Home > Security News > Security Bytes: Vista under the hackers' microscope
Security News:
EMAIL THIS

Security Bytes: Vista under the hackers' microscope

By SearchSecurity.com Staff
14 Jun 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Vista under the hackers' microscope
Microsoft has great confidence in the security features of its upcoming Vista OS. So much confidence, in fact, that it plans to show them off in a den of hackers. At the August Black Hat confab in Las Vegas, the software giant will take to the stage and offer an entire series of sessions on its long-awaited overhaul of the Windows operating system.

It will be the first presentation Microsoft has made at the hacker-oriented gathering. Microsoft security program manager Stephen Toulouse told eWeek that the idea is to provide deeply technical presentations on Vista security to the hacking community.

"We submitted several presentations to the Black Hat event organizers and, based on the technical merit and interest to the audience, they were accepted," Toulouse told eWeek.

John Lambert, group manager in Microsoft's Security Engineering and Communications Group, will also be on hand to discuss the security engineering process behind Vista. Specifically, he will show how Vista's engineering process differs from that of Windows XP, and he'll display new features designed to blunt memory overwrite flaws.

RSA stock option grants under scrutiny
Bedford, Mass.-based RSA Security Inc. acknowledged Tuesday that it has been subpoenaed by the U.S. Attorney for the Southern District of New York for records from 1996 to the present related to the company's granting of stock options.

The company told the Reuters news agency it will cooperate fully with the office of the U.S. Attorney in its investigation of how RSA and other companies granted stock options. According to Reuters, the SEC and federal prosecutors in New York and California are looking at more than 40 companies to determine if they gave backdated stock options to top executives after a run-up in stock options. The majority of companies involved have to date been technology-based companies.

Last Friday RSA said it received notification of a shareholder complaint alleging violations from October 1999 to present of state and federal laws relating to stock option grant practices. The company said in a filing with the U.S. Securities and Exchange Commission that its directors intend to review the allegations before responding.

Shares in RSA dropped by 2.1% to $16.33 in Tuesday mid-day trading on the Nasdaq market.

Report shows spike in spyware
The spyware threat has grown steadily, according to a report from Chicago-based security software firm Aladdin Knowledge Systems Inc. Among the findings, which cover 2005:

  • The number of spyware threats grew from 1,083 in 2004 to 3,389 in 2005, representing a huge spike of more than 213%.
  • The number of malicious threats classified as Trojans -- a form of spyware -- grew from 1,455 in 2004 to 3,521 in 2005, representing a 142% spike.
  • The number all other malicious threats grew from 6,222 in 2004 to 9,713 in 2005, representing a 56% increase.

    The latter statistic covers email worms and file infectors defined as self-replicating/propagating malicious applications. Unlike Spyware and Trojan horses, viruses and worms have self-spreading capabilities, using email, networks, instant messengers and other programs to propagate.

    Tags: Windows Security: Alerts, Updates and Best PracticesInformation Security Laws, Investigations and EthicsMalware, Viruses, Trojans and SpywareVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Windows Security: Alerts, Updates and Best Practices
    Microsoft to address flaws in Windows, Office for Mac
    Microsoft fixes security update that breaks Internet Explorer
    What is the best database patch management process?
    Microsoft addresses critical SMBv2 flaw, fixes record number of flaws
    Microsoft to address SMB zero-day, IIS FTP Service vulnerabilities
    Microsoft releases temporary fix for SMB2 zero-day vulnerability
    Microsoft issues SMB vulnerability advisory, patch pending
    Attackers target Microsoft IIS; new SMB flaw discovered
    Microsoft repairs Windows media, TCP/IP vulnerabilities
    Microsoft five critical updates won't include IIS

    Information Security Laws, Investigations and Ethics
    Melissa Hathaway urges more cooperation, government attention to cybersecurity
    Cybersecurity czar candidate questions clout of new position
    DHS fills National Cybersecurity Center post
    FTC shutters rogue ISP for hosting malicious content, botnets
    Experts optimistic of Obama cybersecurity plan
    WH cybersecurity plan needs private sector guidance
    Obama announces creation of cybersecurity coordinator position
    Cybersecurity Act of 2009: Power grab, or necessary step?
    Face-off: Who should be in charge of cybersecurity?
    Feds should get private sector advice on cybersecurity

    Malware, Viruses, Trojans and Spyware
    Schneier-Ranum Face-Off: Is antivirus dead?
    Modern malware, stealthy botnets, adapt quickly, expert says
    Computer worm infections up, scareware antivirus down, Microsoft says
    Web-based attacks skyrocket, pirating sites surge, security firms say
    Mini guide: How to remove and prevent Trojans, malware and spyware
    Kaspersky system analyzes malicious URLs on Twitter for malware
    Silon malware intercepts Internet Explorer sessions, steals credentials
    Breach forces payroll service provider PayChoice to shut down again
    RSA research underscores problem tracking cybercriminals
    Conficker analysis finds P2P coding limited, less sophisticated

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    BotHunter  (SearchSecurity.com)
    principle of least privilege (POLP)  (SearchSecurity.com)
    security identifier  (SearchSecurity.com)
    trusted computing  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts