Product News

It's official: Microsoft to offer free anti-malware service

Greg Masters June 19, 2009

Next week, Microsoft will make available to consumers a new, free anti-malware service to replace its subscription model.
 

Windows 7 ships Oct. 22

Chuck Miller June 02, 2009

Microsoft's Windows 7 will go into general commercial availability on Oct. 22, according to a Microsoft spokeswoman. The company did not announce prices for the several versions it plans, but said it will introduce a program -- a "Tech Guarantee" or Windows Upgrade Option -- that enables people who buy current PCs with Vista to get a free upgrade to the new Windows 7 software when it becomes available. — CAM
 

Google's new Chome browser comes with privacy option

Chuck Miller May 22, 2009

Google has introduced its latest version of Chrome, and claims to have enhanced speed and privacy features.
 

Microsoft releases SDL tool

Dan Kaplan May 19, 2009

Microsoft on Tuesday released a free tool to help application developers better secure their programs. The SDL (Secure Development Lifecycle) Process Template for Visual Studio Team System provides a framework -- including auditable requirements -- for building security into applications. The offering complements previous Microsoft SDL releases: Optimization Model, Pro Network and Threat Modeling Tool. Microsoft developed SDL in 2004 to address security vulnerabilities in its software. The program is credited with reducing vulnerabilities in Vista and SQL Server. — DK
 

Oracle to acquire Virtual Iron

Greg Masters May 13, 2009

Redwood City, Calif.-based Oracle has agreed to acquire Virtual Iron Software, a vendor of server virtualization software that addresses a variety of data center issues. Oracle said the incorporation of Virtual Iron's technology is expected to provide more dynamic resource management across the full software stack. The deal is pending approvals and is expected to close this summer. Meanwhile, the companies will operate independently. Financial details were not disclosed. Lowell, Mass.-based Virtual Iron was founded in 2003. — GM
 

Microsoft changes AutoRun

Dan Kaplan April 29, 2009

Microsoft is planning to update its Windows platforms so that their AutoRun features - one of the preferred vectors for spreading the infectious Conficker worm - does not support USB sticks, the company announced Tuesday. In the next version of the operating system, Windows 7, AutoRun - a technology that automatically runs programs when media is plugged into a PC - only will work for CDs and DVDs. Engineers plan to extend this change to Vista and XP platforms. — DK
 

Microsoft Forefront now in the clouds

Angela Moscaritolo April 16, 2009

Microsoft has extended its Forefront brand and is now putting messaging security into the cloud.
 

ActiveX flaw detector released

Dan Kaplan April 16, 2009

The CERT Coordination Center at the Carnegie Mellon Software Engineering Institute in Pittsburgh on Thursday released a free, open-source tool that software developers can use to detect ActiveX vulnerabilities. Dubbed Dranzer, the tool was tested on 22,000 ActiveX controls produced by more than 5,000 organizations. Dranzer is designed for use during the quality assurance phase of software creation and can help prevent flaws, such as buffer overflows, from being shipped in software to the public. — DK
 

OWASP releases code guide

Dan Kaplan April 03, 2009

The Open Web Application Security Project (OWASP), an open-source project, has announced a free, 216-page guide for how to review code for application vulnerabilities. The book complements the already released "OWASP Security Developer Guide" and the "Security Testing Guide." The latest publication is "part of OWASP's strategy to make application security visible and enable the market to support the development of secure application software," according to the organization. — DK
 

"High-priority" Firefox patch being readied

Greg Masters March 26, 2009

A new patch for Firefox is being readied for shipment early next week to fix a vulnerability detected on Wednesday.
 

PCI council plans training

Dan Kaplan March 11, 2009

The PCI Security Standards Council, charged with administering payment industry guidelines, is scheduled to host a two-day training session, designed to help merchants better prepare for assessments. The curriculum also will focus on teaching retailers how to create an internal compliance program, so they can maintain adherence to the standards after the assessment is over. The course, which costs $995, is scheduled for April 6 and 7 at the University of Chicago Gleacher Center. — DK
 

Vista SP2 RC now available

Chuck Miller February 25, 2009

The first release candidate (RC) of Service Pack 2 (SP2) for Windows Vista and Windows Server 2008 is now available from Microsoft. Starting Wednesday, the RC is available to TechNet and Microsoft Developer Network (MSDN) subscribers for testing, according to a post on the Microsoft Windows blog. The blog said SP2 includes updates that have been delivered since the release of SP1, in addition to support for new types of hardware and emerging standards, while continuing the security benefits of the operating system. — CAM
 

Safari 4 focuses on security

Dan Kaplan February 25, 2009

Apple's Safari 4, released in beta on Tuesday, contains a number of new security components, bringing it in line with other browsers such as Firefox and Internet Explorer. The latest Safari version includes phishing protection, which notifies users when they visit a suspected fraudulent website, and malware protection, which alerts users of sites hosting malicious code. The latest installment also supports extended-validation SSL certificates. — DK
 

Protest by Facebook users alters use policy

Greg Masters February 18, 2009

A slight change made last month in Facebook's terms of service contract ignited a firestorm from users when the implications were digested.
 

NetForensics buys High Tower

Dan Kaplan February 17, 2009

NetForensics on Monday announced it has acquired High Tower Software, formerly a competitor that provided log management solutions to mid-size businesses. The deal -- terms of which were not disclosed -- enables netForensics and its managed security services provider (MSSP) partners to provide security compliance offerings throughout the lifecycle, including security information and event management, database activity monitoring and log management. High Tower reportedly had closed in November due to poor sales. — DK
 

New encryption specification

Dan Kaplan February 12, 2009

A group of technology providers have created a new protocol designed to streamline encryption and key management systems across an enterprise. The companies, including IBM, Seagate and RSA, on Thursday announced the Key Management Interoperability Protocol (KIMP) and plan to submit it to nonprofit OASIS, which drives the development of security standards. KIMP seeks to increase encryption adoption, while helping organizations reduce costs and risks. — DK
 

CASE STUDY: phion airlock in use at Herba Chemosan

January 27, 2009

A pharmacist wholesaler in Austria modernized its distribution systems and found protection for its network.
 

Spam grows as senders use slicker ways to trick users

Angela Moscaritolo January 26, 2009

The amount of spam is nearing pre-McColo numbers, and junk mailers are using crafty new methods to infect computers, two spam reports released on Monday conclude.
 

Check Point to purchase Nokia's security appliance business

Dan Kaplan December 22, 2008

Check Point Software Technologies is the buyer of Nokia's security appliance business.
 

Apple drops support document encouraging anti-virus adoption

Dan Kaplan December 03, 2008

Calling it "old and innaccurate," Apple has pulled a release note that recommended Mac users install anti-virus software.
 

Apple advises Mac users to install anti-virus software

Dan Kaplan December 02, 2008

For possibly the first time ever, Apple is recommending Mac OS X users deploy anti-virus solutions -- but it remains unclear exactly why.
 

New free tool detects malware on networks

Angela Moscaritolo November 25, 2008

BotHunter was sponsored by the U.S. Army Research Office and is being used by U.S. government and the Department of Defense.
 

Microsoft: Flaws down but malware on the rise

Dan Kaplan November 03, 2008

The amount of malware is increasing, and vulnerabilities are more likely to be found in applications than operating systems, according to the latest Microsoft Security Intelligence Report.
 

Symantec to lay off employees amid faltering economy

Dan Kaplan October 31, 2008

With the economy in a tailspin, Symantec announces that it will reduce the costs of its workforce by 4.5 percent.
 

Google's inaugural browser comes with security focus, including sandboxed sessions

Dan Kaplan September 02, 2008

Google's new Chrome web browser has a number of security elements to go along with an ergonomic design and increased performance and stability.
 

Microsoft unveils privacy controls in Internet Explorer 8

Dan Kaplan August 26, 2008

Microsoft has confirmed speculation that it will include new privacy controls in its next Internet Explorer release.
 

Symantec to buy PC Tools

Chuck Miller August 20, 2008

Symantec said that it has entered an agreement to acquire Australia-based internet security firm PC Tools.
 

Free software unveiled to help track lost laptops

Sue Marquette Poremba July 14, 2008

College researchers have developed free, open-source software that can track the location of a lost or stolen laptop without the need for a third-party vendor.
 

Mozilla set to develop risk model for software development

Dan Kaplan July 07, 2008

Mozilla and an independent security consultant have joined forces to build a risk model -- and Firefox users are not the only ones who could benefit.
 

Millions of downloads -- and the first critical bug -- in Firefox 3

Dan Kaplan June 19, 2008

As the Mozilla community marched toward a supposed world record of downloads of Firefox 3, researchers from TippingPoint announced a critical vulnerability affecting the day-old browser.