
security rss feeds.
Below are several RSS feeds that concern computer and cybersecurity. We do not provide a comprehensive list of these feeds.

Web surfers, it's time to patch
News: Breach-notification laws not working?Breach-notification laws not working?
News: Ransomware resisting crypto cracking effortsRansomware resisting crypto cracking efforts
>> Advertisement <<
Can you answer the ERP quiz?
These 10 questions determine if your
Enterprise RP rollout gets an A+.
http://www.findtechinfo.com/as/acs?pl=781&ca=909
Boycott spotlights antivirus testing issues
Brief: Apple closes holes in Mac OS X, SafariApple closes holes in Mac OS X, Safari

Guidelines for Publishing Information Online
ST05-012: Supplementing PasswordsSupplementing Passwords
SA08-162B: Microsoft Updates for Multiple VulnerabilitiesMicrosoft Updates for Multiple Vulnerabilities
SA08-162C: Apple QuickTime Updates for Multiple VulnerabilitiesApple QuickTime Updates for Multiple Vulnerabilities
SA08-150A: Apple Updates for Multiple VulnerabilitiesApple Updates for Multiple Vulnerabilities

This week was a very interesting week as far as Google and privacy goes. First, a burglary the same on that affected CNET earlier last month was confirmed to have affected all Google employees hired before December 31, 2005. There's nothing Google could have done about it, but it's...
Storm Worm's Independence Day campaignA Storm Worm's Independence Day campaign is circulating online using email as propagation vector, attempting to trick users into visiting a Storm Worm infected host, where a multitude of what looks like over five different exploits attempt to automatically infect the visitors next to the malware binary fireworks.exe. Historically, Storm...
Say it ain't so AVG, say it ain't so: AVG LinkScanner = Badware?The Register covered a very interesting story about AVG. Apparently AVG is spamming the Internet with traffic that looks to be coming from Internet Explorer. AVG software pre-crawls search results to try to protect users, but uses a user agent that makes the software appear to be Internet Explorer. This pre-crawling is flooding websites with...
On deck from MS: Four 'important' patches but nothing for IENext Tuesday, Microsoft plans to ship four security updates for multiple flaws affecting Windows, Microsoft SQL Server and Microsoft Exchange Server but the absence of fixes for publicly known Internet Explorer issues is causing raised eyebrows among security professionals. According to the company's advance notice for July's...
Apple caught neglecting iPhone securityIf you're waiting on iPhone 2 to standardize your business on the awesome new device (yeah, I'll be on line to buy one), you might want to pay attention to the conspicuous absence of iPhone security patches over the last four months. As WaPo's Brian Krebs reports,...

News reports this week that the U.S. Department of Justice is formally reviewing a proposed advertising deal between Google and Yahoo came as no surprise to some tech trade groups and advocacy groups based in Washington, D.C.
Opera patches multiple bugs in flagship browserOpera Software patched the newest version of its flagship browser for the first time Wednesday when it released Opera 9.5.1 to fix several flaws.
Expect iPhone, Fourth of July scams, security firm says4Apple's launch of its new iPhone 3G will produce a flurry of spam and scams, a security company warned Thursday.
Critical vulnerability found in VLC Media PlayerSecurity company Secunia has found a flaw in the VLC Media Player that could allow an attacker to gain control of someone's PC.
Google gives away free Web app security scannerGoogle has released for free one of its internal tools used for testing the security of Web-based applications.

For Google, ready Privacy: That could be the subliminal message Google wants to send by replacing its name on its famously spartan home page with a link to its privacy policy.
Lithuania: Attacks focused on hosting companyA vulnerability in a Web server contributed to attacks on some 300 Web sites in Lithuania earlier this week, a computer security expert said on Friday.
Microsoft trumpets security additons in upcoming IE8Microsoft Wednesday outlined new security features it will add to Internet Explorer (IE) next month, including anti-malware protection to match tools similar to those offer by its rivals and a filter the company said would block most cross-site scripting attacks.
SQL attacks lob onto tennis association Web siteVisitors to the Association of Tennis Professionals Web site have potentially been infected with spyware after apparent lax security allowed a malicious script to be injected across its pages.
Video surveillance for anyone with a PCWant to keep track of things at home when you're not there? Rather than spending thousands of dollars to have a professional video security system installed, you can build one yourself for about US$250 per camera. Logitech International SA's WiLife Video Security System cameras can be strategically placed throughout your home or office to keep an eye on things and alert you when something's amiss.

Bulletin Severity Rating:Important - This security update resolves two privately reported vulnerabilities in the Pragmatic General Multicast (PGM) protocol that could allow a denial of service if malformed PGM packets are received by an affected system. An attacker who successfully exploited this vulnerability could cause a user’s system to become non-responsive and to require a restart to restore functionality. Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate their user rights, but it could cause the affected system to stop accepting requests.
MS08-035 – Important: Vulnerability in Active Directory Could Allow Denial of Service (953235)Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in implementations of Active Directory on Microsoft Windows 2000 Server, Windows Server 2003, and Windows Server 2008; Active Directory Application Mode (ADAM) when installed on Windows XP Professional and Windows Server 2003; and Active Directory Lightweight Directory Service (AD LDS) when installed on Windows Server 2008. The vulnerability could be exploited to allow an attacker to cause a denial of service condition. On Windows XP Professional, Windows Server 2003, and Windows Server 2008, an attacker must have valid logon credentials to exploit this vulnerability. An attacker who successfully exploited this vulnerability could cause the system to stop responding or automatically restart.
MS08-034 – Important: Vulnerability in WINS Could Allow Elevation of Privilege (948745)Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in the Windows Internet Name Service (WINS) that could allow elevation of privilege. A local attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.
MS08-033 – Critical: Vulnerabilities in DirectX Could Allow Remote Code Execution (951698)Bulletin Severity Rating:Critical - This security update resolves two privately reported vulnerabilities in Microsoft DirectX that could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
MS08-032 - Moderate: Cumulative Security Update of ActiveX Kill Bits (950760)Bulletin Severity Rating:Moderate - This security update resolves a publicly reported vulnerability for the Microsoft Speech API. The vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer and has the Speech Recognition feature in Windows enabled. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This update also includes a kill bit for software produced by BackWeb.

Today’s most prevalent and widely discussed attacks exploit code-level flaws such as buffer overruns and type-invalid input. We need to anticipate tomorrow’s attacks and think beyond buffer overruns, beyond code-level bugs, and beyond the horizon. To be ready for threats of the future, we need to be doing more basic research in cybersecurity today. This talk will outline a few suggestions for important research directions in cybersecurity: the foundations of trustworthy computing, security architectures, privacy, usability, and security metrics.
NSF Response to 2007 Summit Final ReportThe Cybersecurity Summit meetings have proven to be a useful forum to foster dialog between awardees, cybersecurity experts and NSF. NSF will provide feedback on the 2007 Summit meeting and discuss best practices in cybersecurity that might be useful to large facilities.
Community UpdatesCommunity updates from EDUCAUSE/Internet2 Security Task Force, InCommon, OpenScience Grid, Research and Education Networking Information Sharing and Analysis Center (REN-ISAC), TeraGrid, and the U.S. Department of Energy Computer Incident Advisory Capability.
EDUCAUSE Now - Show #4 – Cybersecurity, Cyberinfrastucture, Fear 2.0EDUCAUSE Now is a monthly podcast, focusing on the intelligent use of information technology in higher education. Each episode features a variety of stories, interviews, and views that relate to IT in higher education. Let us know what you would like to hear at podcast@educause.edu.
Subscribe to EDUCAUSE NOW RSS feed
This episode of EDUCAUSE Now features:
This is an excerpt of a longer conversation.
EDUCAUSE has published the results of the 2008 Current Issues Survey, and this year Security edged out Funding IT as the top strategic challenge.
The latest EDUCAUSE Quarterly article, "Current Issues Survey Report, 2008", states:
It is no wonder that IT security has again emerged as the top strategic issue for colleges and universities given the increasing amount of critical data and new services that are available electronically and need to be protected. The persistence of security incidents and reported data breaches, and a growing number of compliance requirements including security-related state and federal regulations and contractual obligations, make this a central and acute concern of all IT organizations, no matter their institutions' sizes and missions. College and university personnel have a daunting task to ensure the security of information resources while operating within a culture of openness and decentralization. In addition, the changing nature of the threats continues to challenge IT organizations.
The article goes on to suggest security issues that institutions need to address. Security-related resources are available as part of the 2008 Current Issues Resources.