<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>viaForensics&#187; Security Archives  &#8211; viaForensics</title>
	<atom:link href="http://viaforensics.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://viaforensics.com</link>
	<description>innovative digital forensics and e-discovery</description>
	<lastBuildDate>Fri, 12 Mar 2010 13:39:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The Top 10 Enterprise Botnets &#8211; DarkReading</title>
		<link>http://viaforensics.com/security/the-top-10-enterprise-botnets-darkreading.html</link>
		<comments>http://viaforensics.com/security/the-top-10-enterprise-botnets-darkreading.html#comments</comments>
		<pubDate>Fri, 12 Mar 2010 13:39:50 +0000</pubDate>
		<dc:creator>lhaas</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Breaches]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1696</guid>
		<description><![CDATA[
			
				
			
		
Botnets are the most significant way that companies are having data stolen outside of employee theft. Services, such as viaForensic&#8217;s threatForensics, can help to identify botnets.
Four little-known botnets were behind half of all botnet infiltrations in enterprises last year &#8212; and the No. 1 botnet hitting corporate networks carried the infamous Zeus crimeware&#8230;.
Koobface overall had [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fthe-top-10-enterprise-botnets-darkreading.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fthe-top-10-enterprise-botnets-darkreading.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Botnets are the most significant way that companies are having data stolen outside of employee theft. Services, such as viaForensic&#8217;s threatForensics, can help to identify botnets.</p>
<blockquote><p>Four little-known botnets were behind half of all botnet infiltrations in enterprises last year &#8212; and the No. 1 botnet hitting corporate networks carried the infamous Zeus crimeware&#8230;.</p>
<p>Koobface overall had a surprisingly large representation. The worm, typically spread via social networks such as Facebook and MySpace, was the main malware carried by two additional botnets, Koobface.D (5 percent) and Koobface.C (4 percent). The malware was used as a foot in the door to hijack corporate users&#8217; accounts and to spread among other systems within the organization, according to Gunter Ollmann, vice president of research for Damballa.</p></blockquote>
<p>via <a href="http://www.darkreading.com/insiderthreat/security/client/showArticle.jhtml?articleID=222900762&amp;cid=RSSfeed" rel="nofollow" >The Top 10 Enterprise Botnets &#8211; DarkReading</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fthe-top-10-enterprise-botnets-darkreading.html&amp;linkname=The%20Top%2010%20Enterprise%20Botnets%20%26%238211%3B%20DarkReading"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/security/the-top-10-enterprise-botnets-darkreading.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Experts reboot list of 25 most dangerous coding errors • The Register</title>
		<link>http://viaforensics.com/security/experts-reboot-list-of-25-most-dangerous-coding-errors-%e2%80%a2-the-register.html</link>
		<comments>http://viaforensics.com/security/experts-reboot-list-of-25-most-dangerous-coding-errors-%e2%80%a2-the-register.html#comments</comments>
		<pubDate>Thu, 11 Mar 2010 15:14:37 +0000</pubDate>
		<dc:creator>lhaas</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Breaches]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1692</guid>
		<description><![CDATA[
			
				
			
		
Companies are not paying enough attention to security. Even if all the usual security mechanisms are in place, there is still no way to avoid all the danger. As this Register article states: &#8220;25 [programming] flaws are the cause of almost every major cyber attack in recent history.&#8221; One approach is to hold the developers [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fexperts-reboot-list-of-25-most-dangerous-coding-errors-%25e2%2580%25a2-the-register.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fexperts-reboot-list-of-25-most-dangerous-coding-errors-%25e2%2580%25a2-the-register.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Companies are not paying enough attention to security. Even if all the usual security mechanisms are in place, there is still no way to avoid all the danger. As this <em>Register</em> article states: &#8220;25 [programming] flaws are the cause of almost every major cyber attack in recent history.&#8221; One approach is to hold the developers responsible. Another is for companies to take the initiative to employ additional security (i.e. threatForensics).</p>
<blockquote><p>Computer experts from some 30 organizations worldwide have once again compiled a list of the 25 most dangerous programming errors along with a novel way to prevent them: by drafting contracts that hold developers responsible when bugs creep into applications&#8230;.</p>
<p>The 25 flaws are the cause of almost every major cyber attack in recent history, including the ones that recently struck Google and 33 other large companies, as well as breaches suffered by military systems and millions of small business and home users&#8230;.</p>
<p>As a customer, you have the power to influence vendors to provide more secure products by letting them know that security is important to you,&#8221; the introduction to Tuesday&#8217;s list states.</p></blockquote>
<p>via <a href="http://www.theregister.co.uk/2010/02/17/top_25_programming_errors/" rel="nofollow" >Experts reboot list of 25 most dangerous coding errors • The Register</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fexperts-reboot-list-of-25-most-dangerous-coding-errors-%25e2%2580%25a2-the-register.html&amp;linkname=Experts%20reboot%20list%20of%2025%20most%20dangerous%20coding%20errors%20%E2%80%A2%20The%20Register"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/security/experts-reboot-list-of-25-most-dangerous-coding-errors-%e2%80%a2-the-register.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>State Of Application Security: Nearly 60 Percent Of Apps Fail First Security Test &#8211; DarkReading</title>
		<link>http://viaforensics.com/security/state-application-security-60-percent-apps-fail-security-test-darkreading.html</link>
		<comments>http://viaforensics.com/security/state-application-security-60-percent-apps-fail-security-test-darkreading.html#comments</comments>
		<pubDate>Wed, 03 Mar 2010 19:32:23 +0000</pubDate>
		<dc:creator>lhaas</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Breaches]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1673</guid>
		<description><![CDATA[
			
				
			
		
Application security may still have a ways to go, but Open Source is showing promise&#8230;
Despite the relatively gloomy picture of developers still missing the mark initially on security, there were some bright spots in the report: Open-source software isn&#8217;t as risky as you&#8217;d think, and financial services organizations and government agencies tend to have more [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fstate-application-security-60-percent-apps-fail-security-test-darkreading.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fstate-application-security-60-percent-apps-fail-security-test-darkreading.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Application security may still have a ways to go, but Open Source is showing promise&#8230;</p>
<blockquote><p>Despite the relatively gloomy picture of developers still missing the mark initially on security, there were some bright spots in the report: Open-source software isn&#8217;t as risky as you&#8217;d think, and financial services organizations and government agencies tend to have more secure applications from the get-go; more than half of their apps passed as acceptable in the first submission to testing, according to Veracode&#8217;s report.</p>
<p>&#8220;The conventional wisdom is that open source is risky. But open source was no worse than commercial software upon first submission. That&#8217;s encouraging,&#8221; Oberg says. And it was the quickest to remediate any flaws: &#8220;It took about 30 days to remediate open-source software, and much longer for commercial and internal projects,&#8221; he says.</p></blockquote>
<p>via <a href="http://www.darkreading.com/vulnerability_management/security/app-security/showArticle.jhtml?articleID=223100875" rel="nofollow" >State Of Application Security: Nearly 60 Percent Of Apps Fail First Security Test &#8211; DarkReading</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fstate-application-security-60-percent-apps-fail-security-test-darkreading.html&amp;linkname=State%20Of%20Application%20Security%3A%20Nearly%2060%20Percent%20Of%20Apps%20Fail%20First%20Security%20Test%20%26%238211%3B%20DarkReading"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/security/state-application-security-60-percent-apps-fail-security-test-darkreading.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Law.com &#8211; Step 1 for Legal Holds: Trigger Events</title>
		<link>http://viaforensics.com/computer-forensics/lawcom-step-1-legal-holds-trigger-events.html</link>
		<comments>http://viaforensics.com/computer-forensics/lawcom-step-1-legal-holds-trigger-events.html#comments</comments>
		<pubDate>Mon, 01 Mar 2010 15:51:43 +0000</pubDate>
		<dc:creator>lhaas</dc:creator>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1669</guid>
		<description><![CDATA[
			
				
			
		
A recent article on Law.com (part one of a seven part series) discusses the importance of legal holds for the preservation of electronically stored information (ESI) and other documents.
Why are courts placing so much emphasis on this ministerial step in preservation of issuing a written litigation hold? It appears that patience is running thin for [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensics%2Flawcom-step-1-legal-holds-trigger-events.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensics%2Flawcom-step-1-legal-holds-trigger-events.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>A recent article on Law.com (part one of a seven part series) discusses the importance of legal holds for the preservation of electronically stored information (ESI) and other documents.</p>
<blockquote><p>Why are courts placing so much emphasis on this ministerial step in preservation of issuing a written litigation hold? It appears that patience is running thin for lost ESI in federal court. More importantly, ignorance of litigation hold requirements is no excuse. Also, the days of he-said-she-said litigation hold arguments are numbered. Courts want to see a transparent and credible process by simply looking at a few documents such as the written hold notice, distribution list, follow-up interview reports or logs, as examples.</p>
<p>As articulated by Judge Scheindlin in Pension Committee v. Banc of America, courts definitely do not want to wade through stacks of motions papers and days of hearings to determine if preservation efforts were sufficient to prevent the destruction of ESI and other documents. As a result, it is imperative for an organization to have in place a litigation hold policy and adequate procedures necessary to avoid going down the litigation &#8220;detour&#8221; of discovery sanctions motions.</p></blockquote>
<p>via <a href="http://www.law.com/jsp/PubArticle.jsp?id=1202444383053" rel="nofollow" >Law.com &#8211; Step 1 for Legal Holds: Trigger Events</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensics%2Flawcom-step-1-legal-holds-trigger-events.html&amp;linkname=Law.com%20%26%238211%3B%20Step%201%20for%20Legal%20Holds%3A%20Trigger%20Events"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensics/lawcom-step-1-legal-holds-trigger-events.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spike In Power Grid Attacks Likely In Next 12 Months &#8211; DarkReading</title>
		<link>http://viaforensics.com/security/spike-in-power-grid-attacks-likely-in-next-12-months-darkreading.html</link>
		<comments>http://viaforensics.com/security/spike-in-power-grid-attacks-likely-in-next-12-months-darkreading.html#comments</comments>
		<pubDate>Wed, 24 Feb 2010 20:57:44 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1637</guid>
		<description><![CDATA[
			
				
			
		
This is an interesting and evolving area.  Many of these devices run embedded OS with flash memory so traditional forensic techniques do not work.  However, the Android platform (and other mobile platforms) have similar characteristics and thus the R&#38;D in those areas can be applied to embedded devices.    Moral of the story: if it [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fspike-in-power-grid-attacks-likely-in-next-12-months-darkreading.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fspike-in-power-grid-attacks-likely-in-next-12-months-darkreading.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>This is an interesting and evolving area.  Many of these devices run embedded OS with flash memory so traditional forensic techniques do not work.  However, the Android platform (and other mobile platforms) have similar characteristics and thus the R&amp;D in those areas can be applied to embedded devices.    Moral of the story: if it has data storage or network activity, you&#8217;ll find a forensic geek poking around somewhere close by (hint: contact us if you want to discuss):</p>
<blockquote><p>Attacks against the power grid are likely to rise and intensify during the next 12 months as smart grid research and pilot projects advance, according to utility security experts and a recently published report that analyzes threats to critical infrastructure.</p>
<p>The so-called Project Grey Goose Report on Critical Infrastructure points to state and/or non-state sponsored hackers from the Russian Federation of Independent States, Turkey, and China as the main threats to targeting and hacking into energy providers and other critical infrastructure networks.</p></blockquote>
<p>via <a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=223000369&amp;cid=RSSfeed" rel="nofollow" >Spike In Power Grid Attacks Likely In Next 12 Months &#8211; DarkReading</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fspike-in-power-grid-attacks-likely-in-next-12-months-darkreading.html&amp;linkname=Spike%20In%20Power%20Grid%20Attacks%20Likely%20In%20Next%2012%20Months%20%26%238211%3B%20DarkReading"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/security/spike-in-power-grid-attacks-likely-in-next-12-months-darkreading.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Adobe Reader and Acrobat Vulnerability &#8211; Adobe Product Security Incident Response Team (PSIRT)</title>
		<link>http://viaforensics.com/security/new-adobe-reader-and-acrobat-vulnerability-adobe-product-security-incident-response-team-psirt.html</link>
		<comments>http://viaforensics.com/security/new-adobe-reader-and-acrobat-vulnerability-adobe-product-security-incident-response-team-psirt.html#comments</comments>
		<pubDate>Mon, 21 Dec 2009 13:11:58 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1394</guid>
		<description><![CDATA[
			
				
			
		
Ahhh, nothing like the weekly Adobe zero-day exploit.
This afternoon, Adobe received reports of a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions being exploited in the wild (CVE-2009-4324). We are currently investigating this issue and assessing the risk to our customers. We will provide an update as soon as we have more information. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fnew-adobe-reader-and-acrobat-vulnerability-adobe-product-security-incident-response-team-psirt.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fnew-adobe-reader-and-acrobat-vulnerability-adobe-product-security-incident-response-team-psirt.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Ahhh, nothing like the weekly Adobe zero-day exploit.</p>
<blockquote><p>This afternoon, Adobe received reports of a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions being exploited in the wild (CVE-2009-4324). We are currently investigating this issue and assessing the risk to our customers. We will provide an update as soon as we have more information. Please continue monitoring the Adobe PSIRT blog for the latest information.</p></blockquote>
<p>via <a href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html" rel="nofollow" >New Adobe Reader and Acrobat Vulnerability &#8211; Adobe Product Security Incident Response Team (PSIRT)</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fnew-adobe-reader-and-acrobat-vulnerability-adobe-product-security-incident-response-team-psirt.html&amp;linkname=New%20Adobe%20Reader%20and%20Acrobat%20Vulnerability%20%26%238211%3B%20Adobe%20Product%20Security%20Incident%20Response%20Team%20%28PSIRT%29"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/security/new-adobe-reader-and-acrobat-vulnerability-adobe-product-security-incident-response-team-psirt.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bit9 Releases Annual Report on Top Vulnerable Applications in 2009</title>
		<link>http://viaforensics.com/security/bit9-releases-annual-report-on-top-vulnerable-applications-in-2009.html</link>
		<comments>http://viaforensics.com/security/bit9-releases-annual-report-on-top-vulnerable-applications-in-2009.html#comments</comments>
		<pubDate>Mon, 21 Dec 2009 12:54:19 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1390</guid>
		<description><![CDATA[
			
				
			
		
Well, it&#8217;s nice to see Adobe at the top of the list given all the 0-day exploits.  Bit9 seems to do great work but the white paper is behind a registration firewall (they should just release it, trust me, it&#8217;s better that way).  Here&#8217;s the results from the press release:
This year Adobe applications top the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fbit9-releases-annual-report-on-top-vulnerable-applications-in-2009.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fbit9-releases-annual-report-on-top-vulnerable-applications-in-2009.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Well, it&#8217;s nice to see Adobe at the top of the list given all the 0-day exploits.  Bit9 seems to do great work but the white paper is behind a <a href="http://www.bit9.com/landing/vulnapps2009/" rel="nofollow" title="Bit9 top vulnerable apps in 2009" >registration firewall</a> (they should just release it, trust me, it&#8217;s better that way).  Here&#8217;s the results from the press release:</p>
<blockquote><p>This year Adobe applications top the list with four applications identified in the U.S. National Institute of Standards and Technology&amp;apos;s (NIST) official vulnerability database:</p>
<ul>
<li>Adobe Acrobat</li>
<li>Flash Player</li>
<li>Reader</li>
<li>Shockwave</li>
</ul>
<p>had vulnerabilities that were rated &#8220;High&#8221; including ones that allowed remote attackers to execute arbitrary code, trigger memory corruption, denial of services or application crashing.</p>
<p>Other vulnerable applications on the list include:</p>
<p>* Apple Quicktime</p>
<p>* Mozilla Firefox</p>
<p>* Opera</p>
<p>* RealPlayer</p>
<p>* Sun Java</p>
<p>* Trillian</p>
<p>The applications on the list meet the following criteria:</p>
<p>* Runs on Microsoft Windows</p>
<p>* Is well-known in the consumer space and frequently downloaded by individuals</p>
<p>* Is not classified as malicious by enterprise IT organizations or security vendors</p>
<p>* Contains at least one critical vulnerability that was:</p>
<p>o First reported in January 2009 or after</p>
<p>o Registered in the U.S. National Institute of Standards and Technology&amp;apos;s (NIST) official vulnerability database at http://nvd.nist.gov, and given a severity rating of high (between 7.0-10.0) on the Common Vulnerability Scoring System (CVSS)</p>
<p>o Relies on the end user, rather than a central IT administrator, to manually patch or upgrade the software to eliminate the vulnerability, if such a patch exists</p>
<p>o The application cannot be automatically and centrally updated via Enterprise tools such as Microsoft SMS &amp; WSUS.</p></blockquote>
<p>via <a href="http://www.prnewswire.com/news-releases/bit9-releases-annual-report-on-top-vulnerable-applications-in-2009-79401757.html" rel="nofollow" >Bit9 Releases Annual Report on Top Vulnerable Applications in 2009</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fbit9-releases-annual-report-on-top-vulnerable-applications-in-2009.html&amp;linkname=Bit9%20Releases%20Annual%20Report%20on%20Top%20Vulnerable%20Applications%20in%202009"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/security/bit9-releases-annual-report-on-top-vulnerable-applications-in-2009.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I Was Wrong: There Probably Will Be an Electronic Pearl Harbor</title>
		<link>http://viaforensics.com/security/i-was-wrong-there-probably-will-be-an-electronic-pearl-harbor.html</link>
		<comments>http://viaforensics.com/security/i-was-wrong-there-probably-will-be-an-electronic-pearl-harbor.html#comments</comments>
		<pubDate>Wed, 02 Dec 2009 17:19:24 +0000</pubDate>
		<dc:creator>forensicsadvisor</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1175</guid>
		<description><![CDATA[
			
				
			
		
More thoughts on our smart grid vulnerability:
However, the smart grid changes all of that.  The researchers from IOActive demonstrated that smart grid boxes can be hacked and that they can spread worms. Not only that, the boxes themselves will be connected to every home and be available to anyone. Anyone therefore has access to [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fi-was-wrong-there-probably-will-be-an-electronic-pearl-harbor.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fi-was-wrong-there-probably-will-be-an-electronic-pearl-harbor.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>More thoughts on our smart grid vulnerability:</p>
<blockquote><p>However, the smart grid changes all of that.  The researchers from IOActive <a href="http://www.csoonline.com/article/486067/Power_Grid_is_Found_Susceptible_to_Cyberattack" rel="nofollow" >demonstrated that smart grid boxes can be hacked</a> and that they can spread worms. Not only that, the boxes themselves will be connected to every home and be available to anyone. Anyone therefore has access to the smart grid. With tens of millions of the boxes planned to be distributed throughout the United States, potential attackers can easily get their hands on the systems to tear apart and find new vulnerabilities and attacks. More important, when there is a vulnerability found, how will it be mitigated?</p>
<p>There is a perfect storm brewing where the skills and resources required to launch a significant attack is being drastically lower. Depending upon the effects of a possible worm on the smart grid boxes, and the vulnerability of the generators, there can be a combined attack that does have strategic impact.</p></blockquote>
<p><a href="http://www.csoonline.com/article/print/509213" rel="nofollow" >I Was Wrong: There Probably Will Be an Electronic Pearl Harbor</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fi-was-wrong-there-probably-will-be-an-electronic-pearl-harbor.html&amp;linkname=I%20Was%20Wrong%3A%20There%20Probably%20Will%20Be%20an%20Electronic%20Pearl%20Harbor"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/security/i-was-wrong-there-probably-will-be-an-electronic-pearl-harbor.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BBC NEWS &#124; UK &#124; T-Mobile staff sold personal data</title>
		<link>http://viaforensics.com/security/bbc-news-uk-t-mobile-staff-sold-personal-data.html</link>
		<comments>http://viaforensics.com/security/bbc-news-uk-t-mobile-staff-sold-personal-data.html#comments</comments>
		<pubDate>Mon, 23 Nov 2009 15:59:44 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Breaches]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1164</guid>
		<description><![CDATA[
			
				
			
		
I love that &#8220;without our knowledge&#8221; quote.  Wouldn&#8217;t it be nice if companies took the security of your personal data seriously?  If you are a company who wants to try this, take a look at our fraudForensics service&#8230;do yourself and your customers a huge favor.
Staff at mobile phone company T-Mobile passed on millions of records [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fbbc-news-uk-t-mobile-staff-sold-personal-data.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fbbc-news-uk-t-mobile-staff-sold-personal-data.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>I love that &#8220;without our knowledge&#8221; quote.  Wouldn&#8217;t it be nice if companies took the security of your personal data seriously?  If you are a company who wants to try this, take a look at our <a href="http://viaforensics.com/corporations/" rel="nofollow" title="fraudForensics - viaForensics" >fraudForensics service</a>&#8230;do yourself and your customers a huge favor.</p>
<blockquote><p>Staff at mobile phone company T-Mobile passed on millions of records from thousands of customers to third party brokers, the firm has confirmed.</p>
<p>Details emerged after the firm alerted the information commissioner, who said his office was preparing a prosecution.</p>
<p>Christopher Graham said brokers had sold the data to other phone firms, who then cold-called the customers as their contracts were due to expire.</p>
<p>A T-Mobile spokesman said the data had been sold &#8220;without our knowledge&#8221;.</p></blockquote>
<p>via <a href="http://news.bbc.co.uk/2/hi/uk_news/8364421.stm" rel="nofollow" >BBC NEWS | UK | T-Mobile staff sold personal data</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fbbc-news-uk-t-mobile-staff-sold-personal-data.html&amp;linkname=BBC%20NEWS%20%7C%20UK%20%7C%20T-Mobile%20staff%20sold%20personal%20data"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/security/bbc-news-uk-t-mobile-staff-sold-personal-data.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Computerworld &gt; Microsoft confirms first Windows 7 zero-day bug</title>
		<link>http://viaforensics.com/security/computerworld-microsoft-confirms-first-windows-7-zero-day-bug.html</link>
		<comments>http://viaforensics.com/security/computerworld-microsoft-confirms-first-windows-7-zero-day-bug.html#comments</comments>
		<pubDate>Mon, 23 Nov 2009 15:56:44 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1162</guid>
		<description><![CDATA[
			
				
			
		
I won&#8217;t inundate the blog with Windows exploits but the first zero-day bug is noteworthy.
In a security advisory, Microsoft acknowledged that a bug in SMB (Server Message Block), a Microsoft-made network file- and print-sharing protocol, could be used by attackers to cripple Windows 7 and Windows Server 2008 R2 machines.
via Computerworld &#62; Microsoft confirms first [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fcomputerworld-microsoft-confirms-first-windows-7-zero-day-bug.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fcomputerworld-microsoft-confirms-first-windows-7-zero-day-bug.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>I won&#8217;t inundate the blog with Windows exploits but the first zero-day bug is noteworthy.</p>
<blockquote><p>In a security advisory, Microsoft acknowledged that a bug in SMB (Server Message Block), a Microsoft-made network file- and print-sharing protocol, could be used by attackers to cripple Windows 7 and Windows Server 2008 R2 machines.</p></blockquote>
<p>via <a href="http://computerworld.co.nz/news.nsf/scrt/E9592E1A9719742ACC25766F0066B38D" rel="nofollow" >Computerworld &gt; Microsoft confirms first Windows 7 zero-day bug</a>.</p>
<p>On a similar note, security firm Sophos recently tested Windows 7 with <a href="http://www.sophos.com/blogs/chetw/g/2009/11/03/windows-7-vulnerable" rel="nofollow" title="Windows 7 vulnerable to 8 out of 10 viruses" >10 viruses on 10/22/2009 and found 80% of them successeded</a>:</p>
<blockquote><p>On October 22nd, we settled in at SophosLabs and loaded a full release copy of Windows 7 on a clean machine. We configured it to follow the system defaults for User Account Control (UAC) and did not load any anti-virus software.</p>
<p>We grabbed the next 10 unique samples that arrived in the SophosLabs feed to see how well the newer, more secure version of Windows and UAC held up. Unfortunately, despite Microsoft&#8217;s claims, Windows 7 disappointed just like earlier versions of Windows. The good news is that, of the freshest 10 samples that arrived, 2 would not operate correctly under Windows 7.</p></blockquote>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fsecurity%2Fcomputerworld-microsoft-confirms-first-windows-7-zero-day-bug.html&amp;linkname=Computerworld%20%3E%20Microsoft%20confirms%20first%20Windows%207%20zero-day%20bug"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/security/computerworld-microsoft-confirms-first-windows-7-zero-day-bug.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
