PHP delivers key patches 02 May 2008 16:34 GMTPHP Group delivered release 5.2.6 to fix multiple security vulnerabilities. The open source PHP Group outlined all of the changes and Secunia rated these vulnerabilities "moderately critical." Here's Secunia's breakdown of the vulnerabilities: An unspecified error in the FastCGI SAPI can be exploited to cause a...
Source: ZDNet Questioning IT 02 May 2008 12:15 GMTThis is the 16th excerpt from the first book in the Defen series: The Board Member's IT Brief. This section is concerned with things you should talk to your CIO about - informally, but with attention. Topic Two: Maintaining Information Integrity Mainframe and Client-Server Architectures...
Source: ZDNet News to know: Sun; Microhoo; Vista; Linux security; Spigit 02 May 2008 09:18 GMTNotable headlines: Larry Dignan: Sun plans layoffs following weak quarter; Blames U.S. economy Nate McFeters: Multiple Linux flaws show that Linux also has kernel issues More bad news for McAfee, HackerSafe certification Steve Ballmer's defining hour Mary...
Source: ZDNet More bad news for McAfee, HackerSafe certification 01 May 2008 23:56 GMTDan Godin posted a great article that was picked up by The Register a couple days ago about continued challenges for McAfee's newly purchased HackerSafe division. I find the article interesting as HackerSafe uses a scanning tool that probes for web application security flaws... of course, tools are limited in...
Source: ZDNet Word up to Linux fan boys: Multiple Linux flaws show that Linux also has kernel issues 01 May 2008 21:12 GMTNot to defend Microsoft, as kernel exploits that provide privileged access are terrible flaws, but we had an interesting discussion in the talkbacks where several people acted as if Microsoft was the only place that could've made such mistakes. Well, the proof is in the pudding that this is a common flaw...
Source: ZDNet A personal denial of service attack 01 May 2008 13:15 GMTAbout two weeks ago my mail system started getting a lot of reject and return messages pertaining to email being sent out with murph at winface as the return address. None of that actually originated here, of course, but by last Sunday volumes were up to about a two hundred...
Source: ZDNet Securing Financial Services Beyond the Perimeter 01 May 2008 13:00 GMT(Source: SonicWALL) The traditional financial services network has evolved into a transactional e-commerce model, offering customers products and services beyond the network perimeter. A "clean VPN" integrates intelligent UTM firewall technology with intelligent SSL VPN remote access technology to deliver centrally-managed, multi-layered security and compliance.

Source: Computerworld Using mail for phishing 01 May 2008 12:15 GMTThe standard phishing scams still catch enough people to justify the small costs and low risks involved - but there's a better way. From the bad guy's perspective traditional phishing has costs and benefits. On the cost side there's a few hundred dollars to get a million...
Source: ZDNet