CoreTrace WhiteSpace

The Application Whitelisting and Security Weblog

Targeted marketing & attacks: If you are the goal, they will find you…

In today’s competitive market place, highly targeted marketing plans are essential for reaching your core audience and getting the most bang for your buck. This is what most organizations strive for, and hackers have taken note.

Over the past few years, cyber criminals have embraced a similar business model. Instead of playing the numbers game, which consists of randomly spamming tens of thousands of people in hopes of getting a small percentage of victims to click on their malicious code, malware attacks are now truly targeted. Acting sort of like niche malware, hackers design specific cyber attacks that target specific victims, companies and industries.

As a result, no vertical is safe today. ( Read More… )

Please use the comment form and leave your thoughts!

Why whitelisting is not a standalone replacement for traditional antivirus…

Coming from an application whitelisting provider, you might think it’s rather odd that we would agree with anyone who says whitelisting is not a replacement for antivirus. Because each solution takes an opposing approach to fighting malware, it’s only natural that people think that you can only use one or the other. But it’s just not true.

In the article, “Whitelisting on its own not a substitute for antivirus,” Network World’s Ellen Messmer writes how whitelisting should be used as a complementary security defense, not a standalone solution. And we absolutely agree. Here’s why. ( Read More… )

Most recent comment:   Jose Peñaloza

However, since PCI perspective AWL can meet as compensatory control when the constrained resources (OS legacy, low cpu, low ram) ...

BSides Austin: Keeping security weird at this year’s SxSW

CoreTrace is excited to welcome all of you information security gurus to the ATX for next week’s BSides Austin event during SxSW Interactive. While I won’t be able to make it myself (don’t feel too sorry for me; I am going skiiing at home in Tahoe), the rest of the team are eagerly looking forward to meeting you and partaking in many of the lively (and presumably offbeat) discussions around practical application security, maintaining compliance, understanding and combating new attacks, etc.

Time for a little BSides PSA: Security BSides events are doing some incredible things by bringing social networking chatter to major events around the world, providing homegrown security professional conversations about real-world trends, challenges and solutions that all of us in the infosecurity community face. ( Read More… )

Please use the comment form and leave your thoughts!

Top Endpoint Security Stories for February 2011: RSA, poisoned websites & (of course) cloud security…

Each year, several key topics emerge from RSA that get everybody thinking. This year was no different. From next-generation cyber security to the impact the cloud could have on the industry, every security professional today is thinking about how they’re going to protect their network from evolving cyber threats, regardless of the type of attack or operating platform. Here are some of the top endpoint security stories for February 2011. ( Read More… )

Please use the comment form and leave your thoughts!

Laziness is the mother of invention: Stopping more bad, in more places, with less effort…

The days of criminals randomly blasting out easily spotted cyber attacks, for the most part, are over. According to a recent study by Blue Coat, the older shotgun approach of sending out many attacks to see what sticks has taken a backseat to more precisely targeted attacks.

With today’s cyber criminals more financially driven, the article, “Blue Coat Study Shows Malware Now Targets ‘Trusted Sites’,” said criminals are focusing on corporate networks that they believe have valuable assets they can steal. Blue Coast’s Tom Clare said one of the ways criminals are looking to access networks is through Web-delivered applications. As companies offer more business applications to their employees through a Web browser, they need to protect these applications as the risk of malware increases. ( Read More… )

Most recent comment:   JT Keating

Brad: Thank you so much for the kind words and interest. You are correct that CoreTrace is not currently ...