Stories by Bill Brenner

Vulnerability management basics: Pen testing techniques

It should go without saying that pen testing is one of the most important pieces of an IT security shop's vulnerability management program. And yet it's something that was declared a dead art by Fortify Co-founder Brian Chess a couple years ago.

Windows XP SP2: Don't fear the reaper

An open letter to those who are distraught over the impending retirement of Windows XP SP2:

FireEye vows to expose 'truth' behind modern malware

In his interview with CSO last week, FireEye Chief Security Architect Marc Maiffret lamented what he sees as the inability of security vendors to keep up with the malware innovations made in the pursuit of attacks against the likes of Adobe and Apple.

Your BlackBerry's dirty little security secret

Tyler Shields, senior member of the Veracode Research Lab, spends a lot of time picking apart those BlackBerry devices that are ubiquitous across the enterprise. What he's found may disappoint those who thought they were secure.

SaaS, Security and the Cloud: It's All About the Contract

The term Software as a Service (SaaS) has been around a long time. The term cloud is still relatively new for many. Putting them together has meant a world of hurt for many enterprises, especially when trying to integrate security into the mix.

3

Why 41 Percent of You Would Fail a PCI Audit

Security vendors are launching a gazillion products this week at RSA Conference 2010, but hidden in all of those press releases are a few nuggets that illustrate the big picture trends.

What Researchers Are Learning About DDoS Tactics

A corporate security specialist on motives and tactics Jerry Mangiarelli has gained a lot of private-sector perspective on the DDoS threat over the years through his own personal research into botnets.

Schmidt tapped as White House cybersecurity coordinator

Seven months after he announced the creation of a White House cybersecurity coordinator, President Obama has selected industry veteran Howard Schmidt for the job, an administration official confirmed Monday night.

Does Social Networking Require User Policy Changes?

IT security administrators have had a fairly easy case to make against such social networking sites as Myspace in the past. Myspace in particular tends to be a place for the mostly personal, and some profiles are simply front companies for online mobsters and malware pushers.

Botnets: 4 Reasons It's Getting Harder to Find and Fight Them

The perpetual proliferation of botnets is hardly surprising when one considers just how easy it is for the bad guys to hijack computers without tipping off the users.

Security Vendor Breaches: Fallout Justified

Kaspersky Lab and F-Secure were up-front in acknowledging recent hacks against them, but the negative fallout is still justified.

7 Deadly Sins of Network Security

Companies that suffer serious security breaches have almost always committed one (or all) of 7 deadly security sins. Is your company guilty?

International Challenges in PCI Security

In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective.

Third-party anonymous proxies? No! No! No!

This is the third installment of a three-part series on the pros and cons of anonymous proxy services. Read the first installment here and listen to the second installment here.

Anonymous proxy servers: Necessary or evil?

If there is truly a gray zone in the struggle between online good and evil, anonymous proxy servers live there.

Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/149/dropbox/

Dropbox

Dropbox is a sharing tool that allows you to synchronize your documents, as well share files with others. It automatically uploads the files to the ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia