CoreTrace WhiteSpace

The Application Whitelisting and Security Weblog

Top Endpoint Security Stories for March 2011 — Cyber criminals setting new sights on unprotected intellectual property and government networks

New trends in cybercrime show that hackers are shifting to more monetarily valuable information — unprotected intellectual property, and federal government networks. While traditional antivirus solutions struggle to keep up with today’s prolific attack software, Gartner recommends whitelisting as a complementary security defense in preventing malware attacks on corporate networks and PCs. Here are some of the top endpoint security stories for March 2011. Continue reading this post…

Critical U.S. infrastructure: “There’s always a way in.”

There’s always a way in.

That’s the straightforward, yet disturbing message that hacker-for-hire, Marc Maiffret, made after his team, hired by a large California-based water system to probe the vulnerabilities of its computer networks, took control of the equipment to add chemical treatments to drinking water within one day, hypothetically making the water undrinkable for millions of homes. Continue reading this post…

Targeted marketing & attacks: If you are the goal, they will find you…

In today’s competitive market place, highly targeted marketing plans are essential for reaching your core audience and getting the most bang for your buck. This is what most organizations strive for, and hackers have taken note.

Over the past few years, cyber criminals have embraced a similar business model. Instead of playing the numbers game, which consists of randomly spamming tens of thousands of people in hopes of getting a small percentage of victims to click on their malicious code, malware attacks are now truly targeted. Acting sort of like niche malware, hackers design specific cyber attacks that target specific victims, companies and industries.

As a result, no vertical is safe today. Continue reading this post…

Why whitelisting is not a standalone replacement for traditional antivirus…

Coming from an application whitelisting provider, you might think it’s rather odd that we would agree with anyone who says whitelisting is not a replacement for antivirus. Because each solution takes an opposing approach to fighting malware, it’s only natural that people think that you can only use one or the other. But it’s just not true.

In the article, “Whitelisting on its own not a substitute for antivirus,” Network World’s Ellen Messmer writes how whitelisting should be used as a complementary security defense, not a standalone solution. And we absolutely agree. Here’s why. Continue reading this post…

BSides Austin: Keeping security weird at this year’s SxSW

CoreTrace is excited to welcome all of you information security gurus to the ATX for next week’s BSides Austin event during SxSW Interactive. While I won’t be able to make it myself (don’t feel too sorry for me; I am going skiiing at home in Tahoe), the rest of the team are eagerly looking forward to meeting you and partaking in many of the lively (and presumably offbeat) discussions around practical application security, maintaining compliance, understanding and combating new attacks, etc.

Time for a little BSides PSA: Security BSides events are doing some incredible things by bringing social networking chatter to major events around the world, providing homegrown security professional conversations about real-world trends, challenges and solutions that all of us in the infosecurity community face. Continue reading this post…