IT Security
DNS flaw unfixed as experts argue protocol
Speculation continues as to what the ultimate systemic Domain Name System flaw could be.
Malware prevalent on trusted Web pages
Five seconds into reading this story, a Web page somewhere will become infected with malware or some other malicious code.
Internal security threats multiply
Too many PCs and servers are missing essential security software or using unauthorized technology, increasing the risk of cyberattack or data theft.
Microsoft DNS fix causes trouble for some
Microsoft released a Domain Name Server system fix in its software patch slate for July, but some users have experienced additional difficulties after installing the fix.
DNS vulnerability update: Patch now!
The security blog for Matasano Security mistakenly published some of the details of the DNS vulnerability, creating the possibility that exploits soon could be developed.
NIST revises guidelines for IT security metrics
The National Institute of Standards and Technology has released a revised version of guidelines for developing metrics to ensure that agencies meet IT security requirements.
Casting a net for spear phishers
Intrepidus Group announces the release of PhishMe, a software application that helps users thwart spear phishing attacks.
Open source, open to attack
A recent study of open-source software found a lack of dedicated security experts and secure coding standards, and a focus on functionality rather than security.
Patching the Domain Name System
Vendors scramble to produce patches for a potentially severe design flaw in the Internets Domain Name System, and the race is on to get patches in place before exploits appear.
Patch issued for BlackBerry PDF bug
BlackBerry maker Research in Motion plugs a vulnerability that could have allowed hackers to enter into a network via a maliciously crafted PDF file.





