<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CoreTrace WhiteSpace&#187; CoreTrace WhiteSpace</title>
	<atom:link href="http://www.coretraceblogs.com/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.coretraceblogs.com</link>
	<description>The Application Whitelisting and Security Weblog</description>
	<lastBuildDate>Fri, 27 Jan 2012 17:47:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Social network security key issue for business in 2010</title>
		<link>http://www.coretraceblogs.com/2009-11/social-network-security-key-issue-for-business-in-2010/</link>
		<comments>http://www.coretraceblogs.com/2009-11/social-network-security-key-issue-for-business-in-2010/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 17:15:12 +0000</pubDate>
		<dc:creator>JT Keating</dc:creator>
				<category><![CDATA[whitelisting]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[social networks]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[whitelist]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=867</guid>
		<description><![CDATA[There have been many cases of social networks overlapping security software this year. Whether they are using Twitter or Facebook for botnet control or propagating phishing links through shortened URLs, online criminals are finding ways to tap into the explosive growth of social networks and use that to exploit end users and their devices.
A recent [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.coretraceblogs.com/wp-content/uploads/2009/11/iStock_socialmedia_server-211x227.jpg" alt="Social network security key for business in 2010" title="Social network security key for business in 2010" width="211" height="227" class="alignright size-medium wp-image-872" />There have been many cases of social networks overlapping security software this year. Whether they are using <a href="http://www.internetnews.com/security/article.php/3834721/Twitter+Used+as+Botnet+Control.htm" target="_blank">Twitter or Facebook for botnet control</a> or <a href="http://www.businessweek.com/smallbiz/tips/archives/2009/10/the_dangers_lur.html" target="_blank">propagating phishing links through shortened URLs</a>, online criminals are finding ways to tap into the explosive growth of social networks and use that to exploit end users and their devices.</p>
<p>A recent article in SearchSecurity.com, <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1374907,00.html?track=sy160&#038;utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+techtarget%2FSearchsecurity%2FSecurityWire+%28SearchSecurity+%3A+Security+Wire+Daily+News%29" target="_blank">&#8220;Hackers to sharpen malware, malicious software in 2010&#8243;</a>, points to increasing sophistication in cybercriminals&#8217; use of social networking sites.<span id="more-867"></span> Robert Westervelt writes:</p>
<blockquote>
<p>In an effort to sustain growth and pick up new users, more social networks are opening up their architecture to allow third-party applications. Cybercriminals can take advantage of this by developing applications out of the social network environment to target users. In addition, access to social network APIs gives attackers a roadmap to vulnerabilities in legitimate third-party applications and a way to tap into user accounts.</p>
</blockquote>
<p>Changes in this environment means that businesses will be more pressed than ever to set policies around the use of social networks on company IT resources and this won&#8217;t be popular. It will be made all the more difficult by the fact that social networks aren&#8217;t just for personal use any more. More businesses than ever are engaging in social media and using it to connect to customers, provide service, and promote their company.</p>
<p>Expect web site access control, application whitelisting and software asset management solutions to play an even more important role than ever on corporate networks. It will be essential that businesses both understand and control what applications their employees are using to defend against an increasingly prevalent threat.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2009-11/social-network-security-key-issue-for-business-in-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top Endpoint Security Stories &#8211; September 2009</title>
		<link>http://www.coretraceblogs.com/2009-10/top-endpoint-security-stories-september-2009/</link>
		<comments>http://www.coretraceblogs.com/2009-10/top-endpoint-security-stories-september-2009/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 13:56:58 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[whitelisting]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=624</guid>
		<description><![CDATA[Last month I kicked off a post focusing on the top endpoint security stories in the past month. This month brought a number of endpoint security events ranging from the latest Microsoft zero-day vulnerabilities without a fix to botnet and phishing news. The theme of the month is that both individuals and corporations are simply [...]]]></description>
			<content:encoded><![CDATA[<p>Last <a href="http://www.coretraceblogs.com/2009-09/top-endpoint-security-stories-august-2009/" target="_blank">month I kicked off a post</a> focusing on the top endpoint security stories in the past month. This month brought a number of endpoint security events ranging from the latest Microsoft zero-day vulnerabilities without a fix to botnet and phishing news. The theme of the month is that both individuals and corporations are simply losing the battle against online criminals when it comes to desktop security.</p>
<ul>
<li class="margin_bottom_1em"><strong>Sept 1, 2009 – IIS FTP flaw announced with exploit code</strong><br />
Microsoft kicked off the month by confirming the publication of <a href="http://blogs.zdnet.com/security/?p=4170" target="_blank">exploit code for the IIS FTP vulnerability</a> that could allow remote code execution on affected systems. The vulnerability affected systems running the IIS web server and was particular dangerous to FTP servers that had anonymous accounts for uploads.<span id="more-624"></span></li>
<li class="margin_bottom_1em"><strong>Sept 3, 2009 – Apple shows it continues to have more security problems than its ads would lead you to believe</strong><br />
Apple released security patches for <a href="http://threatpost.com/blogs/apple-patches-15-java-mac-security-flaws-103" target="_blank">Java that fixed 15 documented security vulnerabilities</a>. The most serious vulnerability allowed unauthorized Java applets to gain escalated privileges.</li>
<li class="margin_bottom_1em"><strong>Sept 5, 2009 – Microsoft announces patches will fail to include fix for IIS flaw</strong><br />
The patch that was released following the announcement of the IIS exploit code <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1367160,00.html?track=sy160" target="_blank">did not contain a fix for that problem</a>. Despite the severity of the problem, the complexity involved with producing, testing and distributing a patch to a serious security vulnerability prevented Microsoft from quickly fixing the hole in their operating system. At this same time, limited attacks were beginning to show up against those servers.</li>
<li class="margin_bottom_1em"><strong>Sept 9, 2009 – Microsoft announces SMB2 vulnerability affecting Windows Vista and Windows Server 2008</strong><br />
Yet another zero-day vulnerability was announced without an immediate fix. Some security experts debated the impact of this vulnerability with many thinking this <a href="http://lastwatchdog.com/stage-set-vista-worm-microsoft-scrambles-ready-smb2/" target="_blank">could set the stage for a Vista worm</a>.</li>
<li class="margin_bottom_1em"><strong>Sept 11, 2009 – Clampi botnet continues to be a problem</strong><br />
<a href="http://voices.washingtonpost.com/securityfix/2009/09/clamping_down_on_clampi.html" target="_blank">Online banking credentials continue to be targeted and stolen</a> online by this dangerous botnet.</li>
<li class="margin_bottom_1em"><strong>Sept 17, 2009 – Security researchers demonstrate a remote exploit of the SMB2 vulnerability capable of spawning a worm</strong><br />
The <a href="http://threatpost.com/blogs/remote-exploit-released-windows-vista-smb2-worm-hole-117" target="_blank">vulnerability was originally announced as a denial of service vulnerability and now was shown to have the potential to propagate a worm</a>.</li>
<li class="margin_bottom_1em"><strong>Sept 17, 2009 – Botnets being used for click fraud</strong><br />
Computerworld reported that the <a href="http://www.computerworld.com/s/article/9138213/Sophisticated_botnet_causing_a_surge_in_click_fraud?source=rss_security" target="_blank">&#8220;bahama botnet&#8221; was being used to create fraudulent clicks</a> to be used for affiliate marketing fraud.</li>
<li class="margin_bottom_1em"><strong>Sept 18, 2009 – Microsoft releases fix/workaround to SMB2 vulnerability</strong><br />
The day after researchers announced remote exploitation code for the SMB2 vulnerability that could lead to a worm, <a href="http://threatpost.com/blogs/microsoft-ships-temporary-fix-it-critical-vista-flaw-118" target="_blank">Microsoft issued a fix that essentially turned off the service</a> until a patch could be issued. They also indicated that this could have a performance impact until they produced the patch.</li>
<li><strong>Oct 1, 2009 – Antiphishing Working Group announces that phishing websites and rogue anti-virus software sites are dramatically on the rise.</strong><br />
<a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1369953,00.html?track=sy160" target="_blank">Coordinated attacks to trick users into infecting their PC with malware are booming</a>. Phishing websites and fake anti-virus software both work to direct users to bogus sites where they become infected with malware.</li>
</ul>
<p>All in all, this past month was more evidence that our reactive patching and signature based endpoint security strategy is coming to an end of its useful lifespan. The discussion has already begun at conferences and among the analysts as to what will become the new de facto endpoint security standard. Signs point strongly to a whitelisting solution playing a prominent role in this transition.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2009-10/top-endpoint-security-stories-september-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

