<?phpxml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
>
<channel>
<title>Best of Security / Published News / blogs</title>
<link>http://bestofsecurity.net</link>
<description>Best of Security Portal  votes</description>
<pubDate>Tue, 09 Mar 2010 21:00:16 PST</pubDate>
<language>en</language>
<item>
<title><![CDATA[RSA 2010 Recap]]></title>
<link>http://bestofsecurity.net/blogs/RSA_2010_Recap/</link>
<comments>http://bestofsecurity.net/blogs/RSA_2010_Recap/</comments>
<pubDate>Tue, 09 Mar 2010 21:00:16 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/RSA_2010_Recap/</guid>
<description><![CDATA[Dan Hubbard, myself, our awesome event managers, and the rest of the Websense crew have arrived home after attending and presenting at RSA 2010 in San Francisco. It was another successful year as the conference was very well attended and the presentations were quite informative.<br/><br/>104 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[WordPress Injection Attack]]></title>
<link>http://bestofsecurity.net/blogs/WordPress_Injection_Attack/</link>
<comments>http://bestofsecurity.net/blogs/WordPress_Injection_Attack/</comments>
<pubDate>Tue, 09 Mar 2010 17:00:29 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/WordPress_Injection_Attack/</guid>
<description><![CDATA[Nowadays it is not surprising when people's blogs are attacked, especially when the blog owner is a well-known person. No matter how frustrated or disappointed the bloggers are, attacks still continue. If you search &quot;my blog was hacked&quot; on Google, you get 4,230,000 results; searching &quot;my blog was hacked again&quot; returns 2,380,000 matches, and the number keeps increasing daily. What we can see from the these rough stats? Apparently nearly 44% of attacked blogs are lucky and aren't attacked again, but over 56%<br/><br/>139 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Cloud Security Threats Survey]]></title>
<link>http://bestofsecurity.net/blogs/Cloud_Security_Threats_Survey/</link>
<comments>http://bestofsecurity.net/blogs/Cloud_Security_Threats_Survey/</comments>
<pubDate>Tue, 09 Mar 2010 13:02:37 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Cloud_Security_Threats_Survey/</guid>
<description><![CDATA[Our CTO, Dan Hubbard, will be speaking at RSA on today's top threats within Cloud Computing, as part of the Cloud Security Alliance Summit this upcoming Monday (http://www.cloudsecurityalliance.org/rsa2010.html).<br/><br/>151 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Top Secrets About Your Passwords]]></title>
<link>http://bestofsecurity.net/blogs/Top_Secrets_About_Your_Passwords/</link>
<comments>http://bestofsecurity.net/blogs/Top_Secrets_About_Your_Passwords/</comments>
<pubDate>Tue, 09 Mar 2010 13:02:37 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Top_Secrets_About_Your_Passwords/</guid>
<description><![CDATA[Recent hacker activity highlights how insecure we are in the online world. Black hats keep focusing on collecting passwords in many different ways. Instead of breaking the computer security system or brute-forcing pass phrases, they use a variety of easier techniques to get our credentials.<br/><br/>61 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[What do a philologist and a lollipop have in common?]]></title>
<link>http://bestofsecurity.net/blogs/What_do_a_philologist_and_a_lollipop_have_in_common/</link>
<comments>http://bestofsecurity.net/blogs/What_do_a_philologist_and_a_lollipop_have_in_common/</comments>
<pubDate>Tue, 09 Mar 2010 13:02:32 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/What_do_a_philologist_and_a_lollipop_have_in_common/</guid>
<description><![CDATA[Question: What do a philologist and a lollipop have in common? Answer: LOL (if you don't get it, you will LOL when you see it below)<br/><br/>138 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Web proxy sites using obfuscation]]></title>
<link>http://bestofsecurity.net/blogs/Web_proxy_sites_using_obfuscation/</link>
<comments>http://bestofsecurity.net/blogs/Web_proxy_sites_using_obfuscation/</comments>
<pubDate>Tue, 09 Mar 2010 13:02:30 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Web_proxy_sites_using_obfuscation/</guid>
<description><![CDATA[As some of you may know, Web proxy sites are a common tool used for anonymously surfing the Web or bypassing Web security filters. These sites are easy to find, set up, and share. However, not all Web proxies are the same.<br/><br/>192 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Pharma comments for my blog]]></title>
<link>http://bestofsecurity.net/blogs/Pharma_comments_for_my_blog/</link>
<comments>http://bestofsecurity.net/blogs/Pharma_comments_for_my_blog/</comments>
<pubDate>Tue, 09 Mar 2010 13:02:29 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Pharma_comments_for_my_blog/</guid>
<description><![CDATA[Since the popularization of the Internet, spam has become a non-detachable part of our daily life. There is probably no user on the whole network without experience of spam. Every day, criminals invent new ways of delivering unsolicited information to end users. The rules of this game have been changing almost daily. As a result of strong technology developments and progressive approaches in companies like Websense, cyber criminals have been looking for more sophisticated ways to promote products and servi<br/><br/>100 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Malicious Facebook App Propagates via Users]]></title>
<link>http://bestofsecurity.net/blogs/Malicious_Facebook_App_Propagates_via_Users/</link>
<comments>http://bestofsecurity.net/blogs/Malicious_Facebook_App_Propagates_via_Users/</comments>
<pubDate>Tue, 09 Mar 2010 13:02:28 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Malicious_Facebook_App_Propagates_via_Users/</guid>
<description><![CDATA[The latest scam targeted at Facebook users hit the public today. The rogue app, which comes in many variants of &quot;Who is checking your profile?&quot;, has improved its technique beyond the previous attacks we've seen. Rather than spreading a single app that Facebook can easily block, it tricks users into propagating the exploit by creating a brand new Facebook application that hands over the controls to the bad guys.<br/><br/>139 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Websense Security Labs presents today at RSA 2010]]></title>
<link>http://bestofsecurity.net/blogs/Websense_Security_Labs_presents_today_at_RSA_2010/</link>
<comments>http://bestofsecurity.net/blogs/Websense_Security_Labs_presents_today_at_RSA_2010/</comments>
<pubDate>Tue, 09 Mar 2010 13:02:27 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Websense_Security_Labs_presents_today_at_RSA_2010/</guid>
<description><![CDATA[Dan Hubbard, CTO, is speaking this morning at the Cloud Security Alliance Summit at RSA (http://www.cloudsecurityalliance.org/rsa2010.html). His presentation reviews the top threats in the cloud, impacts, and mitigation and defense strategies. On Wednesday Stephan Chenette, Principal Security Researcher, will present a session titled &quot;Down the Rabbit Hole: Linking the Malicious Web through statistical modeling&quot;. In the session, Stephan will review past and present mass compromise attacks and identify the m<br/><br/>109 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[An Evolution of Profit Driven Malware]]></title>
<link>http://bestofsecurity.net/blogs/An_Evolution_of_Profit_Driven_Malware/</link>
<comments>http://bestofsecurity.net/blogs/An_Evolution_of_Profit_Driven_Malware/</comments>
<pubDate>Tue, 09 Mar 2010 13:02:25 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/An_Evolution_of_Profit_Driven_Malware/</guid>
<description><![CDATA[Malware is a gremlin of cyberspace. Digitally disguised and undeterred by borders or passports, it can be found anywhere in the world and China is no exception. China has now formed a malware industry chain from malware programming to malware spreading. Usually, after malware writers write malware, commercial agents on the Internet will sell access to it, sharing incredible profits with these malware writers.<br/><br/>106 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[The Wizard of Buzz]]></title>
<link>http://bestofsecurity.net/blogs/The_Wizard_of_Buzz/</link>
<comments>http://bestofsecurity.net/blogs/The_Wizard_of_Buzz/</comments>
<pubDate>Tue, 16 Feb 2010 12:00:26 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/The_Wizard_of_Buzz/</guid>
<description><![CDATA[Buzz is just a new wizard in the kingdom of Google. However, it is not hard to foresee through the crystal ball that Dorothy's journey along the yellow brick road will be full of constant attacks from the Witch of malware and her spamming monkeys.The biggest problem with Google Buzz is privacy. You can read lots of blogs and articles on this already, and this blog does not intend to examine this subject. It's enough to know that with Buzz, it is too easy to follow and read other people's messages. What we <br/><br/>73 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[An In-Depth Exploit Analysis on Multilayer Obfuscations]]></title>
<link>http://bestofsecurity.net/blogs/An_In-Depth_Exploit_Analysis_on_Multilayer_Obfuscations/</link>
<comments>http://bestofsecurity.net/blogs/An_In-Depth_Exploit_Analysis_on_Multilayer_Obfuscations/</comments>
<pubDate>Fri, 05 Feb 2010 12:00:30 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/An_In-Depth_Exploit_Analysis_on_Multilayer_Obfuscations/</guid>
<description><![CDATA[Websense® Security Labs™ ThreatSeeker™ Network discovered a kind of obfuscated injection code within the homepage of a Web site with an Alexa ranking within the top 10,000. The malicious code is appended to the end of the source code with deep obfuscated functions. The complexity of this attack is assessed below.<br/><br/>162 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[SOHU Digital Channel Web Site Compromised with Xunlei Thunder DapPlayer Exploit]]></title>
<link>http://bestofsecurity.net/blogs/SOHU_Digital_Channel_Web_Site_Compromised_with_Xunlei_Thunder_DapPlayer_Exploit/</link>
<comments>http://bestofsecurity.net/blogs/SOHU_Digital_Channel_Web_Site_Compromised_with_Xunlei_Thunder_DapPlayer_Exploit/</comments>
<pubDate>Thu, 28 Jan 2010 23:00:22 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/SOHU_Digital_Channel_Web_Site_Compromised_with_Xunlei_Thunder_DapPlayer_Exploit/</guid>
<description><![CDATA[Today Websense® Security Labs™ ThreatSeeker™ Network discovered that the SOHU Digital Channel Web site was compromised with a Xunlei Thunder DapPlayer Exploit that can lead to downloading and executing an Autorun worm that steals users' online game account information.<br/><br/>181 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Don't update via email!]]></title>
<link>http://bestofsecurity.net/blogs/Dont_update_via_email/</link>
<comments>http://bestofsecurity.net/blogs/Dont_update_via_email/</comments>
<pubDate>Mon, 25 Jan 2010 23:00:26 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Dont_update_via_email/</guid>
<description><![CDATA[Not to be confused with our alert last Thursday, spammers seem ready to pounce on the press attention towards the recent out-of-band release of MS10-002 to scare users into downloading fake updates via email. We have been seeing messages pushing a Microsoft update via a link. The messages spoof the From: address which shows as Microsoft Office, and in an effort to further legitimize these messages and broaden their attack targets, the messages also contain Italian and French translations.<br/><br/>155 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Update on the Microsoft Internet Explorer 0-day]]></title>
<link>http://bestofsecurity.net/blogs/Update_on_the_Microsoft_Internet_Explorer_0-day/</link>
<comments>http://bestofsecurity.net/blogs/Update_on_the_Microsoft_Internet_Explorer_0-day/</comments>
<pubDate>Tue, 19 Jan 2010 18:00:38 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Update_on_the_Microsoft_Internet_Explorer_0-day/</guid>
<description><![CDATA[We are monitoring the situation on the new Internet Explorer 0-day vulnerability that we blogged about yesterday. Our ThreatSeeker(TM) network has identified two more malicious URLs that are used in live attacks, this time hxxp://201002.[REMOVED]:2988/log/ie.html and hxxp://m.[REMOVED].net:81/m/index.html. According to reports from our friends at Ahnlab, the second URL was spread through the Instant Messenger network Misslee Messenger, a popular IM client in South Korea.We have created a timeline of the ev<br/><br/>190 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[New Internet Explorer 0-day Vulnerability and Targeted Attacks]]></title>
<link>http://bestofsecurity.net/blogs/New_Internet_Explorer_0-day_Vulnerability_and_Targeted_Attacks/</link>
<comments>http://bestofsecurity.net/blogs/New_Internet_Explorer_0-day_Vulnerability_and_Targeted_Attacks/</comments>
<pubDate>Mon, 18 Jan 2010 18:00:31 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/New_Internet_Explorer_0-day_Vulnerability_and_Targeted_Attacks/</guid>
<description><![CDATA[News of targeted attacks on Google, Adobe and other large companies were made public last week. The initial assumption was that the attacks were done with malicious PDF files but on Thursday Microsoft released information that the attacks were done with a new security vulnerability in Internet Explorer. This is interesting as the majority of targeted attacks are using email attachments sent to one or a few recipients at a target organization. These attachments are typically PDF, Microsoft Word, Excel or Po<br/><br/>73 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Avatar Success Attracts SEO Poisoning Attacks]]></title>
<link>http://bestofsecurity.net/blogs/Avatar_Success_Attracts_SEO_Poisoning_Attacks/</link>
<comments>http://bestofsecurity.net/blogs/Avatar_Success_Attracts_SEO_Poisoning_Attacks/</comments>
<pubDate>Thu, 14 Jan 2010 02:00:11 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Avatar_Success_Attracts_SEO_Poisoning_Attacks/</guid>
<description><![CDATA[The movie Avatar is making a big splash in the global film market, drawing large audiences with its unique viewing experience. It has also attracted some unwanted attention. As people search for information about Avatar on the Internet, cyber criminals are using the opportunity to spread malware. The following figure demonstrates a successful attempt to position malicious content as high as fourth in search results using a common search phrase for the movie. &amp;nbsp;<br/><br/>249 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Farewell 2009, and The Washington Post]]></title>
<link>http://bestofsecurity.net/blogs/Farewell_2009_and_The_Washington_Post/</link>
<comments>http://bestofsecurity.net/blogs/Farewell_2009_and_The_Washington_Post/</comments>
<pubDate>Tue, 29 Dec 2009 14:00:16 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Farewell_2009_and_The_Washington_Post/</guid>
<description><![CDATA[This will be the last post for the Security Fix blog. Dec. 31 marks my final day at The Washington Post Company. Over the last 15 years, I've reported hundreds of stories for washingtonpost.com and the paper edition. I have authored more than 1,300 blog posts since we launched Security Fix back in March 2005. Dozens of investigative reports that first appeared online later were &quot;reverse published&quot; in the newspaper, including eight front-page stories and a Post Magazine cover. Through it all, you - the read<br/><br/>94 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Twitter.com hijacked by 'Iranian cyber army']]></title>
<link>http://bestofsecurity.net/blogs/Twitter-com_hijacked_by_Iranian_cyber_army/</link>
<comments>http://bestofsecurity.net/blogs/Twitter-com_hijacked_by_Iranian_cyber_army/</comments>
<pubDate>Fri, 18 Dec 2009 14:00:47 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Twitter-com_hijacked_by_Iranian_cyber_army/</guid>
<description><![CDATA[Hackers hijacked the Web site of micro-blogging community Twitter.com early Friday, briefly redirecting users to a Web page for a group calling itself the &quot;Iranian Cyber Army.&quot; The attackers apparently were able to redirect Twitter users by stealing the credentials needed to administer the domain name system (DNS) records for Twitter.com. DNS servers act as a kind of phone book for Internet traffic, translating human-friendly Web site names like &quot;Twitter.com&quot; into numeric Internet addresses that are easier<br/><br/>198 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hackers exploit Adobe Reader flaw via comic strip syndicate]]></title>
<link>http://bestofsecurity.net/blogs/Hackers_exploit_Adobe_Reader_flaw_via_comic_strip_syndicate/</link>
<comments>http://bestofsecurity.net/blogs/Hackers_exploit_Adobe_Reader_flaw_via_comic_strip_syndicate/</comments>
<pubDate>Fri, 18 Dec 2009 14:00:46 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Hackers_exploit_Adobe_Reader_flaw_via_comic_strip_syndicate/</guid>
<description><![CDATA[Hackers broke into an online comic strip syndication service Thursday, embedding malicious code that sought to exploit a newly discovered security flaw in Adobe Reader and Acrobat, Security Fix has learned. On Monday, Adobe Systems Inc. said it was investigating reports that criminals were attacking Internet users via a previously unknown security flaw in its Adobe Reader and Acrobat software. Experts warned that the flaw could be used to foist software on unsuspecting users who visit a hacked or booby-tra<br/><br/>172 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Google Scam Kits]]></title>
<link>http://bestofsecurity.net/blogs/Google_Scam_Kits/</link>
<comments>http://bestofsecurity.net/blogs/Google_Scam_Kits/</comments>
<pubDate>Thu, 17 Dec 2009 06:01:58 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Google_Scam_Kits/</guid>
<description><![CDATA[&quot;Making easy money with Google&quot; scams and frauds have been circulating in the Web realm for quite some time now. In the last weeks, a new wave of such scams has emerged using Google's reputation to sell 'working from home' kits that claim Google is hiring people. Those false claims have upset Google, which is looking to sue the group/company behind the campaign and also some related individuals.<br/><br/>243 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Google Spam Kits]]></title>
<link>http://bestofsecurity.net/blogs/Google_Spam_Kits/</link>
<comments>http://bestofsecurity.net/blogs/Google_Spam_Kits/</comments>
<pubDate>Wed, 16 Dec 2009 18:00:35 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Google_Spam_Kits/</guid>
<description><![CDATA[&quot;Making easy money with Google&quot; scams and frauds have been circulating in the Web realm for quite some time now. In the last weeks, a new wave of such scams has emerged using Google's reputation to sell 'working from home' kits that claim Google is hiring people. Those false claims have upset Google, which is looking to sue the group/company behind the campaign and also some related individuals.<br/><br/>92 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hackers target unpatched Adobe Reader, Acrobat flaw]]></title>
<link>http://bestofsecurity.net/blogs/Hackers_target_unpatched_Adobe_Reader_Acrobat_flaw/</link>
<comments>http://bestofsecurity.net/blogs/Hackers_target_unpatched_Adobe_Reader_Acrobat_flaw/</comments>
<pubDate>Wed, 16 Dec 2009 06:00:33 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Hackers_target_unpatched_Adobe_Reader_Acrobat_flaw/</guid>
<description><![CDATA[Adobe Systems Inc. said Monday it is investigating reports that attackers are exploiting a previously unidentified security hole in its Acrobat and PDF Reader software to break into vulnerable computers. The acknowledgment coincided with an alert published by the Shadowserver Foundation, a nonprofit group that tracks the spread of malicious programs that criminals use to control infected systems remotely. Shadowserver member Steven Adair said the flaw is present in the most recent versions of Adobe Acrobat<br/><br/>196 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Group IDs hotbeds of Conficker worm outbreaks]]></title>
<link>http://bestofsecurity.net/blogs/Group_IDs_hotbeds_of_Conficker_worm_outbreaks/</link>
<comments>http://bestofsecurity.net/blogs/Group_IDs_hotbeds_of_Conficker_worm_outbreaks/</comments>
<pubDate>Wed, 16 Dec 2009 06:00:30 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Group_IDs_hotbeds_of_Conficker_worm_outbreaks/</guid>
<description><![CDATA[Internet service providers in Russia and Ukraine are home to some of the highest concentrations of customers whose machines are infected with the Conficker worm, new data suggests. The report comes from the Shadowserver Foundation, a nonprofit that tracks global botnet infections. Shadowserver tracks networks and nations most impacted by Conficker, a computer worm that has infected more than 7 million Microsoft Windows PCs since it first surfaced last November. &quot;Conficker has managed to infect, and maintai<br/><br/>175 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Check your Facebook 'privacy' settings now]]></title>
<link>http://bestofsecurity.net/blogs/Check_your_Facebook_privacy_settings_now/</link>
<comments>http://bestofsecurity.net/blogs/Check_your_Facebook_privacy_settings_now/</comments>
<pubDate>Fri, 11 Dec 2009 13:00:11 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Check_your_Facebook_privacy_settings_now/</guid>
<description><![CDATA[If you use Facebook and care about your privacy, take a moment to read this blog entry. Facebook has made some major changes that allow a great deal more people to see your personal photos and videos, date of birth, family relationships, and other sensitive information. While logged in to Facebook, click the &quot;Settings&quot; link and you should see a box that looks like the one pictured below. You may see that Facebook has reset your privacy settings, so that the everyone can now see the information on your &quot;Abo<br/><br/>154 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Paper-based data breaches on the rise]]></title>
<link>http://bestofsecurity.net/blogs/Paper-based_data_breaches_on_the_rise/</link>
<comments>http://bestofsecurity.net/blogs/Paper-based_data_breaches_on_the_rise/</comments>
<pubDate>Thu, 10 Dec 2009 17:00:07 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Paper-based_data_breaches_on_the_rise/</guid>
<description><![CDATA[More than one quarter of data breaches so far this year involved consumer records that were jeopardized when organizations lost control over sensitive paper documents. Experts say those incidents came to light in large part due to a proliferation of state data breach notification laws, yet current federal proposals to preempt those state measures would allow paper-based breaches to go unreported. According to the Identity Theft Resource Center, a San Diego based nonprofit, at least 27 percent of the data b<br/><br/>179 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Video: Next Year in the Threat Webscape a4 Websense Security Labs Predictions for 2010]]></title>
<link>http://bestofsecurity.net/blogs/Video_Next_Year_in_the_Threat_Webscape_ndash_Websense_Security_Labs_Predictions_for_2010/</link>
<comments>http://bestofsecurity.net/blogs/Video_Next_Year_in_the_Threat_Webscape_ndash_Websense_Security_Labs_Predictions_for_2010/</comments>
<pubDate>Wed, 09 Dec 2009 13:00:27 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Video_Next_Year_in_the_Threat_Webscape_ndash_Websense_Security_Labs_Predictions_for_2010/</guid>
<description><![CDATA[Watch the video overview of the threats expected to increase during the next year and security trends to watch for in 2010. This video covers the following emerging security exploits and 2010 security predictions from Websense Security Labs: · Interesting new trends in Web 2.0 and real-time search exploits · Increased attacks on smartphone, Mac and Microsoft 7 platforms · Changes to the ways that botnets operate, including new aggressive behavior · New sophistication in email and blended attacks<br/><br/>155 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Featured Advertiser]]></title>
<link>http://bestofsecurity.net/blogs/Featured_Advertiser-13/</link>
<comments>http://bestofsecurity.net/blogs/Featured_Advertiser-13/</comments>
<pubDate>Tue, 08 Dec 2009 21:00:16 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Featured_Advertiser-13/</guid>
<description><![CDATA[<br/><br/>121 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Critical updates for Adobe Flash, Microsoft Windows]]></title>
<link>http://bestofsecurity.net/blogs/Critical_updates_for_Adobe_Flash_Microsoft_Windows/</link>
<comments>http://bestofsecurity.net/blogs/Critical_updates_for_Adobe_Flash_Microsoft_Windows/</comments>
<pubDate>Tue, 08 Dec 2009 21:00:11 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Critical_updates_for_Adobe_Flash_Microsoft_Windows/</guid>
<description><![CDATA[Microsoft released six software updates on Tuesday to fix at least a dozen security vulnerabilities in Windows, Internet Explorer, Windows Server and Microsoft Office. More than half of the flaws earned a &quot;critical&quot; rating, meaning criminals could exploit them to break into vulnerable systems without any help from users. Separately, Adobe Systems Inc. issued critical security updates to its Flash Player and AIR Web-browser plugins. The updates are available from the Windows Update Web site, or via the Auto<br/><br/>64 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Security Fix author named 'cybercrime hero']]></title>
<link>http://bestofsecurity.net/blogs/Security_Fix_author_named_cybercrime_hero/</link>
<comments>http://bestofsecurity.net/blogs/Security_Fix_author_named_cybercrime_hero/</comments>
<pubDate>Tue, 08 Dec 2009 09:00:13 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Security_Fix_author_named_cybercrime_hero/</guid>
<description><![CDATA[Networking equipment maker Cisco Systems Inc this week bestowed a generous honor on the Security Fix author. In its 2009 annual security report released Tuesday, Cisco names Yours Truly as a &quot;cybercrime hero,&quot; citing an ongoing investigative series detailing the plight of small businesses that have lost hundreds of thousands of dollars at the hands of malicious software. The mention comes in a section announcing Cisco's first-ever &quot;Cybercrime Showcase,&quot; which the company said aims to &quot;shine a spotlight on <br/><br/>185 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[La. firm sues Capital One after losing thousands in online bank fraud]]></title>
<link>http://bestofsecurity.net/blogs/La-_firm_sues_Capital_One_after_losing_thousands_in_online_bank_fraud/</link>
<comments>http://bestofsecurity.net/blogs/La-_firm_sues_Capital_One_after_losing_thousands_in_online_bank_fraud/</comments>
<pubDate>Mon, 07 Dec 2009 17:00:11 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/La-_firm_sues_Capital_One_after_losing_thousands_in_online_bank_fraud/</guid>
<description><![CDATA[An electronics testing firm in Louisiana is suing its bank, Capital One, alleging that the financial institution was negligent when it failed to stop hackers from transferring nearly $100,000 out of its account earlier this year. In August, Security Fix wrote about the plight of Baton Rouge-based JM Test Systems, an electronics testing firm that in February lost more than $97,000 from two separate unauthorized bank transfers a week apart. According to JM Test, Capital One has denied any responsibility for <br/><br/>164 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Phishers angling for Web site administrators]]></title>
<link>http://bestofsecurity.net/blogs/Phishers_angling_for_Web_site_administrators/</link>
<comments>http://bestofsecurity.net/blogs/Phishers_angling_for_Web_site_administrators/</comments>
<pubDate>Sun, 06 Dec 2009 01:00:10 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Phishers_angling_for_Web_site_administrators/</guid>
<description><![CDATA[Scam e-mail artists have launched a massive campaign to trick webmasters into giving up the credentials needed to administer their Web sites, targeting site owners at more than 90 online hosting providers. Experts say the attackers are attempting to build a distributed network of hacked sites through which to distribute their malicious software. The spam e-mails arrive addressed to users of some of the top Web hosting firms, from hostgator.com to yahoo.com and 50webs.com, and bear the same basic message: &quot;<br/><br/>179 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Apple issues security updates for Mac OS X]]></title>
<link>http://bestofsecurity.net/blogs/Apple_issues_security_updates_for_Mac_OS_X/</link>
<comments>http://bestofsecurity.net/blogs/Apple_issues_security_updates_for_Mac_OS_X/</comments>
<pubDate>Fri, 04 Dec 2009 17:00:10 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Apple_issues_security_updates_for_Mac_OS_X/</guid>
<description><![CDATA[Apple this week pushed an update for Leopard and Snow Leopard systems that plugs a large number of security holes in Apple's version of Java, a package installed by default on those Mac OS X systems that enables a number of multimedia Web applications. The new Java version fixes at least 14 vulnerabilities in the version designed for OS X 10.6 systems; the package put together for 10.5 Macs corrects more than two dozen security flaws. Mac users can grab the patches via Software Update or from Apple Downloa<br/><br/>83 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Prominent Author's Web Site Compromised]]></title>
<link>http://bestofsecurity.net/blogs/Prominent_Authors_Web_Site_Compromised/</link>
<comments>http://bestofsecurity.net/blogs/Prominent_Authors_Web_Site_Compromised/</comments>
<pubDate>Fri, 04 Dec 2009 13:00:21 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Prominent_Authors_Web_Site_Compromised/</guid>
<description><![CDATA[Famous writer and blogger Paulo Coelho had quite a bad surprise this morning when he found out that his blog had been compromised and was proudly advertising Valium.<br/><br/>129 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Bit.ly to scour shortened links for badness]]></title>
<link>http://bestofsecurity.net/blogs/Bit-ly_to_scour_shortened_links_for_badness/</link>
<comments>http://bestofsecurity.net/blogs/Bit-ly_to_scour_shortened_links_for_badness/</comments>
<pubDate>Thu, 03 Dec 2009 16:00:12 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Bit-ly_to_scour_shortened_links_for_badness/</guid>
<description><![CDATA[Scammers and spammers soon will have a tougher time masking links to their malicious Web sites using bit.ly, one of the more popular link-shortening services out there: The company said this week it is teaming with three security firms to warn users when a shortened link looks like it leads to badness. Criminals increasingly are abusing URL-shortening services to disguise the true destination of both phishing Web sites and those that host malicious software. Some of the most prolific and automated of these<br/><br/>195 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Nastygram: CDC 'swine flu' vaccine scam]]></title>
<link>http://bestofsecurity.net/blogs/Nastygram_CDC_swine_flu_vaccine_scam/</link>
<comments>http://bestofsecurity.net/blogs/Nastygram_CDC_swine_flu_vaccine_scam/</comments>
<pubDate>Tue, 01 Dec 2009 20:00:12 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Nastygram_CDC_swine_flu_vaccine_scam/</guid>
<description><![CDATA[E-mail scam artists are impersonating the Centers for Disease Control with a bogus e-mail that claims to offer information about a state-run vaccination program for the H1N1 &quot;Swine Flu&quot; contagion. This highly topical and plausible e-mail message directs recipients to a fake CDC Web site that tries to foist malicious software. Recipients who fall for the ruse and click the link are brought to a counterfeit CDC site that showcases a &quot;Personal H1N1 Vaccination Profile&quot; as an electronic document that supposedl<br/><br/>170 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[DC businessman loses thousands after clicking on wrong e-mail]]></title>
<link>http://bestofsecurity.net/blogs/DC_businessman_loses_thousands_after_clicking_on_wrong_e-mail/</link>
<comments>http://bestofsecurity.net/blogs/DC_businessman_loses_thousands_after_clicking_on_wrong_e-mail/</comments>
<pubDate>Tue, 01 Dec 2009 20:00:10 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/DC_businessman_loses_thousands_after_clicking_on_wrong_e-mail/</guid>
<description><![CDATA[Pay-per-click revenue in the online advertising business may be diminishing for traditional media publishers, but thieves increasingly are earning five- to seven-digit returns when victims click on a booby-trapped link or attachment sent via e-mail. The latest victim to learn this was Nigel Parkinson, president of D.C.-based Parkinson Construction, a firm with an estimated $20 million in annual revenue that has worked on some of Washington's top gathering places, including the new D.C. Convention Center an<br/><br/>136 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Nastygram: Bogus DHL e-mails harbor secret message]]></title>
<link>http://bestofsecurity.net/blogs/Nastygram_Bogus_DHL_e-mails_harbor_secret_message/</link>
<comments>http://bestofsecurity.net/blogs/Nastygram_Bogus_DHL_e-mails_harbor_secret_message/</comments>
<pubDate>Mon, 30 Nov 2009 20:00:11 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Nastygram_Bogus_DHL_e-mails_harbor_secret_message/</guid>
<description><![CDATA[A recent spam run that tries to distribute malicious software disguised as a DHL package tracking number contains a poorly hidden message that insults the Security Fix author by name. According to an analysis by security firm Sophos, the messages arrive as a &quot;Dear Customer&quot; notification stating that the courier company was unable to deliver a parcel to the recipient's address. The message urges recipients to click the attached &quot;shipping label&quot; for more information, and of course the attachment is a malicio<br/><br/>69 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hackers attempt to take $1.3 million from D.C. firm]]></title>
<link>http://bestofsecurity.net/blogs/Hackers_attempt_to_take_1-3_million_from_D-C-_firm/</link>
<comments>http://bestofsecurity.net/blogs/Hackers_attempt_to_take_1-3_million_from_D-C-_firm/</comments>
<pubDate>Mon, 30 Nov 2009 12:00:13 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Hackers_attempt_to_take_1-3_million_from_D-C-_firm/</guid>
<description><![CDATA[It has been a while since I've written about online banking fraud against small to mid-sized businesses, but I assure you the criminals perpetrating these attacks have been busier than ever. In fact, from more than a dozen incidents I've been investigating lately, the attackers for whatever reason now appear to be focusing heavily on property management and real estate firms, and title companies. On Nov. 12, I was contacted by a woman in Washington, D.C. who runs a large property management firm. The woman<br/><br/>115 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Eight tips for safe online shopping]]></title>
<link>http://bestofsecurity.net/blogs/Eight_tips_for_safe_online_shopping/</link>
<comments>http://bestofsecurity.net/blogs/Eight_tips_for_safe_online_shopping/</comments>
<pubDate>Mon, 30 Nov 2009 04:00:16 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Eight_tips_for_safe_online_shopping/</guid>
<description><![CDATA[Shopping online is a great way to save time and money, but those efficiencies quickly vanish for people who lack basic online shopping smarts. Take a few minutes to review these safe shopping tips: They may just save you a world of headache and financial pain. 1. Shop with a credit card, not a debit card. The banks are pushing more consumers toward debit cards with a bevy of awards programs because they can charge merchants higher fees than on credit card-based transactions, said Avivah Litan, a fraud anal<br/><br/>75 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Spam 'Godfather' gets 51 months in prison]]></title>
<link>http://bestofsecurity.net/blogs/Spam_Godfather_gets_51_months_in_prison/</link>
<comments>http://bestofsecurity.net/blogs/Spam_Godfather_gets_51_months_in_prison/</comments>
<pubDate>Tue, 24 Nov 2009 04:00:43 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Spam_Godfather_gets_51_months_in_prison/</guid>
<description><![CDATA[These past few days have seen some notable cyber justice cases: Late Monday, Alan M. Ralsky -- a man dubbed the &quot;Godfather of Spam&quot; -- was sentenced to 51 months in prison. And on Friday, a California man pleaded guilty in a case involving the sale of counterfeit high-tech computer parts to the U.S. military. Ralsky, 64, of West Bloomfield, Mich., joined two co-conspirators in earning stiff prison sentences for long careers of blasting junk e-mail. Following more than four years in prison, Ralsky will be s<br/><br/>139 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[New attack targets weakness in Internet Explorer]]></title>
<link>http://bestofsecurity.net/blogs/New_attack_targets_weakness_in_Internet_Explorer/</link>
<comments>http://bestofsecurity.net/blogs/New_attack_targets_weakness_in_Internet_Explorer/</comments>
<pubDate>Mon, 23 Nov 2009 09:00:12 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/New_attack_targets_weakness_in_Internet_Explorer/</guid>
<description><![CDATA[Blueprints showing attackers how to exploit a previously unknown security hole in versions of Microsoft's Internet Explorer browser recently were published online. The danger here is if IE users browse to a hacked or booby-trapped Web site that uses the exploit, that site could install malicious software. Microsoft has not yet issued an advisory about this threat. According to initial reports from Symantec and vulnerability management firm VUPEN, the exploit works against IE 6 and IE 7 versions only. The v<br/><br/>101 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Alpha Software disclosure leads to confusion]]></title>
<link>http://bestofsecurity.net/blogs/Alpha_Software_disclosure_leads_to_confusion/</link>
<comments>http://bestofsecurity.net/blogs/Alpha_Software_disclosure_leads_to_confusion/</comments>
<pubDate>Fri, 20 Nov 2009 13:00:13 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Alpha_Software_disclosure_leads_to_confusion/</guid>
<description><![CDATA[A few days ago, Security Fix heard from a reader who received a breach notification so casual in tone that he asked me to verify whether it was for real. Sure enough, Burlington, Mass.-based database application company Alpha Software Inc. recently told customers that a data breach had exposed their payment information. That fact was confirmed by similarly confused users posting to the company's online forum. The e-mail notice to affected customers reads: November 9, 2009 Dear Customer, We have been inform<br/><br/>55 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[FDA targets rogue Internet pharmacies]]></title>
<link>http://bestofsecurity.net/blogs/FDA_targets_rogue_Internet_pharmacies/</link>
<comments>http://bestofsecurity.net/blogs/FDA_targets_rogue_Internet_pharmacies/</comments>
<pubDate>Thu, 19 Nov 2009 17:00:11 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/FDA_targets_rogue_Internet_pharmacies/</guid>
<description><![CDATA[The U.S. Food and Drug Administration is pressuring a number of Internet service providers to shut off nearly 12 dozen Web sites alleged to be selling counterfeit or unapproved prescription drugs. The FDA's office of criminal investigations said it sent 22 warning letters to the operators of the sites, and alerted the appropriate ISPs and domain name registrars that the sites were selling phony pharmaceuticals, all without requiring a prescription. The agency said none of the sites represent pharmacies loc<br/><br/>67 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Bill would ban P2P use on federal networks, PCs]]></title>
<link>http://bestofsecurity.net/blogs/Bill_would_ban_P2P_use_on_federal_networks_PCs/</link>
<comments>http://bestofsecurity.net/blogs/Bill_would_ban_P2P_use_on_federal_networks_PCs/</comments>
<pubDate>Wed, 18 Nov 2009 13:00:13 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Bill_would_ban_P2P_use_on_federal_networks_PCs/</guid>
<description><![CDATA[The chairman of the House Oversight and Government Reform Committee introduced legislation on Tuesday to prohibit the use of peer-to-peer (P2P) file-sharing software across all federal government computers and networks. The &quot;Secure Federal File Sharing Act&quot; would direct the White House's Office of Management and Budget to issue guidelines barring the use and/or installation of P2P software on federal systems, unless otherwise approved for a specific purpose. The bill also calls on OMB to develop a policy t<br/><br/>66 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Featured Advertiser]]></title>
<link>http://bestofsecurity.net/blogs/Featured_Advertiser-12/</link>
<comments>http://bestofsecurity.net/blogs/Featured_Advertiser-12/</comments>
<pubDate>Wed, 18 Nov 2009 09:00:17 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Featured_Advertiser-12/</guid>
<description><![CDATA[<br/><br/>136 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Experts: Smart grid poses privacy risks]]></title>
<link>http://bestofsecurity.net/blogs/Experts_Smart_grid_poses_privacy_risks/</link>
<comments>http://bestofsecurity.net/blogs/Experts_Smart_grid_poses_privacy_risks/</comments>
<pubDate>Wed, 18 Nov 2009 09:00:16 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Experts_Smart_grid_poses_privacy_risks/</guid>
<description><![CDATA[Technologists already are worried about the security implications of linking nearly all elements of the U.S. power grid to the public Internet. Now, privacy experts are warning that the so-called &quot;smart grid&quot; efforts could usher in a new class of concerns, as utilities begin collecting more granular data about consumers' daily power consumption. &quot;The modernization of the grid will increase the level of personal information detail available as well as the instances of collection, use and disclosure of perso<br/><br/>59 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft warns of Windows 7 security hole]]></title>
<link>http://bestofsecurity.net/blogs/Microsoft_warns_of_Windows_7_security_hole/</link>
<comments>http://bestofsecurity.net/blogs/Microsoft_warns_of_Windows_7_security_hole/</comments>
<pubDate>Tue, 17 Nov 2009 09:00:16 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Microsoft_warns_of_Windows_7_security_hole/</guid>
<description><![CDATA[Microsoft has confirmed reports of a security flaw in its Windows operating system that hackers could use to temporarily destabilize Windows 7 PCs. The software giant also acknowledged that blueprints for exploiting the flaw are now available online. At issue is a so-called &quot;denial-of-service&quot; vulnerability in the component of Windows that handles the sharing of files and folders. Microsoft said attackers could use exploit code now publicly available to cause vulnerable systems to stop functioning or becom<br/><br/>116 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Security update for Apple's Safari Web browser]]></title>
<link>http://bestofsecurity.net/blogs/Security_update_for_Apples_Safari_Web_browser/</link>
<comments>http://bestofsecurity.net/blogs/Security_update_for_Apples_Safari_Web_browser/</comments>
<pubDate>Fri, 13 Nov 2009 17:00:10 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Security_update_for_Apples_Safari_Web_browser/</guid>
<description><![CDATA[Apple has shipped a new version of its Safari Web browser that fixes at least seven security vulnerabilities. The Safari 4.0.4 update is available for both Mac and Windows versions of the browser. Mac users can grab the latest version through Software Update; Windows users will need to use the bundled Apple Software Update application.<br/><br/>191 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Nastygram: Beware the NACHA gotcha]]></title>
<link>http://bestofsecurity.net/blogs/Nastygram_Beware_the_NACHA_gotcha/</link>
<comments>http://bestofsecurity.net/blogs/Nastygram_Beware_the_NACHA_gotcha/</comments>
<pubDate>Thu, 12 Nov 2009 17:00:16 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Nastygram_Beware_the_NACHA_gotcha/</guid>
<description><![CDATA[Cyber thieves on Thursday began blasting out millions of e-mails impersonating NACHA - The Electronic Payments Association, a not-for-profit group that develops operating rules for organizations that handle electronic payments, from payroll direct deposits to online bill pay services. The missives in this latest scam arrive with various subject lines, but all complain about an unauthorized, rejected or failed ACH transaction. Most regular Internet users probably will ignore this message, as few people prob<br/><br/>185 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Brazilian Govt: Soot, not hackers, caused '07 blackouts]]></title>
<link>http://bestofsecurity.net/blogs/Brazilian_Govt_Soot_not_hackers_caused_07_blackouts/</link>
<comments>http://bestofsecurity.net/blogs/Brazilian_Govt_Soot_not_hackers_caused_07_blackouts/</comments>
<pubDate>Wed, 11 Nov 2009 13:00:21 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Brazilian_Govt_Soot_not_hackers_caused_07_blackouts/</guid>
<description><![CDATA[The Brazilian government is refuting a report aired on Sunday by the CBS news magazine 60 Minutes, which stated that power blackouts in the South American nation in 2005 and 2007 were caused by hackers. Meanwhile, a large swath of Central Brazil is still reeling from another massive blackout that occurred in the region Tuesday evening. Citing six unnamed sources in the intelligence, military and cybersecurity communities, 60 Minutes claimed that a two-day outage that affected 3 million people in the Brazil<br/><br/>152 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[A year later: A look back at McColo]]></title>
<link>http://bestofsecurity.net/blogs/A_year_later_A_look_back_at_McColo/</link>
<comments>http://bestofsecurity.net/blogs/A_year_later_A_look_back_at_McColo/</comments>
<pubDate>Wed, 11 Nov 2009 09:00:11 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/A_year_later_A_look_back_at_McColo/</guid>
<description><![CDATA[A year ago today, the Internet community witnessed a remarkable event: The unplugging of McColo, a Web hosting facility in Northern California that for a long time controlled a majority of the spam-sending operations on the planet. McColo's two main Internet providers abruptly yanked the cord after Security Fix presented them with scads of evidence collected by security researchers tying massive amounts of spam and other illicit activity to McColo's network. The outcome, of course, is now well known: The v<br/><br/>120 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft plugs 15 holes in Windows, Office]]></title>
<link>http://bestofsecurity.net/blogs/Microsoft_plugs_15_holes_in_Windows_Office/</link>
<comments>http://bestofsecurity.net/blogs/Microsoft_plugs_15_holes_in_Windows_Office/</comments>
<pubDate>Tue, 10 Nov 2009 21:00:12 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Microsoft_plugs_15_holes_in_Windows_Office/</guid>
<description><![CDATA[Microsoft on Tuesday released software updates to fix at least 15 security flaws in Windows, Windows Server and Microsoft Office. One of the patches addresses a flaw so serious that users could find their Windows PCs compromised just by visiting booby-trapped Web sites. Richie Lai, director of vulnerability research for patch management firm Qualys, said the most dangerous vulnerability addressed in this month's updates is a flaw in the way Windows handles so-called &quot;embedded font&quot; files. An attacker could<br/><br/>146 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Eight indicted in $9M RBS WorldPay heist]]></title>
<link>http://bestofsecurity.net/blogs/Eight_indicted_in_9M_RBS_WorldPay_heist/</link>
<comments>http://bestofsecurity.net/blogs/Eight_indicted_in_9M_RBS_WorldPay_heist/</comments>
<pubDate>Tue, 10 Nov 2009 13:00:16 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Eight_indicted_in_9M_RBS_WorldPay_heist/</guid>
<description><![CDATA[Eight men have been indicted on charges that they hacked into credit card processing firm RBS Worldpay, and helped steal more than $9 million in a highly coordinated heist nearly a year ago, the U.S. Justice Department said Tuesday. The 16-count indictment, which names individuals from Estonia, Moldova and Russia, is the first major break in a case federal investigators are calling &quot;perhaps the most sophisticated and organized computer fraud attack ever conducted.&quot; &quot;Today, almost exactly one year later, th<br/><br/>88 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Apple ships 50+ security updates]]></title>
<link>http://bestofsecurity.net/blogs/Apple_ships_50_security_updates/</link>
<comments>http://bestofsecurity.net/blogs/Apple_ships_50_security_updates/</comments>
<pubDate>Tue, 10 Nov 2009 09:00:21 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Apple_ships_50_security_updates/</guid>
<description><![CDATA[Apple has shipped a large security update for computers running its Leopard and Snow Leopard operating systems for the Mac. The bundle contains security fixes for more than 50 vulnerabilities, including updates for components like Adaptive Firewall, FTP server, QuickTime and Spotlight. The update applies to Snow Leopard (10.6.x) and Mac OS X Leopard (10.5.8) systems, as well as OS X Server versions of these operating systems. Users can grab the patches directly from Apple Downloads or via the Mac's built-i<br/><br/>119 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Nastygram: MySpace Phish Plants Spy Software]]></title>
<link>http://bestofsecurity.net/blogs/Nastygram_MySpace_Phish_Plants_Spy_Software/</link>
<comments>http://bestofsecurity.net/blogs/Nastygram_MySpace_Phish_Plants_Spy_Software/</comments>
<pubDate>Mon, 09 Nov 2009 13:00:16 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Nastygram_MySpace_Phish_Plants_Spy_Software/</guid>
<description><![CDATA[A new spam campaign targeting MySpace.com users once again illustrates the blended threat from junk e-mail attacks, experts warn. This latest run tries to lure recipients into giving up their MySpace credentials, and then attempts to trick victims into installing password-stealing malicious software. Attackers began blasting out the junk e-mails early Monday, according to researchers at the University of Alabama, Birmingham, Researchers at the school so far have tracked more than 30 Web site names associat<br/><br/>184 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[First iPhone worm targets modified handsets]]></title>
<link>http://bestofsecurity.net/blogs/First_iPhone_worm_targets_modified_handsets/</link>
<comments>http://bestofsecurity.net/blogs/First_iPhone_worm_targets_modified_handsets/</comments>
<pubDate>Mon, 09 Nov 2009 01:00:08 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/First_iPhone_worm_targets_modified_handsets/</guid>
<description><![CDATA[The first known computer worm written for Apple's iPhone currently is infecting iPhones in Australia, swapping out the device's background image with that of 80s singer Rick Astley. The contagion, dubbed &quot;Ikee,&quot; spreads only among iPhones that have been &quot;jailbroken,&quot; a process that removes the device's software protection mechanisms and allows iPhone users to install applications that are not available through Apple's official App Store. Ikee spreads not through any vulnerability exactly, but by exploiting<br/><br/>156 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Poking at Google's new privacy Dashboard]]></title>
<link>http://bestofsecurity.net/blogs/Poking_at_Googles_new_privacy_Dashboard/</link>
<comments>http://bestofsecurity.net/blogs/Poking_at_Googles_new_privacy_Dashboard/</comments>
<pubDate>Fri, 06 Nov 2009 13:00:07 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Poking_at_Googles_new_privacy_Dashboard/</guid>
<description><![CDATA[Google this week unveiled a new feature called Dashboard, intended to give users a way to view -- and in modest ways limit -- the breadth of information the search giant collects about our online lives. To check out Dashboard, browse to this link, and sign in to your Google account. From there, you can manage which Google Documents you're sharing, edit your Gchat history, or clear out items from your Web search history, among other tasks. Google said it was launching the service &quot;to provide users with grea<br/><br/>183 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Updates for Adobe's Shockwave, Sun's Java]]></title>
<link>http://bestofsecurity.net/blogs/Updates_for_Adobes_Shockwave_Suns_Java/</link>
<comments>http://bestofsecurity.net/blogs/Updates_for_Adobes_Shockwave_Suns_Java/</comments>
<pubDate>Thu, 05 Nov 2009 21:00:10 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Updates_for_Adobes_Shockwave_Suns_Java/</guid>
<description><![CDATA[Sun Microsystems has issued an update to its Java software that fixes at least one security vulnerability. Separately, Adobe is pushing out a patch to plug four security holes in its Shockwave Player. The Sun patch brings Java 6 to version 17. If you're not sure whether you have Java or what version you may be running, visit this page and click the &quot;Do I have Java?&quot; link. If you don't have Java, you probably don't need it. If you do have it, make sure you've got this latest version. To update from within J<br/><br/>107 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Veterans Day Spam on the Rise]]></title>
<link>http://bestofsecurity.net/blogs/Veterans_Day_Spam_on_the_Rise/</link>
<comments>http://bestofsecurity.net/blogs/Veterans_Day_Spam_on_the_Rise/</comments>
<pubDate>Wed, 04 Nov 2009 17:00:20 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Veterans_Day_Spam_on_the_Rise/</guid>
<description><![CDATA[Just like any business owners, spammers have been using holidays to increase their revenue. Last week's theme was Halloween. This week, spammers are capitalizing on the upcoming Veterans Day holiday to sell their products. They're using discounts, free shipping, combo packs, and free samples with purchase, among other marketing strategies, to lure their victims.<br/><br/>121 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[SnapNames: Former exec. bid up domain prices]]></title>
<link>http://bestofsecurity.net/blogs/SnapNames_Former_exec-_bid_up_domain_prices/</link>
<comments>http://bestofsecurity.net/blogs/SnapNames_Former_exec-_bid_up_domain_prices/</comments>
<pubDate>Wed, 04 Nov 2009 17:00:07 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/SnapNames_Former_exec-_bid_up_domain_prices/</guid>
<description><![CDATA[SnapNames, the largest reseller of Web site names, Wednesday alleged that a former top executive secretly bid on tens of thousands of domain name auctions over the past four years, driving up costs for other bidders and enriching himself in the process. SnapNames owner Oversee.net said it learned about a month ago that the executive had been bidding on its domain auctions in violation of company policy that bars employees from doing so. Mason Cole, vice president of Oversee corporate communications, said t<br/><br/>157 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Spike in Social Media Malware, Phishing Attacks]]></title>
<link>http://bestofsecurity.net/blogs/Spike_in_Social_Media_Malware_Phishing_Attacks/</link>
<comments>http://bestofsecurity.net/blogs/Spike_in_Social_Media_Malware_Phishing_Attacks/</comments>
<pubDate>Wed, 04 Nov 2009 13:00:08 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Spike_in_Social_Media_Malware_Phishing_Attacks/</guid>
<description><![CDATA[E-mail scams targeting users of social media sites like Twitter and Facebook are blurring the lines between traditional phishing attacks and those designed to plant password-stealing malicious software on the victim's PC. For the past week, scammers have been blasting out e-mails that at first glance appear to be run-of-the-mill phishing scams aimed at stealing user names and passwords from Facebook users. The messages urge recipients to &quot;update&quot; their information by clicking a provided link and entering t<br/><br/>93 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Business e-banking and the 6-figure password]]></title>
<link>http://bestofsecurity.net/blogs/Business_e-banking_and_the_6-figure_password/</link>
<comments>http://bestofsecurity.net/blogs/Business_e-banking_and_the_6-figure_password/</comments>
<pubDate>Wed, 04 Nov 2009 13:00:06 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Business_e-banking_and_the_6-figure_password/</guid>
<description><![CDATA[On Monday, Security Fix featured the story of Ronnie Cutshall, a Tennessee man who was caught up in an international money laundering scam after being recruited through a work-at-home job offer. That story mentioned that Cutshall received a $9,600 transfer from a company called American Realty, but that I didn't have any luck in tracking down the victim company. Today the American Realty company affected by that scam contacted me after reading my story (turns out they're located in Shalimar, Fla., not Geor<br/><br/>76 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Featured Advertiser]]></title>
<link>http://bestofsecurity.net/blogs/Featured_Advertiser-11/</link>
<comments>http://bestofsecurity.net/blogs/Featured_Advertiser-11/</comments>
<pubDate>Mon, 02 Nov 2009 21:00:06 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Featured_Advertiser-11/</guid>
<description><![CDATA[<br/><br/>170 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[What Windows Autorun Has Wrought]]></title>
<link>http://bestofsecurity.net/blogs/What_Windows_Autorun_Has_Wrought/</link>
<comments>http://bestofsecurity.net/blogs/What_Windows_Autorun_Has_Wrought/</comments>
<pubDate>Mon, 02 Nov 2009 21:00:04 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/What_Windows_Autorun_Has_Wrought/</guid>
<description><![CDATA[A new report by Microsoft shows that the two most prevalent threats to Windows PCs in the first half of 2009 were malicious programs that have been aided mightily in their spread by a decision by Microsoft to allow the contents of removable media -- such as USB thumb drives -- to load automatically when inserted into Windows machines. In its latest &quot;Security Intelligence Report,&quot; Microsoft counted the number of threats detected by its anti-malware desktop products, and found that the Conficker worm, along <br/><br/>141 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[FDIC: Uptick in 'money mule' scams]]></title>
<link>http://bestofsecurity.net/blogs/FDIC_Uptick_in_money_mule_scams/</link>
<comments>http://bestofsecurity.net/blogs/FDIC_Uptick_in_money_mule_scams/</comments>
<pubDate>Mon, 02 Nov 2009 05:00:05 PST</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/FDIC_Uptick_in_money_mule_scams/</guid>
<description><![CDATA[The Federal Deposit Insurance Corporation (FDIC) is warning financial institutions about an uptick in scams involving unauthorized funds transfers from hacked online bank accounts to so-called &quot;money mules,&quot; people hired through work-at-home scams to help cyber criminals overseas launder money. According to the FDIC, the following are examples of events that may indicate money mule account activity: -A customer who just opened a new account suddenly receives one or several deposits, each totaling a little <br/><br/>88 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[A makeover for federal cybersecurity reporting]]></title>
<link>http://bestofsecurity.net/blogs/A_makeover_for_federal_cybersecurity_reporting/</link>
<comments>http://bestofsecurity.net/blogs/A_makeover_for_federal_cybersecurity_reporting/</comments>
<pubDate>Fri, 30 Oct 2009 14:00:18 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/A_makeover_for_federal_cybersecurity_reporting/</guid>
<description><![CDATA[The federal regulations telling agencies how to secure their computer networks are overdue for an overhaul: Even the author of the 2002 law now admits that it needs updating to reflect today's threats from hackers, viruses and cyber spies. Critics of the Federal Information Security Management Act (FISMA) long have complained that the way it has been implemented often amounts to a massive paperwork exercise. Yet somehow that criticism seems so much more valid when you actually see all of the resulting pape<br/><br/>58 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[DHS: PhoneSnoop app bugs BlackBerrys]]></title>
<link>http://bestofsecurity.net/blogs/DHS_PhoneSnoop_app_bugs_BlackBerrys/</link>
<comments>http://bestofsecurity.net/blogs/DHS_PhoneSnoop_app_bugs_BlackBerrys/</comments>
<pubDate>Thu, 29 Oct 2009 10:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/DHS_PhoneSnoop_app_bugs_BlackBerrys/</guid>
<description><![CDATA[The Department of Homeland Security's U.S. Computer Emergency Readiness Team (US-CERT) is warning BlackBerry users about a spyware program that allows attackers to turn a target's handset into a microphone that can be accessed remotely. PhoneSnoop is a free, remote spying application designed for BlackBerry phones. The app works by intercepting phone calls from a predetermined 'trigger' number. When PhoneSnoop detects an incoming call from that number, it accepts the call and turns on the BlackBerry's spea<br/><br/>134 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Nastygram: Spoofed FDIC bank fail e-mail]]></title>
<link>http://bestofsecurity.net/blogs/Nastygram_Spoofed_FDIC_bank_fail_e-mail/</link>
<comments>http://bestofsecurity.net/blogs/Nastygram_Spoofed_FDIC_bank_fail_e-mail/</comments>
<pubDate>Wed, 28 Oct 2009 10:00:17 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Nastygram_Spoofed_FDIC_bank_fail_e-mail/</guid>
<description><![CDATA[Spam e-mails mimicking the Federal Deposit Insurance Corp. and warning of additional bank failures are instead the latest bid by cyber crooks to empty your bank account, security experts warn. The messages arrive with subjects such as &quot;FDIC has officially named your bank a failed bank,&quot; and &quot;Check your Bank Deposit Insurance Coverage.&quot; The missives warn: &quot;You have received this message because you are a holder of a FDIC-insured bank account. Recently FDIC has officially named the bank you have opened your <br/><br/>122 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Former Anti-Virus Researcher Turns Tables On Industry]]></title>
<link>http://bestofsecurity.net/blogs/Former_Anti-Virus_Researcher_Turns_Tables_On_Industry/</link>
<comments>http://bestofsecurity.net/blogs/Former_Anti-Virus_Researcher_Turns_Tables_On_Industry/</comments>
<pubDate>Tue, 27 Oct 2009 18:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Former_Anti-Virus_Researcher_Turns_Tables_On_Industry/</guid>
<description><![CDATA[A security researcher shunned by the anti-virus community for violating its unwritten rules has attempted to turn the tables, erecting a Web service that virus writers could use to make their creations more stealthy and undetectable for longer periods of time. At issue is a new site called avtracker.info, which aims to keep tabs on the different automated analysis services used by the security industry, such as Virustotal, ThreatExpert, and Norman Sandbox. Researchers who unearth new malicious code samples<br/><br/>180 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Barackobama.com 'hack' is a hoax]]></title>
<link>http://bestofsecurity.net/blogs/Barackobama-com_hack_is_a_hoax/</link>
<comments>http://bestofsecurity.net/blogs/Barackobama-com_hack_is_a_hoax/</comments>
<pubDate>Tue, 27 Oct 2009 10:00:16 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Barackobama-com_hack_is_a_hoax/</guid>
<description><![CDATA[A hacker's claim that he compromised President Obama's campaign Web site appears to be a hoax, according to information that surfaced since the matter came to light early Monday. The kerfuffle started when a hacker and blogger with a history of posting evidence of security vulnerabilities in popular and high-traffic Web sites published evidence indicating that poor security at barackobama.com had exposed internal databases at the site. The hacker, identified only as &quot;Unu,&quot; claimed that a security flaw in b<br/><br/>123 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[FBI: Cyber Crooks Stole $40M From U.S. Small, Mid-Sized Firms]]></title>
<link>http://bestofsecurity.net/blogs/FBI_Cyber_Crooks_Stole_40M_From_U-S-_Small_Mid-Sized_Firms/</link>
<comments>http://bestofsecurity.net/blogs/FBI_Cyber_Crooks_Stole_40M_From_U-S-_Small_Mid-Sized_Firms/</comments>
<pubDate>Mon, 26 Oct 2009 14:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/FBI_Cyber_Crooks_Stole_40M_From_U-S-_Small_Mid-Sized_Firms/</guid>
<description><![CDATA[Cyber criminals have stolen at least $40 million from small to mid-sized companies across America in a sophisticated but increasingly common form of online banking fraud, the FBI said this week. According to the FBI and other fraud experts, the perpetrators have stuck to the same basic tactics in each attack. They steal the victim's online banking credentials with the help of malicious software distributed through spam. The intruders then initiate a series of unauthorized bank transfers out of the company'<br/><br/>159 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Nastygram: 'A New Settings File']]></title>
<link>http://bestofsecurity.net/blogs/Nastygram_A_New_Settings_File/</link>
<comments>http://bestofsecurity.net/blogs/Nastygram_A_New_Settings_File/</comments>
<pubDate>Fri, 23 Oct 2009 10:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Nastygram_A_New_Settings_File/</guid>
<description><![CDATA[Security Fix is debuting &quot;Nastygram,&quot; a short, hopefully regular feature alerting readers about some of the latest, sneakier e-mail scams. Each report will include a graphic at the top like the one in this blog post, which hopefully explains what readers should do with these missives. One particularly insidious and persistent nastygram of late is a message that will look like it was sent by your company's internal IT folks, and carries the subject &quot;A new settings file for the [insert address of someone on <br/><br/>57 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[ToorCon 11 San Diego]]></title>
<link>http://bestofsecurity.net/blogs/ToorCon_11_San_Diego/</link>
<comments>http://bestofsecurity.net/blogs/ToorCon_11_San_Diego/</comments>
<pubDate>Wed, 21 Oct 2009 14:00:21 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/ToorCon_11_San_Diego/</guid>
<description><![CDATA[Toorcon 11 will be taking place this coming weekend, October 24th and 25th, in San Diego. Here the speaker line-up: http://sandiego.toorcon.org/ This year I'm presenting a quick 20 minute talk entitled: &quot;The Dewey Decimal System for Exploit Analysis&quot;. This talk will cover exploit analysis and how from a researcher perspective, to go about matching exploits with known and unknown vulnerabilities. I hope to see you all there!<br/><br/>203 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[San Diego OWASP Chapter Meeting]]></title>
<link>http://bestofsecurity.net/blogs/San_Diego_OWASP_Chapter_Meeting/</link>
<comments>http://bestofsecurity.net/blogs/San_Diego_OWASP_Chapter_Meeting/</comments>
<pubDate>Tue, 20 Oct 2009 14:00:23 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/San_Diego_OWASP_Chapter_Meeting/</guid>
<description><![CDATA[The newly formed Open Web Application Security Project (OWASP) San Diego Chapter will meet Thursday, October 22 at 6 PM. Websense, Inc., is proud to host this event at our corporate headquarters. The event is a great way to network with some of the best security auditors, researchers, and developers in the San Diego area. We look forward to seeing you there! Please join us this Thursday, October 22 at 6 PM.<br/><br/>187 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[E-Banking on a Locked Down PC, Part II]]></title>
<link>http://bestofsecurity.net/blogs/E-Banking_on_a_Locked_Down_PC_Part_II/</link>
<comments>http://bestofsecurity.net/blogs/E-Banking_on_a_Locked_Down_PC_Part_II/</comments>
<pubDate>Tue, 20 Oct 2009 14:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/E-Banking_on_a_Locked_Down_PC_Part_II/</guid>
<description><![CDATA[A pair of Security Fix blog posts last week urging businesses to consider using something other than Microsoft Windows when banking online elicited strong reactions from readers. Most said they thought it was a fresh perspective and sound advice, while others criticized me for going too far or for failing to recommend less drastic alternatives. Let me be clear: The advice was aimed not at consumers, but at small to mid-sized companies that may not have a full-time IT/security staff, and who rely on one or <br/><br/>149 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[ChoicePoint Breach Exposed 13,750 Consumer Records]]></title>
<link>http://bestofsecurity.net/blogs/ChoicePoint_Breach_Exposed_13750_Consumer_Records/</link>
<comments>http://bestofsecurity.net/blogs/ChoicePoint_Breach_Exposed_13750_Consumer_Records/</comments>
<pubDate>Mon, 19 Oct 2009 18:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/ChoicePoint_Breach_Exposed_13750_Consumer_Records/</guid>
<description><![CDATA[ChoicePoint Inc., one of the nation's consumer data brokers, agreed to pay $275,000 to federal regulators as a result of a data breach last year that exposed Social Security numbers and other personal information on 13,750 people. The agreement comes in response to claims by the Federal Trade Commission that ChoicePoint violated the terms of a settlement reached following a separate data breach at the company in 2005 that led to hundreds of cases of identity theft. In 2006, ChoicePoint - now a subsidiary o<br/><br/>54 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[President Obama on Cyber Security Awareness]]></title>
<link>http://bestofsecurity.net/blogs/President_Obama_on_Cyber_Security_Awareness/</link>
<comments>http://bestofsecurity.net/blogs/President_Obama_on_Cyber_Security_Awareness/</comments>
<pubDate>Mon, 19 Oct 2009 14:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/President_Obama_on_Cyber_Security_Awareness/</guid>
<description><![CDATA[President Obama this week issued a short video address discussing the importance of cyber security awareness. The three-minute clip offers little in the way of startling revelation or news. But it is probably the most the president has had to say publicly about the topic since May, when he delivered a 16-minute speech saying he planned to create a new cyber security office at the White House that would be led by an as-yet-unappointed coordinator. In this latest remarks, Obama said he would soon appoint som<br/><br/>111 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Mozilla Disables Microsoft's Insecure Firefox Add-on]]></title>
<link>http://bestofsecurity.net/blogs/Mozilla_Disables_Microsofts_Insecure_Firefox_Add-on/</link>
<comments>http://bestofsecurity.net/blogs/Mozilla_Disables_Microsofts_Insecure_Firefox_Add-on/</comments>
<pubDate>Sat, 17 Oct 2009 18:00:17 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Mozilla_Disables_Microsofts_Insecure_Firefox_Add-on/</guid>
<description><![CDATA[Mozilla is disabling a pair of components stealthily installed by Microsoft earlier this year for Windows users of the Firefox Web browser, warning that the plug-in suffers from a serious security vulnerability. Firefox users may already have seen a pop-up notice about an unstable or insecure add-on being disabled. The message would look something like image below. There's a short backstory to this drama. In May, I wrote about a Windows patch for the Microsoft .NET package that silently installed the Micro<br/><br/>164 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Researcher: Hackers Hijack Some Facebook Apps]]></title>
<link>http://bestofsecurity.net/blogs/Researcher_Hackers_Hijack_Some_Facebook_Apps/</link>
<comments>http://bestofsecurity.net/blogs/Researcher_Hackers_Hijack_Some_Facebook_Apps/</comments>
<pubDate>Thu, 15 Oct 2009 18:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Researcher_Hackers_Hijack_Some_Facebook_Apps/</guid>
<description><![CDATA[A number of games and other applications built to be used on Facebook.com have been hacked so that users are quietly sent to sites that try to install malicious programs, a security researcher has found. Roger Thompson, chief research officer for computer security firm AVG, discovered about a half-dozen Facebook games and app home pages had been compromised by attackers. While hacked Facebook profile pages are not uncommon -- thanks largely to threats like the Koobface worm -- Thompson said this was the fi<br/><br/>81 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[PayChoice Suffers Another Data Breach]]></title>
<link>http://bestofsecurity.net/blogs/PayChoice_Suffers_Another_Data_Breach/</link>
<comments>http://bestofsecurity.net/blogs/PayChoice_Suffers_Another_Data_Breach/</comments>
<pubDate>Thu, 15 Oct 2009 18:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/PayChoice_Suffers_Another_Data_Breach/</guid>
<description><![CDATA[Payroll services provider PayChoice took its Web-based service offline for the second time in a month on Wednesday in response to yet another data breach caused by hackers. Moorestown, N.J. based PayChoice, provides direct payroll processing services and licenses its online employee payroll management product to at least 240 other payroll processing firms, serving 125,000 organizations. On Thursday morning, the company sent a notice to its customers saying it had once again closed onlineemployer.com - the <br/><br/>97 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Mozilla: Firefox Users, Check Your Plug-ins]]></title>
<link>http://bestofsecurity.net/blogs/Mozilla_Firefox_Users_Check_Your_Plug-ins/</link>
<comments>http://bestofsecurity.net/blogs/Mozilla_Firefox_Users_Check_Your_Plug-ins/</comments>
<pubDate>Wed, 14 Oct 2009 18:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Mozilla_Firefox_Users_Check_Your_Plug-ins/</guid>
<description><![CDATA[Mozilla is now offering Firefox users a simple way to tell whether the browser's various plug-ins are up-to-date with the latest security patches. Plug-ins are components installed by third-party software that power videos, animation and games in the browser, among other things. Outdated plug-ins can give malware an easy way into your computer, so it's important to make sure your browser has the latest, most secure versions. Even if you are normally vigilant about updating third-party software, occasionall<br/><br/>178 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Featured Advertiser]]></title>
<link>http://bestofsecurity.net/blogs/Featured_Advertiser-10/</link>
<comments>http://bestofsecurity.net/blogs/Featured_Advertiser-10/</comments>
<pubDate>Wed, 14 Oct 2009 14:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Featured_Advertiser-10/</guid>
<description><![CDATA[<br/><br/>72 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Trojan Turns Smash &amp; Grab Into Grab &amp; Smash]]></title>
<link>http://bestofsecurity.net/blogs/Trojan_Turns_Smash__Grab_Into_Grab__Smash/</link>
<comments>http://bestofsecurity.net/blogs/Trojan_Turns_Smash__Grab_Into_Grab__Smash/</comments>
<pubDate>Wed, 14 Oct 2009 14:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Trojan_Turns_Smash__Grab_Into_Grab__Smash/</guid>
<description><![CDATA[Imagine being in charge of your organization's finances, and learning from your bank one morning that thieves had stolen tens of thousands of dollars from company coffers overnight using your online banking credentials. Now imagine your frustration when you go to log in to your PC to assess the damage, only to find that the computer you typically use to access the account has been kneecapped by the bad guys. This is precisely what happened to Kathy Dake, office manager for St. Isidore Catholic Church in Da<br/><br/>176 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Adobe Plugs 29 Critical Reader, Acrobat Holes]]></title>
<link>http://bestofsecurity.net/blogs/Adobe_Plugs_29_Critical_Reader_Acrobat_Holes/</link>
<comments>http://bestofsecurity.net/blogs/Adobe_Plugs_29_Critical_Reader_Acrobat_Holes/</comments>
<pubDate>Tue, 13 Oct 2009 18:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Adobe_Plugs_29_Critical_Reader_Acrobat_Holes/</guid>
<description><![CDATA[Adobe Systems Inc. on Tuesday issued a new version of both Adobe Acrobat and its free Adobe PDF Reader to fix at least 29 separate security vulnerabilities in these products. If you have either (or both) of these programs installed, take a moment to update them. Adobe warns that hackers already are exploiting at least one of the flaws to break into vulnerable systems. Users of Adobe Reader and Acrobat version 9.1.3 and earlier should update to version 9.2, available in the &quot;solution&quot; section at this link. <br/><br/>148 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft Issues Record Number of Security Updates]]></title>
<link>http://bestofsecurity.net/blogs/Microsoft_Issues_Record_Number_of_Security_Updates-1/</link>
<comments>http://bestofsecurity.net/blogs/Microsoft_Issues_Record_Number_of_Security_Updates-1/</comments>
<pubDate>Tue, 13 Oct 2009 14:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Microsoft_Issues_Record_Number_of_Security_Updates-1/</guid>
<description><![CDATA[Microsoft Corp. on Tuesday issued an unprecedented number of updates to fix security problems in PCs powered by its Windows operating systems and other software: The software giant released patches to plug at least 34 security holes, the highest number of vulnerabilities it has ever addressed in a single month. October's batch of patches offer a little something for all Windows users, fixing security issues in Windows applications from the Internet Explorer (IE) browser and Microsoft Silverlight, to Micros<br/><br/>62 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[E-Banking on a Locked Down (Non-Microsoft) PC]]></title>
<link>http://bestofsecurity.net/blogs/E-Banking_on_a_Locked_Down_Non-Microsoft_PC/</link>
<comments>http://bestofsecurity.net/blogs/E-Banking_on_a_Locked_Down_Non-Microsoft_PC/</comments>
<pubDate>Mon, 12 Oct 2009 14:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/E-Banking_on_a_Locked_Down_Non-Microsoft_PC/</guid>
<description><![CDATA[In past Live Online chats and blog posts, I've mentioned any easy way to temporarily convert a Windows PC into a Linux-based computer in order to ensure that your online banking credentials positively can't be swiped by password-stealing malicious software. What follows is a brief tutorial on how to do that with Ubuntu, one of the more popular bootable Linux installations. Also known as &quot;Live CDs,&quot; these are generally free, Linux-based operating systems that one can download and burn to a CD-Rom or DVD. Th<br/><br/>88 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Avoid Windows Malware: Bank on a Live CD]]></title>
<link>http://bestofsecurity.net/blogs/Avoid_Windows_Malware_Bank_on_a_Live_CD/</link>
<comments>http://bestofsecurity.net/blogs/Avoid_Windows_Malware_Bank_on_a_Live_CD/</comments>
<pubDate>Mon, 12 Oct 2009 14:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Avoid_Windows_Malware_Bank_on_a_Live_CD/</guid>
<description><![CDATA[An investigative series I've been writing about organized cyber crime gangs stealing millions of dollars from small to mid-sized businesses has generated more than a few responses from business owners who were concerned about how best to protect themselves from this type of fraud. The simplest, most cost-effective answer I know of? Don't use Microsoft Windows when accessing your bank account online. I do not offer this recommendation lightly (and at the end of this column you'll find a link to another colu<br/><br/>92 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Adobe Warns of Critical Threat to Reader, Acrobat Users]]></title>
<link>http://bestofsecurity.net/blogs/Adobe_Warns_of_Critical_Threat_to_Reader_Acrobat_Users/</link>
<comments>http://bestofsecurity.net/blogs/Adobe_Warns_of_Critical_Threat_to_Reader_Acrobat_Users/</comments>
<pubDate>Fri, 09 Oct 2009 14:00:16 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Adobe_Warns_of_Critical_Threat_to_Reader_Acrobat_Users/</guid>
<description><![CDATA[Adobe Systems Inc. late Thursday issued an alert saying that hackers are exploiting a newly-discovered vulnerability in its free PDF Reader and Acrobat products to break into Microsoft Windows systems. Adobe said it plans to release a patch to fix this vulnerability next Tuesday, in keeping with its recent shift to push out security updates in tandem with Microsoft's regular monthly patch cycle, which occurs on the second Tuesday of each month (a.k.a. &quot;Patch Tuesday&quot;). According to the Adobe advisory, the <br/><br/>128 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Comcast Trials Browser Alerts for Bot-Infected Customer PCs]]></title>
<link>http://bestofsecurity.net/blogs/Comcast_Trials_Browser_Alerts_for_Bot-Infected_Customer_PCs/</link>
<comments>http://bestofsecurity.net/blogs/Comcast_Trials_Browser_Alerts_for_Bot-Infected_Customer_PCs/</comments>
<pubDate>Fri, 09 Oct 2009 14:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Comcast_Trials_Browser_Alerts_for_Bot-Infected_Customer_PCs/</guid>
<description><![CDATA[Comcast, the nation's largest residential Internet service provider, this week began rolling out an initiative to contact customers whose PCs appear to be infected with malicious software, by notifying these users via Web browser alerts. The Philadelphia-based cable Internet company has already been alerting bot-infected customers via phone for the past year, but a pilot program in Denver that began Thursday will inform affected users with a so-called &quot;service notice,&quot; a semi-transparent banner that overla<br/><br/>129 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Phishing Scam Spooked FBI Director Off E-Banking]]></title>
<link>http://bestofsecurity.net/blogs/Phishing_Scam_Spooked_FBI_Director_Off_E-Banking/</link>
<comments>http://bestofsecurity.net/blogs/Phishing_Scam_Spooked_FBI_Director_Off_E-Banking/</comments>
<pubDate>Thu, 08 Oct 2009 14:00:19 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Phishing_Scam_Spooked_FBI_Director_Off_E-Banking/</guid>
<description><![CDATA[In announcing a crackdown on &quot;phishing&quot; e-mail scams that netted one of the FBI's largest cyber crime cases ever, FBI Director Robert Mueller on Wednesday offered a candid revelation: A personal close call with a phishing scam has kept his family away from online banking altogether. Addressing the Commonwealth Club of California in San Francisco, Mueller spoke at length about the insidiousness of cyber crime, and how cyber criminals had affected him personally. Not long ago, the head one of our nation's do<br/><br/>151 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Latest FBI Crackdown on Phishing Targets 100 Defendants in U.S., Egypt]]></title>
<link>http://bestofsecurity.net/blogs/Latest_FBI_Crackdown_on_Phishing_Targets_100_Defendants_in_U-S-_Egypt/</link>
<comments>http://bestofsecurity.net/blogs/Latest_FBI_Crackdown_on_Phishing_Targets_100_Defendants_in_U-S-_Egypt/</comments>
<pubDate>Wed, 07 Oct 2009 18:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Latest_FBI_Crackdown_on_Phishing_Targets_100_Defendants_in_U-S-_Egypt/</guid>
<description><![CDATA[UPDATED: 7:45 p.m. Law enforcement authorities in California, Nevada, North Carolina arrested 33 people Wednesday as part of an international crackdown on &quot;phishing,&quot; e-mail scams that trick people into giving personal and financial data to counterfeit Web sites. The action, dubbed &quot;Operation Phish Phry&quot; by the FBI, targeted at least 100 people, including 20 defendants in the United States who remain at large. The FBI said that authorities in Egypt have charged at least 47 unindicted co-conspirators there <br/><br/>63 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hijacked Webmail Accounts Used to Promote Dodgy E-Commerce Sites]]></title>
<link>http://bestofsecurity.net/blogs/Hijacked_Webmail_Accounts_Used_to_Promote_Dodgy_E-Commerce_Sites/</link>
<comments>http://bestofsecurity.net/blogs/Hijacked_Webmail_Accounts_Used_to_Promote_Dodgy_E-Commerce_Sites/</comments>
<pubDate>Wed, 07 Oct 2009 14:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Hijacked_Webmail_Accounts_Used_to_Promote_Dodgy_E-Commerce_Sites/</guid>
<description><![CDATA[Tens of thousands of compromised Gmail, Hotmail and Yahoo Webmail accounts are being used to gin up traffic for dodgy, bargain-basement electronics vendors online that only accept bank transfers and Western Union payments, security experts warn. Over the weekend, the credentials for at least ten thousand Microsoft Hotmail accounts were briefly posted online. Microsoft acknowledged the incident on Monday, saying the accounts were stolen as part of a phishing scam. Since then, other news outlets have reporte<br/><br/>94 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Zeus Trojan Infiltrates Bank Security Firm]]></title>
<link>http://bestofsecurity.net/blogs/Zeus_Trojan_Infiltrates_Bank_Security_Firm/</link>
<comments>http://bestofsecurity.net/blogs/Zeus_Trojan_Infiltrates_Bank_Security_Firm/</comments>
<pubDate>Tue, 06 Oct 2009 14:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Zeus_Trojan_Infiltrates_Bank_Security_Firm/</guid>
<description><![CDATA[On Sept. 1, security industry start-up Silver Tail Systems held an in-depth online seminar for its bank and e-commerce clients that examined the stealth and sophistication of Zeus, a data-stealing Trojan horse program that organized thieves have used in a string of lucrative cyber heists this year. A week later, Silver Tail learned that Zeus had infiltrated its own network defenses. Silver Tail founder Laura Mather said she believes her company was targeted by criminals wielding Zeus specifically because o<br/><br/>75 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Trove of Hotmail Passwords Posted Online]]></title>
<link>http://bestofsecurity.net/blogs/Trove_of_Hotmail_Passwords_Posted_Online/</link>
<comments>http://bestofsecurity.net/blogs/Trove_of_Hotmail_Passwords_Posted_Online/</comments>
<pubDate>Mon, 05 Oct 2009 22:00:10 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Trove_of_Hotmail_Passwords_Posted_Online/</guid>
<description><![CDATA[If you use Microsoft's free Hotmail service, it may be time to change your password: Microsoft said Monday that several thousand Hotmail account credentials were posted online over the weekend. In a statement posted to its Windows Live Spaces blog, Microsoft said the company has determined that the data spill was not the result of a breach of internal Microsoft data, but rather was likely the haul from a phishing scheme. Microsoft said it is taking measures to block access to all of the accounts that were <br/><br/>153 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[DHS Seeking 1,000 Cyber Security Experts]]></title>
<link>http://bestofsecurity.net/blogs/DHS_Seeking_1000_Cyber_Security_Experts/</link>
<comments>http://bestofsecurity.net/blogs/DHS_Seeking_1000_Cyber_Security_Experts/</comments>
<pubDate>Thu, 01 Oct 2009 14:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/DHS_Seeking_1000_Cyber_Security_Experts/</guid>
<description><![CDATA[The Department of Homeland Security is poised to go on a geek hiring spree. DHS Secretary Janet Napolitano announced Thursday that the agency has been cleared to hire at least 1,000 new cybersecurity professionals over the next three years to fill staffing gaps at various DHS agencies. &quot;This new hiring authority will enable DHS to recruit the best cyber analysts, developers and engineers in the world to serve their country by leading the nation's defenses against cyber threats,&quot; Napolitano said. According <br/><br/>62 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hackers Breach Payroll Giant, Target Customers]]></title>
<link>http://bestofsecurity.net/blogs/Hackers_Breach_Payroll_Giant_Target_Customers/</link>
<comments>http://bestofsecurity.net/blogs/Hackers_Breach_Payroll_Giant_Target_Customers/</comments>
<pubDate>Wed, 30 Sep 2009 22:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Hackers_Breach_Payroll_Giant_Target_Customers/</guid>
<description><![CDATA[Hackers last week apparently used stolen account information from a New Jersey company that provides online payroll services to target the firm's customers in a scheme to steal passwords and other information. Morrestown, N.J. based PayChoice, provides direct payroll processing services and licenses its online employee payroll management product to at least 240 other payroll processing firms, serving 125,000 organizations. Last Wednesday, a number of PayChoice customers received an e-mail warning them that<br/><br/>102 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Stress Testing Microsoft's Free Anti-virus Offering]]></title>
<link>http://bestofsecurity.net/blogs/Stress_Testing_Microsofts_Free_Anti-virus_Offering/</link>
<comments>http://bestofsecurity.net/blogs/Stress_Testing_Microsofts_Free_Anti-virus_Offering/</comments>
<pubDate>Wed, 30 Sep 2009 10:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Stress_Testing_Microsofts_Free_Anti-virus_Offering/</guid>
<description><![CDATA[Microsoft's free new anti-virus product is earning decent marks in preliminary tests, putting it roughly on par with many other stand-alone anti-virus products available today. A number of readers seem keen to try out Microsoft Security Essentials (MSE), but are eager to hear how the program stacks up against other free anti-virus tools in terms of detecting and removing malware. While the results of early testing may not provide that side-by-side comparison, they do offer a glimpse of how effective MSE ma<br/><br/>171 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft's Free Anti-virus Tool Now Available]]></title>
<link>http://bestofsecurity.net/blogs/Microsofts_Free_Anti-virus_Tool_Now_Available/</link>
<comments>http://bestofsecurity.net/blogs/Microsofts_Free_Anti-virus_Tool_Now_Available/</comments>
<pubDate>Tue, 29 Sep 2009 14:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Microsofts_Free_Anti-virus_Tool_Now_Available/</guid>
<description><![CDATA[Windows users looking for a free anti-virus alternative can now take advantage of an offering from Microsoft, which today began offering its Security Essentials anti-virus program. Microsoft Security Essentials is a real-time and on-demand anti-virus scanner that is free for personal use. It runs on Windows XP, Windows Vista, and Windows 7 (both 32-bit and 64-bit versions). Note that in order to use this software, Windows users will first need to pass Microsoft's Genuine Validation (anti-piracy) check, whi<br/><br/>77 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[BruCon 2009 - Brussels Security Conference]]></title>
<link>http://bestofsecurity.net/blogs/BruCon_2009_-_Brussels_Security_Conference/</link>
<comments>http://bestofsecurity.net/blogs/BruCon_2009_-_Brussels_Security_Conference/</comments>
<pubDate>Mon, 28 Sep 2009 22:00:19 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/BruCon_2009_-_Brussels_Security_Conference/</guid>
<description><![CDATA[I recently returned from presenting at BruCon 2009 and wanted to give everyone a quick recap of my trip. This was officially the first BruCon, but the organizers did such a professional job that it ran like a seasoned conference. I was thoroughly impressed by the venue, setup, motivation from the volunteers, and the speakers. Here is a list of the talks with a summary of those speakers whose presentations I especially enjoyed attending:<br/><br/>204 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Featured Advertiser]]></title>
<link>http://bestofsecurity.net/blogs/Featured_Advertiser-9/</link>
<comments>http://bestofsecurity.net/blogs/Featured_Advertiser-9/</comments>
<pubDate>Mon, 28 Sep 2009 18:00:19 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Featured_Advertiser-9/</guid>
<description><![CDATA[<br/><br/>159 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[New IRS Scam E-mail Could Be Costly]]></title>
<link>http://bestofsecurity.net/blogs/New_IRS_Scam_E-mail_Could_Be_Costly/</link>
<comments>http://bestofsecurity.net/blogs/New_IRS_Scam_E-mail_Could_Be_Costly/</comments>
<pubDate>Mon, 28 Sep 2009 18:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/New_IRS_Scam_E-mail_Could_Be_Costly/</guid>
<description><![CDATA[The Department of Homeland Security's Computer Emergency Readiness Team is warning Internet users to be on guard against a convincing e-mail virus scam disguised as a message from auditors at the Internal Revenue Service. According to one victim interviewed by Security Fix, falling for the ruse could cost you or your employer tens of thousand of dollars. An alert issued Monday by the U.S.-CERT states: &quot;The attacks arrive via an unsolicited email message and may contain a subject line of 'Notice of Underrep<br/><br/>95 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[iPhone Blackhat SEO Poisoning Leads to Total Security Rogue Antivirus]]></title>
<link>http://bestofsecurity.net/blogs/iPhone_Blackhat_SEO_Poisoning_Leads_to_Total_Security_Rogue_Antivirus/</link>
<comments>http://bestofsecurity.net/blogs/iPhone_Blackhat_SEO_Poisoning_Leads_to_Total_Security_Rogue_Antivirus/</comments>
<pubDate>Mon, 28 Sep 2009 14:00:29 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/iPhone_Blackhat_SEO_Poisoning_Leads_to_Total_Security_Rogue_Antivirus/</guid>
<description><![CDATA[Websense Security Labs(TM) ThreatSeeker Network has detected that Google searches on terms related to iPhone SMS information are returning results that lead to Rogue Antivirus software. The Apple iPhone is one of the most popular smart phones on the market, and it's quite typical for users to google for information relating to SMS and other features of the iPhone.When Google is used to search for terms related to iPhone SMS information, malicious URLs are returned as high as the sixth result. When a user c<br/><br/>119 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Cyber Gangs Hit Healthcare Providers]]></title>
<link>http://bestofsecurity.net/blogs/Cyber_Gangs_Hit_Healthcare_Providers/</link>
<comments>http://bestofsecurity.net/blogs/Cyber_Gangs_Hit_Healthcare_Providers/</comments>
<pubDate>Mon, 28 Sep 2009 14:00:19 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Cyber_Gangs_Hit_Healthcare_Providers/</guid>
<description><![CDATA[Organized cyber thieves that have stolen millions from corporations and schools over the past few months recently defrauded several health care providers, including a number of non-profit organizations that cater to the disabled and the uninsured. The victims are the latest casualties of an online crime wave being perpetrated against U.S.-based organizations at the hands of cyber thieves thought to be based out of Eastern Europe. On Sept. 9, crooks stole $30,000 from the Evergreen Children's Association (c<br/><br/>143 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Don't Get Web 2.0wned]]></title>
<link>http://bestofsecurity.net/blogs/Dont_Get_Web_2-0wned/</link>
<comments>http://bestofsecurity.net/blogs/Dont_Get_Web_2-0wned/</comments>
<pubDate>Fri, 25 Sep 2009 02:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Dont_Get_Web_2-0wned/</guid>
<description><![CDATA[A recent attack in which tainted banner ads served up rogue software for visitors of popular sites such as drudgereport.com, lyrics.com and horoscope.com is a stark reminder of the importance of keeping up-to-date on software patches. According to Web vulnerability scanning firm ScanSafe, between Sept. 19 and 21, tainted ads that tried to foist malicious software cycled through some of the Web's most popular destinations (drudgereport.com receives more a million visitors per day, according to compete.com).<br/><br/>106 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA['Money Mule' Recruitment Network Exposed]]></title>
<link>http://bestofsecurity.net/blogs/Money_Mule_Recruitment_Network_Exposed/</link>
<comments>http://bestofsecurity.net/blogs/Money_Mule_Recruitment_Network_Exposed/</comments>
<pubDate>Thu, 24 Sep 2009 14:00:18 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Money_Mule_Recruitment_Network_Exposed/</guid>
<description><![CDATA[In a blog post earlier this week, Security Fix examined the crucial role of &quot;money mules&quot; -- people in the United States who are willingly or unwittingly recruited to help cyber fraudsters steal money from businesses. In this column, we'll peer a bit deeper into how mules are recruited, and how they often communicate with their employers. Security Fix interviewed one of the mules hired to receive money from Sanford School District, a small school system in Colorado that was robbed of $117,000 last month wh<br/><br/>92 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Maine Firm Sues Bank After $588,000 Cyber Heist]]></title>
<link>http://bestofsecurity.net/blogs/Maine_Firm_Sues_Bank_After_588000_Cyber_Heist/</link>
<comments>http://bestofsecurity.net/blogs/Maine_Firm_Sues_Bank_After_588000_Cyber_Heist/</comments>
<pubDate>Wed, 23 Sep 2009 14:00:17 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Maine_Firm_Sues_Bank_After_588000_Cyber_Heist/</guid>
<description><![CDATA[A construction firm in Maine is suing a local bank after cyber thieves stole more than a half million dollars from the company in a sophisticated online bank heist. On Friday, Sanford, Maine based Patco Construction Co. filed suit in York County Superior Court against Ocean Bank, a division of Bridgeport, Conn. based People's United Bank. The lawsuit alleges that Ocean Bank did not do enough to prevent cyber crooks from transferring approximately $588,000 to dozens of co-conspirators throughout the United <br/><br/>57 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft Issues Stopgap Fix for Windows Flaw]]></title>
<link>http://bestofsecurity.net/blogs/Microsoft_Issues_Stopgap_Fix_for_Windows_Flaw/</link>
<comments>http://bestofsecurity.net/blogs/Microsoft_Issues_Stopgap_Fix_for_Windows_Flaw/</comments>
<pubDate>Tue, 22 Sep 2009 14:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Microsoft_Issues_Stopgap_Fix_for_Windows_Flaw/</guid>
<description><![CDATA[Microsoft this week released a stopgap security fix for a critical flaw present in some Windows PCs that could let attackers remotely seize control of vulnerable systems. But as scary as this vulnerability sounds, it may actually be better for some Vista users to wait until Microsoft issues an official update. Microsoft issued the emergency workaround after reports that security researchers were publishing proof-of-concept exploits that attackers might use to figure out how to attack the flaw. The workarou<br/><br/>117 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Rogue Anti-virus SEO Poisoning: Kanye West, Taylor Swift, Obama, Annie Le]]></title>
<link>http://bestofsecurity.net/blogs/Rogue_Anti-virus_SEO_Poisoning_Kanye_West_Taylor_Swift_Obama_Annie_Le/</link>
<comments>http://bestofsecurity.net/blogs/Rogue_Anti-virus_SEO_Poisoning_Kanye_West_Taylor_Swift_Obama_Annie_Le/</comments>
<pubDate>Wed, 16 Sep 2009 18:00:46 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Rogue_Anti-virus_SEO_Poisoning_Kanye_West_Taylor_Swift_Obama_Annie_Le/</guid>
<description><![CDATA[SEO poisoning is fast becoming a trend in spreading rogue anti-virus software. This type of attack coupled with relevant news items that might be of interest to users from all walks of life is a lethal combination. Search terms related to the recent MTV Video Music Awards brouhaha and President Obama's off-the-record comments about Kanye West, as well as updates on murdered Yale graduate student Annie Le, are the latest targets.<br/><br/>199 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Data Breach Highlights Role Of &quot;Money Mules&quot;]]></title>
<link>http://bestofsecurity.net/blogs/Data_Breach_Highlights_Role_Of_Money_Mules/</link>
<comments>http://bestofsecurity.net/blogs/Data_Breach_Highlights_Role_Of_Money_Mules/</comments>
<pubDate>Wed, 16 Sep 2009 06:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Data_Breach_Highlights_Role_Of_Money_Mules/</guid>
<description><![CDATA[On Friday, Brunswick, Maine-based heating and hardware firm Downeast Energy &amp; Building Supply sent a letter notifying at least 850 customers that the company had suffered a data breach. Downeast sent the notice after discovering that hackers had broken in and stolen more than $200,000 from the company's online bank account. The attack on Downeast Energy bears all the hallmarks of online thieves who have stolen millions from dozens of other businesses, schools and counties over the past several months. In e<br/><br/>118 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Websense Security Labs report - State of Internet Security, Q1-Q2 2009]]></title>
<link>http://bestofsecurity.net/blogs/Websense_Security_Labs_report_-_State_of_Internet_Security_Q1-Q2_2009/</link>
<comments>http://bestofsecurity.net/blogs/Websense_Security_Labs_report_-_State_of_Internet_Security_Q1-Q2_2009/</comments>
<pubDate>Tue, 15 Sep 2009 14:00:22 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Websense_Security_Labs_report_-_State_of_Internet_Security_Q1-Q2_2009/</guid>
<description><![CDATA[Today, Websense released its biannual &quot;State of the Internet&quot; report, a deep dive into the most significant threats on the Internet during the first half of 2009. Today, most threats to information security are leading to the Web -- either using the Internet as the attack vector, or simply the route through which stolen, confidential data is transmitted.<br/><br/>168 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Cyber Crooks Target Public &amp; Private Schools]]></title>
<link>http://bestofsecurity.net/blogs/Cyber_Crooks_Target_Public__Private_Schools/</link>
<comments>http://bestofsecurity.net/blogs/Cyber_Crooks_Target_Public__Private_Schools/</comments>
<pubDate>Mon, 14 Sep 2009 06:00:22 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Cyber_Crooks_Target_Public__Private_Schools/</guid>
<description><![CDATA[A gang of organized cyber criminals that has stolen millions from businesses across the United States over the past month appears to have turned its sights on public schools and universities. On the morning of Aug. 17, hackers who had broken into computers at the Sanford School District in tiny Sanford, Colorado initiated a batch of bogus transfers out of the school's payroll account. Each of the transfers was kept just below $10,000 to avoid banks' anti-money laundering reporting requirements, and went ou<br/><br/>146 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Patches for Macs, and Advice for Mac Users]]></title>
<link>http://bestofsecurity.net/blogs/Patches_for_Macs_and_Advice_for_Mac_Users/</link>
<comments>http://bestofsecurity.net/blogs/Patches_for_Macs_and_Advice_for_Mac_Users/</comments>
<pubDate>Mon, 14 Sep 2009 02:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Patches_for_Macs_and_Advice_for_Mac_Users/</guid>
<description><![CDATA[Apple last week released Mac OS X 10.6.1, the first security update for Snow Leopard users. Cupertino also issued a bundle of updates to fix more than 30 security flaws in its 10.4 and 10.5 OS X and OS X Server systems. Snow Leopard shipped with an outdated and insecure version of the Adobe Flash Player. The 10.6.1 update fixes that, patching at least nine vulnerabilities in Flash, and bringing the Snow Leopard Flash plug-in up to date with the current 10.0.32.18 version. The Tiger and Leopard security bun<br/><br/>150 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Clamping Down on the 'Clampi' Trojan]]></title>
<link>http://bestofsecurity.net/blogs/Clamping_Down_on_the_Clampi_Trojan/</link>
<comments>http://bestofsecurity.net/blogs/Clamping_Down_on_the_Clampi_Trojan/</comments>
<pubDate>Fri, 11 Sep 2009 06:00:56 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Clamping_Down_on_the_Clampi_Trojan/</guid>
<description><![CDATA[Finding the notorious Clampi banking Trojan on a computer inside your network is a little like spotting a single termite crawling into a crack in the wall: Chances are, the unwelcome little intruder is part of a much larger infestation. At least, that's the story told by two businesses which recently discovered Clampi infections, compromises that handed organized cyber gangs the access they needed to steal tens of thousands of dollars. In early August, attackers used Clampi to swipe the online banking cred<br/><br/>182 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Updates Plug iPhone, QuickTime Security Holes]]></title>
<link>http://bestofsecurity.net/blogs/Updates_Plug_iPhone_QuickTime_Security_Holes/</link>
<comments>http://bestofsecurity.net/blogs/Updates_Plug_iPhone_QuickTime_Security_Holes/</comments>
<pubDate>Thu, 10 Sep 2009 10:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Updates_Plug_iPhone_QuickTime_Security_Holes/</guid>
<description><![CDATA[Apple has shipped a security update to fix multiple vulnerabilities in the iPhone and iPod Touch. The company also pushed out a patch to plug security holes in Windows and Mac versions of its QuickTime media player. The iPhone update -- version 3.1 -- includes at least 10 security fixes, and several minor new features, such as the ability to better organize apps in iTunes and to download ring tones wirelessly. Apple also issued an update for its iPod Touch (v. 3.1.1) that includes a short list of new featu<br/><br/>158 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Cyber Thieves Steal $447,000 From  Wrecking Firm]]></title>
<link>http://bestofsecurity.net/blogs/Cyber_Thieves_Steal_447000_From__Wrecking_Firm/</link>
<comments>http://bestofsecurity.net/blogs/Cyber_Thieves_Steal_447000_From__Wrecking_Firm/</comments>
<pubDate>Wed, 09 Sep 2009 22:00:09 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Cyber_Thieves_Steal_447000_From__Wrecking_Firm/</guid>
<description><![CDATA[Organized cyber thieves are increasingly looting businesses in heists that can net hundreds of thousands of dollars. Security vendors and pundits may be quick to suggest a new layer of technology to thwart such crimes, but in a great many cases, the virtual robbers are foiled because an alert observer spotted something amiss early on and raised a red flag. In mid-July, computer crooks stole $447,000 from Ferma Corp., a Santa Maria, Calif.-based demolition company, by initiating a large batch of transfers f<br/><br/>55 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Websense Joins The Cloud Security Alliance]]></title>
<link>http://bestofsecurity.net/blogs/Websense_Joins_The_Cloud_Security_Alliance/</link>
<comments>http://bestofsecurity.net/blogs/Websense_Joins_The_Cloud_Security_Alliance/</comments>
<pubDate>Wed, 09 Sep 2009 18:00:41 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Websense_Joins_The_Cloud_Security_Alliance/</guid>
<description><![CDATA[Earlier this month we officially joined the Cloud Security Alliance (http://www.cloudsecurityalliance.org/). The purpose of the CSA, as stated on the CSA Web site, is: &quot;To promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing.&quot;<br/><br/>91 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Wordpress Users, Are You Safe?]]></title>
<link>http://bestofsecurity.net/blogs/Wordpress_Users_Are_You_Safe/</link>
<comments>http://bestofsecurity.net/blogs/Wordpress_Users_Are_You_Safe/</comments>
<pubDate>Wed, 09 Sep 2009 14:00:23 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Wordpress_Users_Are_You_Safe/</guid>
<description><![CDATA[This is a cross post from the Defensio blog, by Carl MercierIf you are running an older version of Wordpress, meaning less than 2.8.4, you ABSOLUTELY want to read this. A worm that can post malware and spam to vulnerable Wordpress installations has recently been discovered in the wild and unless you're running the very latest version of Wordpress, you are at risk. Seriously at risk.<br/><br/>147 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Future Firefox to Nag Users on Insecure Plug-ins]]></title>
<link>http://bestofsecurity.net/blogs/Future_Firefox_to_Nag_Users_on_Insecure_Plug-ins/</link>
<comments>http://bestofsecurity.net/blogs/Future_Firefox_to_Nag_Users_on_Insecure_Plug-ins/</comments>
<pubDate>Wed, 09 Sep 2009 02:00:09 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Future_Firefox_to_Nag_Users_on_Insecure_Plug-ins/</guid>
<description><![CDATA[Mozilla says that the next version of Firefox will warn users if they are running insecure, outdated versions of the Adobe Flash Player, as part of a nascent effort to work with vendors of the most popular browser plug-ins to ensure users aren't falling behind on important security updates. Beginning with Firefox 3.5.3 and Firefox 3.0.14, Mozilla will warn users if their Flash plugin is out-of-date. Mozilla said it is starting with Flash because if its ubiquity, but also in response to recent studies showi<br/><br/>50 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft Fixes Eight Security Flaws]]></title>
<link>http://bestofsecurity.net/blogs/Microsoft_Fixes_Eight_Security_Flaws/</link>
<comments>http://bestofsecurity.net/blogs/Microsoft_Fixes_Eight_Security_Flaws/</comments>
<pubDate>Tue, 08 Sep 2009 14:00:17 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Microsoft_Fixes_Eight_Security_Flaws/</guid>
<description><![CDATA[Microsoft today pushed out software updates to plug at least eight critical security holes in computers powered by its various Windows operating systems. The patches are available through Windows Update or via Automatic Updates. The flaws were addressed in a bundle of five patches, each of which earned Microsoft's most dire &quot;critical&quot; rating, meaning they are serious enough that attackers could break into systems without any help from users. One particularly dangerous flaw covered by this month's patch bat<br/><br/>195 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[More Business Banking Victims Speak Out]]></title>
<link>http://bestofsecurity.net/blogs/More_Business_Banking_Victims_Speak_Out/</link>
<comments>http://bestofsecurity.net/blogs/More_Business_Banking_Victims_Speak_Out/</comments>
<pubDate>Fri, 04 Sep 2009 10:00:16 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/More_Business_Banking_Victims_Speak_Out/</guid>
<description><![CDATA[Since our story about Eastern European cyber crooks targeting small to mid-sized U.S. businesses ran last week, I've heard from a few more victims. Eerie similarities in their descriptions of how they were robbed suggest the bulk of this crime may be the work of one or two gangs. David Johnston, owner of Sign Designs, Inc., a Modesto, Calif.-based company that makes and installs electric signs, said his company lost nearly $100,000 on July 23, when crooks used the company's credentials to log in to its onl<br/><br/>165 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Apple Updates Java, Backdates Flash]]></title>
<link>http://bestofsecurity.net/blogs/Apple_Updates_Java_Backdates_Flash/</link>
<comments>http://bestofsecurity.net/blogs/Apple_Updates_Java_Backdates_Flash/</comments>
<pubDate>Thu, 03 Sep 2009 14:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Apple_Updates_Java_Backdates_Flash/</guid>
<description><![CDATA[Apple Thursday shipped an update to plug a slew of critical security holes in its version of Java for Leopard systems (OS X 10.5). In other Apple patch news, it appears those who have updated to the latest version of OS X -- 10.6/Snow Leopard -- received an insecure version of the Adobe Flash player. The Java update brings Mac's version of Java to 10.5 Update 5, and fixes at least 16 security flaws in the program. Users can grab the patch through Software Update or directly from Apple Software Downloads. M<br/><br/>145 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Rogue AV Goes Green]]></title>
<link>http://bestofsecurity.net/blogs/Rogue_AV_Goes_Green/</link>
<comments>http://bestofsecurity.net/blogs/Rogue_AV_Goes_Green/</comments>
<pubDate>Wed, 02 Sep 2009 14:00:27 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Rogue_AV_Goes_Green/</guid>
<description><![CDATA[Given the world's ever-increasing environmental concerns, it's easy to see why malware authors are monetizing via an eco-friendly strategy. Just as the scare tactics of rogue AVs have already taken their toll, yet another ingenious twist appears - this time resorting to a friendlier, &quot;greener&quot; tone.<br/><br/>196 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Featured Advertiser]]></title>
<link>http://bestofsecurity.net/blogs/Featured_Advertiser-8/</link>
<comments>http://bestofsecurity.net/blogs/Featured_Advertiser-8/</comments>
<pubDate>Wed, 02 Sep 2009 14:00:18 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Featured_Advertiser-8/</guid>
<description><![CDATA[<br/><br/>124 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[What To Do When Scareware Strikes]]></title>
<link>http://bestofsecurity.net/blogs/What_To_Do_When_Scareware_Strikes/</link>
<comments>http://bestofsecurity.net/blogs/What_To_Do_When_Scareware_Strikes/</comments>
<pubDate>Wed, 02 Sep 2009 14:00:17 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/What_To_Do_When_Scareware_Strikes/</guid>
<description><![CDATA[Mrs. Krebs and I were enjoying a relaxing, quiet morning last Saturday in our living room -- silently bonding with our respective laptops propped on our knees -- when she nearly jumped off of the sofa, shouting, &quot;Uh oh! It's one of those fake virus things popping up! WhatdoIdo!?!?&quot; It occurred to me as I reached for her computer that most people probably wouldn't know what to do should they stumble across a hacked or malicious site that tries to frighten and corral visitors into downloading and purchasing <br/><br/>141 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Getting Friended By Koobface]]></title>
<link>http://bestofsecurity.net/blogs/Getting_Friended_By_Koobface/</link>
<comments>http://bestofsecurity.net/blogs/Getting_Friended_By_Koobface/</comments>
<pubDate>Mon, 31 Aug 2009 18:00:18 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Getting_Friended_By_Koobface/</guid>
<description><![CDATA[You know you've attracted the attention of online troublemakers when they start using their malicious software to taunt you by name. Such is apparently the case with the latest version of Koobface, a worm that spreads on Facebook, Twitter and other Web 2.0 sites and turns infected systems into bots that can be used for a variety of improper and possibly criminal purposes. According to an analysis performed on the malware by researchers from the University of Alabama at Birmingham, the latest version refere<br/><br/>159 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Snow Leopard's Anti-Malware Feature]]></title>
<link>http://bestofsecurity.net/blogs/Snow_Leopards_Anti-Malware_Feature/</link>
<comments>http://bestofsecurity.net/blogs/Snow_Leopards_Anti-Malware_Feature/</comments>
<pubDate>Fri, 28 Aug 2009 17:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Snow_Leopards_Anti-Malware_Feature/</guid>
<description><![CDATA[Apple has long maintained that Mac users don't need to worry about viruses and other malicious software. So it's hardly surprising that many media outlets have seized upon revelations that Snow Leopard, the newest version of Apple's OS X operating system, detects and warns users about certain types of malicious software designed to attack Macs. Snow Leopard went on sale Friday and I haven't had a chance to fiddle with it yet (I'm hoping to tackle this over the weekend). By most accounts this anti-malware f<br/><br/>134 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Phishing Attacks on the Wane]]></title>
<link>http://bestofsecurity.net/blogs/Phishing_Attacks_on_the_Wane/</link>
<comments>http://bestofsecurity.net/blogs/Phishing_Attacks_on_the_Wane/</comments>
<pubDate>Thu, 27 Aug 2009 21:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Phishing_Attacks_on_the_Wane/</guid>
<description><![CDATA[Phishing attacks have fallen out of favor among cyber crooks who make a living stealing personal and financial information, according to a report released this week by IBM. Instead, attackers increasingly are using malicious Web links and password-stealing Trojan horse programs to filch information from victims, the company found. The analysis from X-Force, IBM's security research and development division, notes that Trojan horse programs are taking the place of phishing attacks aimed at financial targets.<br/><br/>64 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[U.K. Govt: Spammers Before Downloaders?]]></title>
<link>http://bestofsecurity.net/blogs/U-K-_Govt_Spammers_Before_Downloaders/</link>
<comments>http://bestofsecurity.net/blogs/U-K-_Govt_Spammers_Before_Downloaders/</comments>
<pubDate>Thu, 27 Aug 2009 09:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/U-K-_Govt_Spammers_Before_Downloaders/</guid>
<description><![CDATA[The British government plans to suspend the Internet accounts of residents suspected of downloading pirated music and films, according to news reports. But the latest figures on the geographic location spam-spewing zombie PCs suggest the U.K. government might do better to start by disconnecting the nation's most notorious uploaders. The Associated Press reports that plans announced Tuesday by the British Treasury Minister include blocking access to download sites, and temporarily suspending users' Internet<br/><br/>150 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Following the Injection - a0v.org]]></title>
<link>http://bestofsecurity.net/blogs/Following_the_Injection_-_a0v-org/</link>
<comments>http://bestofsecurity.net/blogs/Following_the_Injection_-_a0v-org/</comments>
<pubDate>Wed, 26 Aug 2009 17:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Following_the_Injection_-_a0v-org/</guid>
<description><![CDATA[We have been following the mass injection campaign that was reported last Friday. Websense Security Labs ThreatSeeker(TM) network also detected this threat, and Websense customers have been protected against it. We are interested in exploring these issues: What's been going on with this injection? What does it try to exploit, and how? In this blog we focus on the payload sites that follow the injection, to see where that takes us.<br/><br/>196 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft Expands Office Anti-Piracy Program]]></title>
<link>http://bestofsecurity.net/blogs/Microsoft_Expands_Office_Anti-Piracy_Program/</link>
<comments>http://bestofsecurity.net/blogs/Microsoft_Expands_Office_Anti-Piracy_Program/</comments>
<pubDate>Wed, 26 Aug 2009 13:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Microsoft_Expands_Office_Anti-Piracy_Program/</guid>
<description><![CDATA[Microsoft expanded its anti-piracy program this week, shipping a new software update that checks whether Office users are running a licensed or pirated version of the productivity suite. Windows users who have Automatic Updates turned on probably have by now noticed at least one new update available from Redmond. The patch represents the next phase of the Office Genuine Advantage (OGA) anti-piracy pilot program Microsoft launched last year. Microsoft says the update is being gradually rolled out to differe<br/><br/>67 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Businesses Reluctant to Report Online Banking Fraud]]></title>
<link>http://bestofsecurity.net/blogs/Businesses_Reluctant_to_Report_Online_Banking_Fraud/</link>
<comments>http://bestofsecurity.net/blogs/Businesses_Reluctant_to_Report_Online_Banking_Fraud/</comments>
<pubDate>Tue, 25 Aug 2009 05:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Businesses_Reluctant_to_Report_Online_Banking_Fraud/</guid>
<description><![CDATA[A confidential alert sent on Friday by a banking industry association to its members warns that Eastern European cyber gangs are stealing millions of dollars from small to mid-sizes businesses through online banking fraud. Unfortunately, many victimized companies are reluctant to come forward out of fear of retribution by their bank. According to the alert, sent by the Financial Services Information Sharing and Analysis Center (FS-ISAC), the victims of this type of fraud tell different stories, but the bas<br/><br/>171 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Tighter Security Urged for Businesses Banking Online]]></title>
<link>http://bestofsecurity.net/blogs/Tighter_Security_Urged_for_Businesses_Banking_Online/</link>
<comments>http://bestofsecurity.net/blogs/Tighter_Security_Urged_for_Businesses_Banking_Online/</comments>
<pubDate>Mon, 24 Aug 2009 17:00:07 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Tighter_Security_Urged_for_Businesses_Banking_Online/</guid>
<description><![CDATA[An industry group representing some of nation's largest banks sent a private alert to its members last week warning about a surge in reported cybercrime targeting small to mid-sized business. The advisory, issued by the Financial Services Information Sharing and Analysis Center, recommends that commercial banking customers take some fairly rigorous steps to secure their online banking accounts. For example, the group recommends that commercial banking customers &quot;carry out all online banking activity from a<br/><br/>53 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Malware Writers: Will That Be OS X, or W?]]></title>
<link>http://bestofsecurity.net/blogs/Malware_Writers_Will_That_Be_OS_X_or_W/</link>
<comments>http://bestofsecurity.net/blogs/Malware_Writers_Will_That_Be_OS_X_or_W/</comments>
<pubDate>Mon, 24 Aug 2009 09:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Malware_Writers_Will_That_Be_OS_X_or_W/</guid>
<description><![CDATA[Security researchers increasingly are finding that sites designed to trick the visitor into installing malicious software will serve different malware depending on whether the visitor arrives at the page using a Microsoft Windows PC or a Mac. Trend Micro researcher Ivan Macalintal recently found a new variant of the dreaded DNS changer Trojan that checks to see which operating system the visitor's Web browser appears to be riding on, and then offers the appropriate Windows- or Mac-based installer. The malw<br/><br/>160 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[TwitBlock Helps Root Out Spammy Followers]]></title>
<link>http://bestofsecurity.net/blogs/TwitBlock_Helps_Root_Out_Spammy_Followers/</link>
<comments>http://bestofsecurity.net/blogs/TwitBlock_Helps_Root_Out_Spammy_Followers/</comments>
<pubDate>Wed, 19 Aug 2009 21:00:09 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/TwitBlock_Helps_Root_Out_Spammy_Followers/</guid>
<description><![CDATA[Those of you who use Twitter know how quickly one can accumulate unknown &quot;followers,&quot; people who sign up to receive updates on their Twitter pages whenever you post a Tweet. Unfortunately, it's not uncommon to find that a number of those unknown followers aren't really people at all, but fake profiles designed to draw visitors away from your profile to adult Web sites and other dicey online destinations. A new service called TwitBlock makes this task of separating spam from fan an interesting and fun - if <br/><br/>188 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[TJX Hacker Indicted in Heartland, Hannaford Breaches]]></title>
<link>http://bestofsecurity.net/blogs/TJX_Hacker_Indicted_in_Heartland_Hannaford_Breaches/</link>
<comments>http://bestofsecurity.net/blogs/TJX_Hacker_Indicted_in_Heartland_Hannaford_Breaches/</comments>
<pubDate>Mon, 17 Aug 2009 13:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/TJX_Hacker_Indicted_in_Heartland_Hannaford_Breaches/</guid>
<description><![CDATA[A federal grand jury has indicted three individuals for allegedly hacking into credit and debit card payment processing giant Heartland Payment Systems last year, as part of an investigation the Justice Department is calling the largest identity theft case ever prosecuted. According to indictments returned Monday in a New Jersey federal court, the government believes the same individuals were involved in a string of high-profile data breaches between October 2006 and May 2008, including intrusions at Hanna<br/><br/>189 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Security Patch Catchup: Java, Safari &amp; OS X]]></title>
<link>http://bestofsecurity.net/blogs/Security_Patch_Catchup_Java_Safari__OS_X/</link>
<comments>http://bestofsecurity.net/blogs/Security_Patch_Catchup_Java_Safari__OS_X/</comments>
<pubDate>Mon, 17 Aug 2009 09:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Security_Patch_Catchup_Java_Safari__OS_X/</guid>
<description><![CDATA[Security Fix took a mini-vacation last week, but that's all it takes to fall behind in important software security updates. Here's a quick pointer to some recent updates that have recently happened. The last time I wrote about Java updates was at Update 13, but as several readers have pointed out, the latest version is now Update 16. Near as I could tell, Updates 14 and 16 did not include security updates. Indeed, Java maker Sun Microsystems says users who have Java SE 6 Update 15 have the latest security <br/><br/>168 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Mass Injection of Chinese College Web Sites]]></title>
<link>http://bestofsecurity.net/blogs/Mass_Injection_of_Chinese_College_Web_Sites/</link>
<comments>http://bestofsecurity.net/blogs/Mass_Injection_of_Chinese_College_Web_Sites/</comments>
<pubDate>Fri, 14 Aug 2009 05:00:10 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Mass_Injection_of_Chinese_College_Web_Sites/</guid>
<description><![CDATA[Recently, since Microsoft released information about new vulnerabilities in MS Office and DirectShow in July, attacks spreading through the infection of thousands of legitimate Web sites have increased sharply in the wild. Coinciding with the student recruitment period after the Chinese National College Entrance Examination, the Web sites of universities and some higher education institutions have become the major targets of attackers.<br/><br/>180 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft Fixes 19 Windows Security Flaws]]></title>
<link>http://bestofsecurity.net/blogs/Microsoft_Fixes_19_Windows_Security_Flaws/</link>
<comments>http://bestofsecurity.net/blogs/Microsoft_Fixes_19_Windows_Security_Flaws/</comments>
<pubDate>Tue, 11 Aug 2009 13:00:07 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Microsoft_Fixes_19_Windows_Security_Flaws/</guid>
<description><![CDATA[Microsoft today issued a raft of software updates to plug at least 19 security holes in its various Windows operating systems and other software, 15 of which earned the company's most dire &quot;critical&quot; rating. This month's batch of patches fix some fairly dangerous flaws. Redmond labels a security flaw &quot;critical&quot; if attackers could use it to seize control over a vulnerable system without any help from the victim. What's more, a dozen of the flaws earned the highest rating on Microsoft's &quot;exploitability index<br/><br/>159 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Keep Your Passwords Close and Your Password Secrets Closer]]></title>
<link>http://bestofsecurity.net/blogs/Keep_Your_Passwords_Close_and_Your_Password_Secrets_Closer/</link>
<comments>http://bestofsecurity.net/blogs/Keep_Your_Passwords_Close_and_Your_Password_Secrets_Closer/</comments>
<pubDate>Mon, 10 Aug 2009 21:00:10 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Keep_Your_Passwords_Close_and_Your_Password_Secrets_Closer/</guid>
<description><![CDATA[Bruce Schneier, over the years, has posted quite a number of blogs on password security. There are things we all know are common sense, yet we still break most of the fundamental rules.<br/><br/>189 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Russia-Georgia Conflict Blamed for Twitter, Facebook Outages]]></title>
<link>http://bestofsecurity.net/blogs/Russia-Georgia_Conflict_Blamed_for_Twitter_Facebook_Outages/</link>
<comments>http://bestofsecurity.net/blogs/Russia-Georgia_Conflict_Blamed_for_Twitter_Facebook_Outages/</comments>
<pubDate>Fri, 07 Aug 2009 09:00:05 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Russia-Georgia_Conflict_Blamed_for_Twitter_Facebook_Outages/</guid>
<description><![CDATA[The theories behind who and what attacked Twitter and Facebook yesterday -- causing intermittent outages at each -- are flying like so many tweets across the Internet. The prevailing theory suggests that the outage was due to a cyber skirmish stemming from simmering tensions between Russia and Georgia. CNet and CNN place blame for the incident on an elaborate, politically motivated vendetta timed to coincide with the one year anniversary of the Russia-Georgia war, a brief but costly skirmish in August 2008<br/><br/>179 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Patch Updates Coming to a Theater Near You]]></title>
<link>http://bestofsecurity.net/blogs/Patch_Updates_Coming_to_a_Theater_Near_You/</link>
<comments>http://bestofsecurity.net/blogs/Patch_Updates_Coming_to_a_Theater_Near_You/</comments>
<pubDate>Thu, 06 Aug 2009 17:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Patch_Updates_Coming_to_a_Theater_Near_You/</guid>
<description><![CDATA[Patches have been flowing in since last week, some for 0days found in the the wild, some for 0days disclosed at Black Hat presentations given last week. In this post, I'm going to focus mainly on vulnerabilities related to client-side browsers.<br/><br/>173 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hackers Target House.gov Sites]]></title>
<link>http://bestofsecurity.net/blogs/Hackers_Target_House-gov_Sites/</link>
<comments>http://bestofsecurity.net/blogs/Hackers_Target_House-gov_Sites/</comments>
<pubDate>Thu, 06 Aug 2009 13:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Hackers_Target_House-gov_Sites/</guid>
<description><![CDATA[Hackers broke into more than a dozen Web sites for members of the U.S. House of Representatives in the past week, replacing portions of their home pages with digital graffiti, according House officials. The landing pages at house.gov for Reps. Duncan Hunter (R-Calif.), Jesse L. Jackson, Jr. (D-Ill.), and Spencer Bachus (R-Ala.) were among at least 18 member pages that were defaced in a series of break-ins that apparently began earlier this month, according to zone-h.com, a site that archives evidence of We<br/><br/>147 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Researchers: XML Security Flaws are Pervasive]]></title>
<link>http://bestofsecurity.net/blogs/Researchers_XML_Security_Flaws_are_Pervasive/</link>
<comments>http://bestofsecurity.net/blogs/Researchers_XML_Security_Flaws_are_Pervasive/</comments>
<pubDate>Wed, 05 Aug 2009 13:00:06 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Researchers_XML_Security_Flaws_are_Pervasive/</guid>
<description><![CDATA[Security researchers today unveiled details about a little-known but ubiquitous class of vulnerabilities that may reside in a range of Internet components, from Web applications to mobile and cloud computing platforms to documents, images and instant messaging products. At issue are problems with the way many hardware and software makers handle data from an open standard called XML. Short for &quot;eXtensible Markup Language,&quot; XML has been used for many years as a fast and efficient way to transport, store and <br/><br/>93 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Featured Advertiser]]></title>
<link>http://bestofsecurity.net/blogs/Featured_Advertiser-7/</link>
<comments>http://bestofsecurity.net/blogs/Featured_Advertiser-7/</comments>
<pubDate>Tue, 04 Aug 2009 17:00:10 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Featured_Advertiser-7/</guid>
<description><![CDATA[<br/><br/>140 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Twitter Tries to Tame Tainted Links]]></title>
<link>http://bestofsecurity.net/blogs/Twitter_Tries_to_Tame_Tainted_Links/</link>
<comments>http://bestofsecurity.net/blogs/Twitter_Tries_to_Tame_Tainted_Links/</comments>
<pubDate>Tue, 04 Aug 2009 17:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Twitter_Tries_to_Tame_Tainted_Links/</guid>
<description><![CDATA[Faced with a recent surge in the number of malicious software programs using its micro-blogging service to spread, Twitter is making an effort to block users from posting links to known malicious Web sites. The initiative, first noted in a blog posting by Finnish anti-virus maker F-Secure Corp., involves the use of Google's Safe Browsing program, which the search giant uses to prevent Internet users from visiting Web sites that Google's bots have flagged for installing malicious software. &quot;Our Safety and S<br/><br/>101 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Security Updates for iPhone, Adobe Reader]]></title>
<link>http://bestofsecurity.net/blogs/Security_Updates_for_iPhone_Adobe_Reader/</link>
<comments>http://bestofsecurity.net/blogs/Security_Updates_for_iPhone_Adobe_Reader/</comments>
<pubDate>Tue, 04 Aug 2009 09:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Security_Updates_for_iPhone_Adobe_Reader/</guid>
<description><![CDATA[Apple has issued a security update for the iPhone. The patch fixes a vulnerability demonstrated recently at a hacker conference in Las Vegas, where security researchers showed they could hijack an iPhone simply by sending it a series of booby-trapped text messages. Apple's patch comes in response to research revealed at last week's Black Hat security conference, by well-known Apple hacker Charlie Miller and co-presenter Collin Mulliner, a Ph.D. student in telecommunications security at the Technical Univer<br/><br/>169 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Black Hat Conference Wrap-up]]></title>
<link>http://bestofsecurity.net/blogs/Black_Hat_Conference_Wrap-up/</link>
<comments>http://bestofsecurity.net/blogs/Black_Hat_Conference_Wrap-up/</comments>
<pubDate>Mon, 03 Aug 2009 21:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Black_Hat_Conference_Wrap-up/</guid>
<description><![CDATA[We just got back from Black Hat/Defcon and wanted to summarize some of the research highlights of this year's con. If you were following us on Twitter, we tweeted the presentations that we found interesting. We certainly were not the only ones taking advantage of micro-blogging at the con.<br/><br/>170 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Following the Money: Rogue Anti-virus Software]]></title>
<link>http://bestofsecurity.net/blogs/Following_the_Money_Rogue_Anti-virus_Software/</link>
<comments>http://bestofsecurity.net/blogs/Following_the_Money_Rogue_Anti-virus_Software/</comments>
<pubDate>Fri, 31 Jul 2009 13:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Following_the_Money_Rogue_Anti-virus_Software/</guid>
<description><![CDATA[By its very nature, the architecture and limited rules governing the Web make it difficult to track individuals who might be involved in improper activity. Cyber-sleuths often must navigate through a maze of dead-end records, pseudonyms or anonymous corporations, usually based overseas. The success rate is fairly low. Even if you manage to trace one link in the chain -- such as a payment processor or Web host -- the business or person involved claims that he or she was merely providing a legal service to a<br/><br/>89 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Critical Update for Adobe Flash Player]]></title>
<link>http://bestofsecurity.net/blogs/Critical_Update_for_Adobe_Flash_Player/</link>
<comments>http://bestofsecurity.net/blogs/Critical_Update_for_Adobe_Flash_Player/</comments>
<pubDate>Thu, 30 Jul 2009 21:00:06 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Critical_Update_for_Adobe_Flash_Player/</guid>
<description><![CDATA[Adobe Systems Inc. today issued a security update to its Flash player to plug at least a dozen security holes in the software, including some that hackers have been using in to break into vulnerable systems. The latest update brings Flash player to version 10.0.32.18. Updates are available for most Flash installations on Windows, Mac and Linux machines. To find out what version of Flash you have, visit this page. Adobe recommends users of Adobe AIR version 1.5.1 and earlier versions update to Adobe AIR 1.5<br/><br/>113 Vote(s) ]]></description>
</item>

</channel>
</rss>
