Home > Security News > Security Bytes: Strategic shift at Symantec leads to 80 layoffs
Security News:
EMAIL THIS

Security Bytes: Strategic shift at Symantec leads to 80 layoffs

By SearchSecurity.com Staff
28 Jun 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Strategic shift at Symantec leads to 80 layoffs
Cupertino, Calif.-based Symantec Corp. has decided to draw down its investment in network and gateway security appliances and let 80 of its 15,500 employees go as part of the strategic shift. Symantec informed its workforce of the changes late last week, according to published reports.

The company said it will stop making hardware for Symantec Gateway Security (SGS), Symantec Network Security (SNS) 7100, and the SGS Advanced Manager 3.0 products, though it will still develop the software used in these appliances. The company will now turn to partners to build the hardware.

Appliances currently in the market will continue to be sold and supported. The new strategy does not affect all appliances. Symantec Mail Security (SMS), Symantec Security Information Manager (SSIM) and Symantec Network Access Control Enforcer are among the products that won't be affected.

New flaws and exploits surface for Internet Explorer
Attackers could bypass security restrictions and launch malicious commands by exploiting two new flaws in Microsoft Internet Explorer (IE), vulnerability researcher Plebo Aesdi Nael said in an analysis published on the Full Disclosure message board hosted by Danish vulnerability clearinghouse Secunia.

In its advisory on the flaws, the French Security Incident Response Team (FrSIRT) described the vulnerabilities as:

  • An origin validation error when handling the "object.documentElement.outerHTML" property, which could be exploited by remote attackers to read content and data served from another domain in the context of a malicious Web page.
  • An error when browsing file shares, which attackers could exploit to trick a user into executing a malicious .hta file via a specially crafted Web page.

    FrSIRT noted that proof-of-concept exploits have been published.

    These new IE flaw reports come only days after Microsoft and Symantec warned of flaws and exploits targeting Microsoft's Remote Access Connection Manager (RASMAN), which was patched in the MS06-025 security bulletin June 13; and Windows Live Messenger, the instant messaging client formerly called MSN Messenger.

    Apple fixes Mac OS X flaws
    Apple Computer Inc. has released Mac OS X version 10.4.7 to address multiple security holes in the operating system.

    The update addresses the following problems:

  • An information disclosure vulnerability affecting the AFP server component. The problem occurs because search results can include the names of files and folders that an end-user should not be able to access. This may result in the disclosure of sensitive information if the file names themselves are of a sensitive nature.
  • A stack-based buffer overflow vulnerability affects ImageIO when viewing malformed .tiff images. An attacker could exploit this issue to control program execution flow; failed exploit attempts will likely result in a crash, effectively denying service to legitimate users.
  • A local format-string vulnerability affects the operating system's logging facility and may be exploited by attackers to execute arbitrary code with elevated privileges.
  • A denial-of-service vulnerability affects OpenLDAP. This issue can be exploited by remote attackers by asserting invalid requests. Successful exploits will cause the service to crash, effectively denying service.

    The flaws do not affect Mac OS X versions prior to 10.4.0

    New data security bill filed
    Sen. Bob Bennett, R-Utah, and Sen. Tom Carper, D-Del., have added to the growing list of data security measures now pending before Congress. The proposed Data Security Act of 2006 would create a national data protection and breach notification standard, Computerworld reported.

    "This bill would require all financial institutions, retailers and government agencies to maintain strong internal safety protections for the data they hold," Carper said in a statement. It would also require them to "quickly investigate" security breaches and to notify law enforcement, regulators and customers when there is a real risk of harm, he said.

    The proposed bill would expand the reach of current laws that require only financial institutions to protect the security and confidentiality of customer information, Bennett said in a separate statement.

    The Bennett-Carper legislation is modeled after the Gramm-Leach-Bliley Act and will require federal and state regulators to enforce compliance with the law and to make sure that data security procedures are uniformly applied, Computerworld noted.

    F-Secure patches flaw in its antivirus products
    Finnish antivirus firm F-Secure Corp. has addressed flaws that could allow attackers to push malware past the sensors of several antivirus products.

    "Antivirus products for Windows client and server systems fail to detect malware under certain circumstances," F-Secure said in an advisory. "Failures of this kind may lead to malware infections on protected systems."

    Linux, mobile and Windows-based gateway products are not affected by the vulnerability, F-Secure said.

    The advisory and issued hotfixes address two separate scenarios that both can lead to malware bypass:

  • The name of an executable program has been modified in a certain way. This leads to scanning failure despite the fact that it may be possible to execute the file.
  • The product fails to scan files on removable media. This occurs only in certain configurations where the "scan network drives" option has been disabled.

    Both scenarios may lead to system infection as the real-time scanner may grant permission to execute program files even if they are infected. But the vulnerability cannot, to F-Secure's knowledge, be used for privilege escalation attacks or to gain remote access to affected systems.

    Tags: Security Industry Market Trends, Predictions and ForecastsAlternative OS security: Mac, Linux, Unix, etc.Web Browser SecurityVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Security Industry Market Trends, Predictions and Forecasts
    Cybersecurity czar candidate questions clout of new position
    Gartner sees better days ahead for security budgets
    Sophos CEO on Symantec, McAfee after Utimaco acquisition
    WH cybersecurity plan needs private sector guidance
    Obama announces creation of cybersecurity coordinator position
    Security budgets take hit in media, tech industry, survey finds
    Cybersecurity Act of 2009: Power grab, or necessary step?
    Opinion: Gartner gets NAC wrong, again
    Cloud computing security group releases report outlining trouble areas
    White House cybersecurity advisor calls for public-private cooperation
    Security Industry Market Trends, Predictions and Forecasts Research

    Alternative OS security: Mac, Linux, Unix, etc.
    Mac OS memory flaws pose challenges for enterprise endpoint protection
    Rootkit Hunter demo: Detect and remove Linux rootkits
    Oracle to buy Sun Microsystems for $7.4 billion
    How to harden Linux operating systems
    Serious holes in Mac OS X memory, researcher shows
    What is the best operating system for an FTP server implementation?
    Black Hat DC 2009: Mac OS attack method
    New hacking method stealthily attacks Macs with malware
    Apple fixes critical QuickTime flaws
    User provisioning and SSO for PeopleSoft- and Unix-based products
    Alternative OS security: Mac, Linux, Unix, etc. Research

    Web Browser Security
    Researchers to demonstrate new EV SSL man-in-the-middle hacks
    Security researchers develop browser-based darknet
    Microsoft cracks down on click fraud ring
    Mozilla patches 11 Firefox security flaws, JavaScript errors
    Microsoft patches WebDAV security vulnerability in bevy of updates
    IT pros can detect, prevent website vulnerabilities, thwart attacks
    Stolen FTP credentials likely in massive website attacks
    Trust eroding as social engineering attacks climb in 2009, says Kaspersky expert
    US-CERT warns of Gumblar, Martuz drive-by exploits
    Google study backs browser silent auto update feature
    Web Browser Security Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    backscatter body scanning  (SearchSecurity.com)
    marketecture  (SearchSecurity.com)
    NCSA  (SearchSecurity.com)
    Palladium  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    Focused on Channel Security?
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts