcing a schedule and strategy update for Forefront Endpoint Protection 2010, a component of the upcoming Forefront Protection Suite (previously codenamed “Stirling.”)

More Info

Thursday, October 22, 2009

Latest Reactive and Proactive AV test results


Microsoft ForeFront Client security is doing great on the latest Virusbtn Test
February 2009 saw the introduction of RAP testing to VB's VB100 comparative reviews, measuring products' reactive and proactive detection abilities against the most recent malware that has emerged around the world.



Wednesday, October 21, 2009

One week of MSE: 1.5 million downloads, 4 million detections

Microsoft Security Essentials data for the first week has been released, and the numbers tell quite a story.

Redmond has released data from the first week (between September 29 to October 6) of Microsoft Security Essentials (MSE) usage, the company's free, real-time consumer antimalware solution for fighting viruses, spyware, rootkits, and Trojans. The product was made generally available to consumers in 19 countries in eight languages, and in the first week Microsoft says it has seen well over 1.5 million downloads. "By the end of week two, we had exceeded 2.6 million downloads," a Microsoft spokesperson told Ars. Number of downloads is never equivalent to the number of installs though: the software giant can't say how many machines have the software installed, but it can weigh in on the number of infected machines

Read More

Tuesday, October 13, 2009

Forefront Threat Management Gateway 2010 Release Candidate

The new version Of ISA server is Finally Out TMG 2010

Forefront Threat Management Gateway 2010 allows employees to safely and productively use the Internet without worrying about malware and other threats. Forefront Threat Management Gateway 2010 is available for download in both Standard Edition and Enterprise Edition

http://www.microsoft.com/DOWNLOADS/details.aspx?FamilyID=e05aecbc-d0eb-4e0f-a5db-8f236995bccd&displaylang=en#QuickInfoContainer

Wednesday, September 30, 2009

Microsoft Security Essentials Is finally Out

Microsoft Security Essentials provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software.
Microsoft Security Essentials is a free* download from Microsoft that is simple to install, easy to use, and always kept up to date so you can be assured your PC is protected by the latest technology. It’s easy to tell if your PC is secure — when you’re green, you’re good. It’s that simple.
Microsoft Security Essentials runs quietly and efficiently in the background so that you are free to use your Windows-based PC the way you want—without interruptions or long computer wait times.

http://www.microsoft.com/Security_essentials/

Thursday, September 17, 2009

New scam adds live chat to phishing attack

Online scammers have created a phishing site masquerading as a U.S.-based bank that launches a live chat window where victims are tricked into revealing more information, researchers at the RSA FraudAction Research Team said on Wednesday.

Read More

Monday, August 10, 2009

Pentagon Orders Review of Social Networking

The Pentagon is reviewing its policy toward social networking sites amid security concerns. The order comes a day after the U.S. Marine Corps issued a ban on the use of Facebook, Twitter and MySpace.
The Pentagon is reviewing its policies toward social networking sites amid network security and other concerns.
According to reports, U.S. officials have ordered a review of the threats and benefits of using Web 2.0 sites such as Facebook and others. The review is slated to be completed by the end of September.
ReadMore

Tuesday, June 23, 2009

Microsoft Security Essentials Review (With Screenshots)

Microsoft Security Essentials is the name of Microsoft’s latest Anti-Virus/Anti-Spyware software for Windows operating system. It is already being tested internally at Microsoft and is rumored to launch in September of this year. We were lucky to gets hands on the pre-beta build version of Security Essentials. I tested it on Windows Vista and was quite impressed with it. Below is the complete review along with some interesting findings.

Read More

Wednesday, June 17, 2009

MS Free Morro Antivirus is out Soon

Finally Microsoft will release their new Antivirus Morro ( Beta version )

Read More

Thursday, May 21, 2009

Web attack that poisons Google results gets worse

A new attack that peppers Google search results with malicious links is spreading quickly, the U.S. Computer Emergency Readiness Team warned on Monday.
The attack, which has intensified in recent days, can be found on several thousand legitimate Web sites, according to security experts. It targets known flaws in Adobe's software and uses them to install a malicious program on victims' machines, CERT said
The program then steals FTP login credentials from victims and uses that information to spread further. It also hijacks the victim's browser, replacing Google search results with links chosen by the attackers

Read More

Thursday, March 19, 2009

IE8 is more secure against malware than rival browsers

Microsoft plans to make its Internet Explorer 8 browser available on Thursday, along with a company-commissioned report claiming IE8 is more secure against malware than rival browsers from Mozilla and Google.
Users will be able to download IE8 in 25 languages at 12:00 noon Eastern Daylight Time on Thursday from Microsoft's IE Web site and its online download center.

Read More

Monday, March 09, 2009

Microsoft Offers free protection scan

Use Microsoft free protection scan to check for and remove viruses, spyware, and other potentially unwanted software and to find vulnerabilities in your Internet connection

http://onecare.live.com/site/en-US/center/howsafe.htm?s_cid=mscom_msrt

Tuesday, February 17, 2009

Conficker, Downadup worm , full Story

Microsoft has released a blog post explaining everything you need to know about Conficker

for more information about this worm . please check this link

Centralized Information About The Conficker Worm

Monday, January 19, 2009

Independent research firm recognizes Microsoft NAP as a leader in Network Access Control


Microsoft’s Network Access Protection (NAP) solution was cited as a leader, the top category, in a recent independent report, “The Forrester Wave: Network Access Control, Q3 2008.” Forrester placed a lot of emphasis on different access control scenarios for the evaluation, and the different vendors were evaluated around 12 different scenarios as well as strengths across technology, strategy, and market presence.
“Microsoft has the strongest NAC product for managed endpoints,” the report stated. The report goes on to state that even though its official product has only been shipping since the inception of Windows Server 2008, Microsoft has already established itself as a critical thought leader and contributor to the standardizations of NAC. “Microsoft has the overall highest score among the 12 scenarios we evaluated.


Monday, January 12, 2009

Malware Inspection at the Perimeter

The new Microsoft Forefront Threat Management Gateway Medium Business Edition (TMG MBE), available as part of Essential Business Server and as a standalone product, provides significant improvements for the Microsoft Firewall service operation. One of the most important features of this new firewall is the capability to inspect HTTP traffic that crosses it for malware. By using this new feature, you will be able to:
Improve your ability to protect your internal network against malware coming from the Internet.
Keep the perimeter updated with the latest malware signatures by using TMG Update Center.
Keep an eye on suspicious traffic via real-time monitoring of log entries and get post-mortem malware statistics using the new set of reports.

Read More

Wednesday, December 17, 2008

Malware infection rates in the Middle East among highest worldwide

Based on Microsoft’s latest Security Intelligence Report

The report features a number of countries in the region, including Bahrain, Egypt, Iraq, Saudi, Turkey, Jordan, Lebanon, Yemen, and the UAE in the worst 25 countries for malware infection as covered by the report.

Read More

Friday, December 05, 2008

Microsoft ,EMC partner in Data Loss Prevention

I think this is a good move from microsoft on the security area
Microsoft Thursday said it plans to integrate RSA data-loss prevention technology into its products to enable security managers to monitor sensitive data and block unauthorized use. RSA is EMC's security division. \
http://www.networkworld.com/news/2008/120408-microsoft-emc-partner.html?nlhtsec=ts_120508&nladname=120508securityal

Sunday, November 30, 2008

"Morro," OneCare and Forefront

I know you have many questions regarding this news , so let’s here from Microsoft

Here is the Story

Monday, November 24, 2008

Gmail exploit may allow attackers to forward e-mail

Gmail security vulnerability may allow an attacker to set up filters on users' e-mail accounts without their knowledge, according to a proof of concept posted Sunday at GeekCondition.com.
In his post, Brandon writes that the vulnerability has caused some people to lose their domain names registered through GoDaddy.com

Read More

Wednesday, November 19, 2008

Microsoft announces free Morro antivirus software

Microsoft is getting serious about global security, offering a free anti-malware package code-named Morro that has been specially designed for low cost PCs in developing nations.
The software will be available in the second half of 2009 and will provide 'comprehensive protection' from 'the majority of online threats', including viruses, spyware, rootkits and trojans.

Read More

Thursday, November 06, 2008

Microsoft: Flaws down but malware on the rise

The number of flaws impacting Microsoft products dropped 33.6 percent in the first half of 2008 compared to the last half of 2007, as hackers ramp up their focus on third-party applications, the latest Microsoft Security Intelligence Report found.This trend was particularly noticeable in the browser, said the report, released Monday. Browser-based exploits occurring on Windows XP machines were attributable to Microsoft bugs 42 percent of the time and third-party software 58 percent of the time.

Read More

Wednesday, October 29, 2008

Antivirus Defense-in-Depth Guide

The information presented in the Antivirus Defense-in-Depth guide has been updated to reflect the security improvements provided as part of Windows XP Service Pack 2. A number of the features in Windows XP Service Pack 2 have made it more difficult for malware to attack a Windows XP-based computer. The updates to this guide are designed to ensure that these enhancements are identified and explained.
http://www.microsoft.com/technet/security/guidance/serversecurity/avdind_0.mspx

Malware Removal Starter Kit

Many small- and medium-sized organizations use antivirus software, and yet new viruses, worms, and other forms of malicious software (malware) continue to infect large numbers of computers in these organizations. Malware proliferates at alarming speed and in many different ways, which makes it particularly widespread today.
This guide is intended for IT Generalists who want information and recommendations that they can use to effectively address and limit malware that infects computers in small- and medium-sized organizations. This guidance provides a set of tasks that licensed Windows® users can perform at no cost to create the Malware Removal Starter Kit. Recommendations for free malware-scanning tools are included. You can use these tools in combination with the kit to conduct scans, detect problems, and remove malware from your computer

http://www.microsoft.com/technet/security/guidance/disasterrecovery/malware/default.mspx#EHD

Sunday, October 12, 2008

Fake Microsoft email contains "backdoor" virus

I personally received this email,

fake phishing email making the rounds seemingly comes from Microsoft, but actually contains a “backdoor” trojan.
The email has a subject line that reads, “Security Update for OS Microsoft Windows” and supposedly came from the "Microsoft Official Update Center" at a domain named securityassurance[at]microsof[dot]com.
The message urges users to run an attached file to install an update that the email said will protect from the recipient from security threats and performance problems.

Read More

Tuesday, October 07, 2008

How thieves can steal your card info without you knowing it

Nice article to Read and secure you Credit Card Transactions
Taking just 5 seconds to inspect any credit/debit card readers before you swipe could end up saving you from identity and credit card theft.
Read More

Tuesday, September 23, 2008

Yahoo, Hotmail, Gmail all vulnerable to password reset hack

Yahoo Mail isn't the only Web-based mail service that could be duped into giving up someone else's account password, the tactic that some have argued was used to break into Gov. Sarah Palin's e-mail earlier this week.
Google Inc.'s Gmail, Microsoft Corp.'s Windows Live Hotmail and Yahoo Inc.'s Mail all rely on automated password reset mechanisms that can be abused by knowing a username associated with an account and an answer to a single security question, according to quick tests run by Computerworld .

Read More

Wednesday, September 17, 2008

How to configure NAP for Windows Server 2008

Really Nice Article in how to configure Microsoft NAP

http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1327034,00.html?track=NL-422&ad=659042&asrc=EM_NLT_4467618&uid=7917188

Microsoft's NAC comes out on top

Microsoft comes out on top of the NAC heap in an evaluation of 10 vendors that was published recently by Forrester Research.
The result is interesting because it’s not based on how many units were sold or performance tests but rather on evaluation of how well the products would meet the challenges of a set of real-world deployment situations

Read More

Monday, September 08, 2008

Will Microsoft Take a Sip of 'Midori'?

After some 23 years of Windows development, Microsoft appears to be more seriously considering the delivery of a non-Windows operating system. "Midori," the code name for a componentized operating system being built from scratch, has been kicking around the Redmond labs for four or five years. Recently, however, sources familiar with the project say Midori is now in "incubation," meaning the product is likely meandering its way closer to commercial availability. Midori is just one of a number of incubations under Craig Mundie, Microsoft's chief research and strategy officer.
However, another indication that the company is beginning to take Midori more seriously is that Eric Rudder, a longtime Microsoft veteran and senior vice president for technical strategy, is now supervising the project.

Read More

Sunday, September 07, 2008

Cisco warns of flaws in Cisco ASA 5500, PIX, Cisco Secure ACS

Cisco is warning of multiple security holes in its security appliances that if exploited, could result in a reload of the devices or disclosure of confidential information. The company has also issued a fix to a vulnerability in its Cisco Secure Access Control Server, that was discovered by external security researchers.

Read More

Thursday, September 04, 2008

Early security issues tarnish Google's Chrome

Security researchers have already uncovered vulnerabilities in Google's Chrome browser, including one that could allow a user to download malicious code

Read More

Wednesday, August 27, 2008

Intrusions hit Fedora, Red Hat Enterprise Linux servers; some OpenSSH packages compromised

The maker of Red Hat Enterprise Linux and Fedora said that hackers have gained access to key servers in what appear to be two separate incidents. Red Hat Inc. found last week that someone had compromised several Fedora servers, including one that is used to sign Fedora packages. The company said that although the server was accessed illegally, they don’t believe that the passphrase used to get to the key used to actually sign the packages was compromised.

Read More

Monday, August 18, 2008

Microsoft BlueHat Security Briefings: Fall 2008

The eighth edition of BlueHat will be held on October 16-17, 2008, at the Microsoft corporate headquarters. The Microsoft BlueHat conference is a twice-a-year event aimed at bringing internal Microsoft security professionals and external security researchers together in a relaxed environment to promote the sharing of ideas and social networking. The event highlights important emergent technologies, techniques, and industry best practices.
Sessions
BlueHat v8 will consist of two full days of great content from both internal and external security experts presented in a lecture theater environment. These presentations will offer speakers the opportunity to showcase ongoing research and collaborate with peers while educating and highlighting advancements in security products and techniques.
Day 1: Sessions will be a hybrid of content from deep-dive technical security issues to innovative techniques and best practices in the information security realm.
Day 2: Microsoft’s Security Development Lifecycle (SDL) team will host sessions emphasizing secure development and testing practices and how to develop with security in mind from the beginning of the software development lifecycle. The BlueHat SDL sessions will focus more on appropriate defense strategies and less on attack techniques. Sessions might include demonstrations of secure coding techniques or correct and incorrect methods of using various security tools.

http://technet.microsoft.com/en-us/security/cc748656.aspx

Thursday, August 14, 2008

Hackers spoof MSNBC alerts in new twist on malware ruse

Hackers trying to plant malware on PCs have switched from touting CNN news in come-on messages to pushing breaking stories said to be from rival network MSNBC, security experts said today.
The fake messages pose with subject headings that include the phrase "Breaking News," along with phony news story headlines, such as " Jerry Yang relinquishes control over Yahoo," "Mary-Kate Olsen responsible for Heath Ledger's death," and "Plane crashes into prep school, hundreds of kids killed," said researchers at F-Secure Corp. and Sophos Plc

Read More

Thursday, August 07, 2008

From BLACK HAT 2008: Google gadget flaws

Google gadgets are small applications, such as a currency converter, calendar or weather forecast, that can be added to the iGoogle homepage or a computer's desktop. The problem lies in the fact that the mini-modules are created by third-party developers, who can embed malicious JavaScript to redirect users to hacker websites, security researcher Robert “RSnake” Hansen told several hundred people in attendance
Read More

Tuesday, August 05, 2008

Microsoft to give partners heads-up on security vulnerabilities

Microsoft will be giving companies that sell security software and services to its customers a sneak peek at the technical details of the vulnerabilities in Microsoft software before the company releases its monthly "Patch Tuesday" updates.
The new Microsoft Active Protection Program, set to be announced at the Black Hat security conference on Tuesday, is designed to give software vendors a change to prepare updates to their software before attackers have a chance to reverse engineer Microsoft's security patch and create an exploit.
"It's essentially a race between the attackers and the protectors," said Andrew Cushman, who runs the Microsoft Security Response Center. The program will "give a head start to software providers delivering security features to our mutual customers."

Read More

Switches are Supported by MS NAP 802.1x Enforcement

very Important article for implementing MS NAP 802.1x Enforcement
http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx

Sunday, August 03, 2008

MySpace and Facebook targeted by worm

Facebook users take care of this !!!

The worm variants are spread through the popular social networking sites, turning infected machines into zombies - PCs illicitly controlled by hackers to carry out tasks like denial of service attacks.The Net-Worm.Win32.Koobface.a is activated when a user accesses their MySpace account, and is spread when it automatically comments on linked friend's sites. Facebook is targeted by Net-Worm.Win32.Koobface.b, which sends messages to the infected user's contacts through the Facebook site.

Read More

Wednesday, July 23, 2008

Details of major Internet flaw posted by accident

The flaw was discovered several months ago by IOActive researcher Dan Kaminsky, who worked through the early part of this year with Internet software vendors such as Microsoft, Cisco and the Internet Systems Consortium to patch the issue.
The companies released a fix for the bug two weeks ago and encouraged corporate users and ISPs to patch their DNS systems as soon as possible. Although the problem could affect some home users, it is not considered to be a major issue for consumers, according to Kaminsky.

Read More

Tuesday, July 22, 2008

New risks in 802.11n

Along with the potential performance and coverage benefits of 802.11n come a few new security risks, says industry security guru Joshua Wright. Wright presented a Webinar last week that outlined several new vulnerabilities that high-speed 802.11n networks introduce

Read More

Monday, July 21, 2008

Facebook best Security practice

If you are Facebook user , really you need to read this
Sophos recommended privacy settings for Facebook
ID fraudsters target Facebook and other social networking sites to harvest information about you. Sophos experts recommend you set the following Facebook privacy options to protect against online identity theft.

Read More

Sunday, July 20, 2008

Anything But Microsoft

Really nice Article to read

Microsoft is a security nightmare, Macs and Linux are a godsend.
Just because you're a Linux or Mac person sipping coffee in your server room on Patch Tuesdays doesn't mean you're immune from exploits. Nothing is bulletproof these days.

http://www.darkreading.com/document.asp?doc_id=99291&page_number=3

Tuesday, July 15, 2008

Intel Chips under Attack

Waaw!!!!!!!!

Security researcher and author Kris Kaspersky plans to demonstrate how an attacker can target flaws in Intel's microprocessors to remotely attack a computer using JavaScript or TCP/IP packets, regardless of what operating system the computer is running.

Read More

Thursday, July 03, 2008

IE8.0 new security features

Microsoft has outlined new security features it will add to Internet Explorer (IE) next month, including anti-malware protection to block most cross-site scripting attacks.
Read More

ISA Server 2006 Service Pack 1 - Released

Finally Microsoft has released ISA 2006 SP1 ,and you can downlaoded from the following link
http://www.microsoft.com/downloads/details.aspx?FamilyId=D2FECA6D-81D7-430A-9B2D-B070A5F6AE50&displaylang=en

Monday, June 30, 2008

Yahoo Mail flaw found and fixed

If you have Yahoo desktop messenger , you need to read this one

Researchers at Cenzic discovered a vulnerability in Yahoo Mail they said could allow attackers to steal Yahoo identities and potentially access users’ sensitive information.
The company, a Web application security provider based in Santa Clara, Calif., notified Yahoo of the cross-site scripting flaw in its popular Web mail program on May 23 and Yahoo fixed it June 13.
The vulnerability requires the attacker use Yahoo Messenger desktop application version 8.1.0.209 to chat with someone using the Messenger support in the latest version of Yahoo Mail. An attacker can make their chat status “invisible” and craft a malicious message; when he returns to the chat and the user clicks on the message, the malicious scripting is executed, said Mandeep Khera, Cenzic vice president of marketing.

Read More

Saturday, May 24, 2008

ISA Server 2006 Service Pack 1 Features

Microsoft® Internet Security and Acceleration (ISA) Server 2006 Service Pack (SP) 1 will be available for your installation pleasure this summer!

really enjoy the new features

read More

Thursday, May 22, 2008

Microsoft Offers Cash To Use Its Search Engine

Microsoft plans to entice advertisers and users of its search engine with savings on online purchases on a site called Live Search cashback

Read More

Thursday, May 15, 2008

Facebook applications exposed as security risk

Take care while you are using Facebook , security report shows Facebook applications exposed as security risk

Speculation on the security of social networking has increased amid reports that applications on Facebook are capable of collecting personal information.

Read The Report

Tuesday, May 13, 2008

The Award for “outstanding Individual contributor FY08”


I was very delightful when I received a call from Symantec inviting me to attend the “Symantec Partner Awards Dinner 08” held in Dubai.
At the beginning they insisted to have me there without giving me a reason, I did my best to get the Visa and it did not work , So I wasn’t able to attend.
One of my colleges attended on my behalf and the surprise that I have been awarded as the “outstanding Individual contributor FY08”, Best Pre -Sales in the ME.

Monday, May 12, 2008

Flaw turns Gmail into spamming machine

A "serious security flaw" in Gmail turns Google's e-mail service into a spamming machine, according to a recent security report.
INSERT, the Information Security Research Team, has created a proof of concept that exploits the "trust hierarchy" that exists between mail service providers. By exploiting a flaw in the way Google forwards messages, a spammer can send thousands of bulk e-mails through Google's SMTP service, bypassing Google's 500-address bulk e-mail limit and identity fraud protections.

Read More

Wednesday, May 07, 2008

Microsoft is winning the NAC war, expert says

Why Microsoft is doing it right, ACLs are better than VLANs and the dirty dark corner of NAC (management).
By Julie Bort , Network World , 05/06/2008

Security guru Joel Snyder from Opus One recently starred as the guest of a live Network World chat where he discussed the state of network access control. Snyder says that Microsoft is emerging as one of the clear winners of NAC, but that Microsoft's technology is a foundation from which to build, not an end-all. He also says that those who are anti-NAC simply don't understand the technology. He answered a slew of technical questions from attendees including why ACLs are better than VLANs, the dirty dark corner of NAC (management) and the how and why of 802.1X. What follows is a full transcript

Read More

Wednesday, April 30, 2008

MS gaining fast in AV-Comparatives tests

Detection rates up 7% in six months, more improvement predicted.
AV-Comparatives have released the results of their latest test of detection rates, pitting 17 scanners already known to perform well against their huge collection of malware. The most improvement over the previous run, which took place in February, was shown by Microsoft, whose score shot up by 7%.

The tests take the form of an on-demand scan over a testset of over 800,000 verified samples, including file and macro viruses, worms, trojans, backdoors and other malware, using 'best possible' settings. Multi-engine product AEC Trustport (which combines detection technologies from Norman, BitDefender and AVG) topped the tables with over 99.64%, with Avira's AntiVir in second place and another multi-engine scanner, GDATA's AVK, in third - both scored over 99%. Symantec and Kaspersky round out the top five, both spotting over 98% of all samples.

Read More

Microsoft Adds Two to Forefront Family

LAS VEGAS -- Interop 2008 -- Microsoft is adding two edge security products to its Forefront line -- next-generation and rebranded versions of its remote network access product and its network edge protection product, the company revealed here today.
The newly christened Forefront Unified Access Gateway (formerly its Internet Access Gateway) and Forefront Threat Management Gateway (formerly Internet Security & Acceleration Server 2006) will be released in public beta versions later this year. Microsoft also announced that it will roll out an updated version of its SharePoint Optimizer for the existing IAG 2007 SSL VPN product next month.
“We wanted to update our naming and branding, and the vision you will see us [following] better over time is the integration and alignment with multiple access solutions across Microsoft” products, says Margaret Dawson, group product manager for Forefront edge products. “We will do a better job of integrating with SharePoint, OWA, mobile, Windows Server, etc."


Read More

Tuesday, April 29, 2008

MS Forefront security

http://www.youtube.com/watch?v=-kRNkm0TEuA

Microsoft hosts its own police academy

Hundreds of officials from agencies around the world including the FBI, Interpol, state attorneys general, city and county police, and the Air Force are attending a three-day technology training session at Microsoft's Redmond, Wash., campus beginning on Monday.
Microsoft is training the officers how to use technologies that can help them fight cybercrime as well as help them investigate traditional crime with an online component. Nearly 400 people from more than 80 agencies in 35 countries are attending.

Read More

Wednesday, April 23, 2008

Microsoft encourages researchers to hack

Microsoft wants to encourage legitimate researchers to investigate its online services for vulnerabilities -- and promises not to sue as long as they submit the bugs they find

Read the Full Story

Tuesday, April 15, 2008

30 day countdown until Cisco releases Microsoft-NAP friendly NAC gear

New and Hot subject .....

A story in Network World's Network Access Control newsletter reports that Cisco will have its Microsoft-compatible NAC gear ready in about a month, which should be good news for a lot of potential NAC users who are customers of both vendors. Cisco NAC being compatible with Microsoft network access protection (NAP) means users can deploy NAC without having to also deploy a NAC client. Instead, endpoints using Microsoft Vista and XP with Service Pack 3 can use the built-in NAP
Read More

Thursday, April 10, 2008

Microsoft releases public beta of security console

Microsoft on Tuesday released the first public beta of a centralized management console that will pull together administrative tasks around its collection of Forefront security software for clients, servers and the network edge.
At the RSA Conference, Microsoft released the first test code for Stirling, which it unveiled last summer. Stirling is designed as the knot that ties together Microsoft's Forefront security software – Client Security, Security for Exchange Server, Security for SharePoint, Internet Security and Acceleration Server (ISA), and the Intelligent Application Gateway

Read More

Sunday, April 06, 2008

Microsoft Technology Day( Kuwait)





Really it was a big event, at the Microsoft Technology Day 2008 held on March 30, 2008. There were around 300 attendees, 20 speakers and 42 sessions on various Microsoft technologies.

I have delivered the following sessions.

1- Microsoft Intelligent Application Gateway
2- Microsoft System Center Essential

Speakers were of MVPs, Microsoft employees and trainers from Infocenter Kuwait,


Magic Quadrant for Endpoint Protection

Gartner has positioned Microsoft Forefront Client Security in the Challengers Quadrant of the analyst group’s Magic Quadrant for Endpoint Protection Platforms, 2007

21 December 2007
Peter Firstbrook, Arabella Hallawell, John Girard, Neil MacDonald
Gartner RAS Core Research Note G00153291
The stand-alone antivirus market has been replaced with a broader suite of defensive technologies supported by an extensible management platform that can subsume horizontal products, such as data protection and device management capabilities

Read More

Thursday, April 03, 2008

RSA to kick off next week with Microsoft's 'Stirling'

The world's largest security conference will kick off next week in San Francisco with the public unveiling of Microsoft's next-generation of security software, code-named Stirling.

Read More

Sunday, March 23, 2008

Microsoft wins 2008 Info Security Products Guide Global Product Excellence Awards for ISA Server 2006 and Forefront Security for Exchange Server

Microsoft wins 2008 Info Security Products Guide Global Product Excellence Awards for ISA Server 2006 and Forefront Security for Exchange Server
Read More

Microsoft Acquires Security Firm

Komoku technology will be incorporated into Forefront and Windows Live OneCare.

Nancy Gohring, IDG News Service
PC World
Saturday, March 22, 2008; 2:19 PM

Microsoft hopes to beef up its security capabilities with the acquisition of Komoku, a developer of rootkit detection products, announced last week.
Financial terms of the deal were not disclosed.
Microsoft plans to add Komoku's technology into its Forefront and Windows Live OneCare products.Forefrontis Microsoft's suite of enterprise security software that includes malware protection for PCs, security tools for Exchange and SharePoint servers, and gateways that secure remote access to corporate data.

Read The Story

Sunday, March 16, 2008

Trend Micro hit by massive Web hack

Security vendor Trend Micro has fallen victim to a widespread Web attack that splashed malicious software onto hundreds of legitimate Web sites in recent days.
A Trend Micro spokesman confirmed that the company's site had been hacked Thursday, saying that the attack took place earlier in the week. "A portion of our site -- some pages were attacked," said Mike Sweeny, a Trend Micro spokesman. "We took the pages down overnight Tuesday night -- and took corrective action."

Read The Story

Thursday, March 13, 2008

Cisco patches two flaws in its Secure Access Control Server

Submitted by Cisconet on Wed, 03/12/2008 - 7:54pm.
Cisco released free software fixes for two sets of vulnerabilities that affect its Cisco Secure Access Control Server (ACS) for Windows User-Changeable Password (UCP) application. The flaws were reported to Cisco by Felix 'FX' Lindner of Recurity Labs.

Read the Story

Open Day funny Video

Community Open Day –Kuwait





It is our first community event , and really it was amazing one based on the attendees feedback (a round 150 attendees )
Here is some details about the event

http://www.dotnetboom.net/openday/Default.aspx


Tuesday, March 11, 2008

Security vendors rally around NAP

It is a nice article about NAC solution competition

Security vendors are clamoring to announce their products' compatibility with Microsoft's network access protection, a key security feature of Windows Server 2008.
Foundry Networks

Read More

Microsoft Technology Day


























Microsoft Technology Day is being conducted by the Microsoft Experts Community (MSExperts.net) at Kuwait on InfoCenter Dawalia bulding on 30th of march 2008

I will be presenting at the event on the following topics:

1- Microsoft Intelligent application gateway (SSL VPN)


2-Microsoft System Essential 2007

Thursday, May 31, 2007

Google buys into security, acquires GreenBorder

San Francisco (InfoWorld) - Google has jumped into the anti-malware market, snatching up browser-based security software maker GreenBorder Technologies for an undisclosed amount of money.
Read More

Monday, April 23, 2007

Eight in ten major Web sites highly vulnerable to attack

Eight out of ten Web sites contain common flaws that can allow attackers to steal customer data, create phishing exploits, or craft a variety of other attacks, a security company reported today.
WhiteHat Security regularly scans hundreds of "very popular, very high-traffic sites" for its online business customers, says Jeremiah Grossman, the company's founder. "More than likely, you have shopped there, or bank there," he says. Thirty percent of scanned sites contain an urgent vulnerability, such as one that allows direct access to a company database with customer information, he says.

Read More

Hacker breaks into Mac at security conference

A hacker managed to break into a Mac and win a $10,000 prize as part of a contest started at the CanSecWest security conference in Vancouver
In winning the contest, he exposed a hole in Safari, Apple's browser. "Currently, every copy of OS X out there now is vulnerable to this," said Sean Comeau, one of the organizers of CanSecWest.

Read More

Wednesday, September 27, 2006

USB memory sticks pose new dangers

The ability to use tiny USB memory sticks to download and walk away with relatively large amounts of data has already made the ubiquitous devices a potent security threat in corporate environments. Now, the emergence of USB flash drives that can store and automatically run applications straight off the device could soon make the drives even more of a security headache.

Demonstrating the potential danger, Hak.5, a security-related podcast, earlier this month showed how a USB memory stick can -- in just a few seconds -- be turned into a device capable of automatically installing back doors, retrieving passwords or grabbing software product codes.

Hak.5's "hacking framework" is called USB SwitchBlade and gives hackers a way to automate different payloads running on a USB flash drive, said Darren Kitchen, the Williamsburg, Va.-based co-host of Hak.5.

Read Full story

Sunday, August 20, 2006

Yahoo fixes Web mail bug

Yahoo fixes Web mail bug
August 17, 2006 2:47 PM PDT
Web giant Yahoo has fixed a security flaw in its Yahoo Mail service that exposed user accounts to cyberattacks.

The flaw involves how Yahoo Mail handles attachments and was discovered in early August by Israeli security company Avnet, according to various online news reports. An attacker could hijack a user's account after a malicious attachment was opened, these reports said.

"Online security issues are taken very seriously at Yahoo. We developed a fix for this bug and deployed it last week," a Yahoo representative said Thursday.

Because Yahoo Mail is a hosted service, users don't have to take any action to be protected against potential attacks that exploit the flaw, the representative said. "There were no documented cases of this vulnerability being exploited prior to our fix being released," the representative said.

The flaw could let an attacker craft an HTML attachment to an e-mail and bypass Yahoo Mail's security filter to execute malicious JavaScript code, according to an IDG News Service report Thursday.


Posted by Joris Evers
Read More

Saturday, August 12, 2006

Hackers Expose 'Critical' Wi-Fi Driver Flaw

Black Hat Briefings: A pair of hackers show off a new technique for breaking into computers via flaws in wireless drivers shipped on Windows and Mac systems.

LAS VEGAS—Wi-Fi-enabled computers are sitting ducks for code execution attacks because of gaping flaws in wireless drivers shipped on both Mac and Windows systems, security researchers warned at the Black Hat Briefings security conference here.

A pair of hackers—David Maynor and Jon Ellch—demonstrated such a break-in on an Apple MacBook laptop fitted with a wireless card that was broadcasting its presence to another computer set up as an access point.


Read More

Monday, August 07, 2006

Unpatched flaw revealed in Cisco firewall

Vulnerability in PIX firewall appliances could allow outside attackers to gain access to corporate networks

By Robert McMillan, IDG News Service
August 04, 2006
Cisco Systems just can't seem to make it through the Black Hat USA conference unscathed. On Wednesday a security researcher showed how an unpatched vulnerability in the company's PIX firewall appliances that could allow outside attackers to gain access to corporate networks
Read More

Saturday, August 05, 2006

Microsoft Challenges Hackers To Crack Vista

LAS VEGAS - After suffering embarrassing security exploits over the past several years, Microsoft Corp. is trying a new tactic: inviting some of the world's best-known computer experts to try to poke holes in Vista, the next generation of its Windows operating system.

Microsoft made a test version of Vista available to about 3,000 security professionals Thursday as it detailed the steps it has taken to fortify the product against attacks that can compromise bank account numbers and other sensitive information.

"You need to touch it, feel it," Andrew Cushman, Microsoft's director of security outreach, said during a talk at the Black Hat computer-security conference. "We're here to show our work."

Microsoft has faced blistering criticism for security holes that have led to network outages and business disruptions for its customers. After being accused for not putting enough resources into shoring up its products, the software maker is trying to convince outsiders that it has changed.

Read More

Even offline computers can be hacked, researchers say

LAS VEGAS — Some computers with wireless Internet capabilities are vulnerable to malicious software that would let hackers take over the machines even if their owners aren't actually online, researchers announced here Wednesday.
The researchers planned to detail the vulnerability in a demonstration at a computer-security conference, showing how to take complete control of a MacBook from Apple. But researchers David Maynor and Johnny Ellch said the technique will work on an array of machines, including those that run Microsoft's Windows and the free Linux operating system.

Read More