Access control and authentication - News, Features, and Slideshows

News

  • Amazon adds app for easier two-factor authentication

    Amazon Web Services has added the option to use applications to create codes for its Multi-Factor Authentication (MFA) service, the company said on Wednesday.

    Written by Mikael Ricknäs04 Nov. 11 04:20
  • Ongoing drive-by download campaign hijacked MIT server

    A server belonging to the Massachusetts Institute of Technology was commandeered by hackers who used it to launch attacks against other websites as part of a larger drive-by download campaign, according to antivirus vendor BitDefender.

    Written by Lucian Constantin04 Nov. 11 00:25
  • Duqu exploits zero-day Windows kernel vulnerability to infect computers

    Security researchers from the CrySyS laboratory in Hungary have located an installer for Duqu, the <a href="http://www.pcworld.com/businesscenter/article/242114/duqu_new_malware_is_stuxnet_20.html">Stuxnet-inspired threat</a> that has kept the security industry on its toes for the past couple of weeks, and determined that it exploits a previously unknown vulnerability in the Windows kernel.

    Written by Lucian Constantin02 Nov. 11 06:18
  • Researchers defeat CAPTCHA on popular websites

    Researchers from Stanford University have developed an automated tool that is capable of deciphering text-based anti-spam tests used by many popular websites with a significant degree of accuracy.

    Written by Lucian Constantin02 Nov. 11 02:47
  • IBM anoints Q1 Labs technology as centerpiece of security portfolio

    IBM intends to make the security information and event management (SIEM) technology gained through the acquisition of Q1 Labs, which was officially closed yesterday, the centerpiece of IBM's broad security product portfolio.

    Written by Ellen Messmer28 Oct. 11 05:34
  • Researchers demo cloud security issue with Amazon AWS attack

    Researchers from the Horst Goertz Institute (HGI) of the Ruhr-University Bochum (RUB) in Germany have demonstrated an account hijacking attack against Amazon Web Services (AWS) that they believe affects other cloud computing products as well.

    Written by Lucian Constantin27 Oct. 11 02:31
  • Researchers demo cloud security issue with Amazon AWS attack

    Researchers from the Horst Goertz Institute (HGI) of the Ruhr-University Bochum (RUB) in Germany have demonstrated an account hijacking attack against Amazon Web Services (AWS) that they believe affects other cloud computing products as well.

    Written by Lucian Constantin27 Oct. 11 00:29
  • Exploit-powered Android Trojan uses update attack

    A new variant of the DroidKungFu Android Trojan is posing as a legitimate application update in order to infect handsets, according to security researchers from Finnish antivirus vendor F-Secure.

    Written by Lucian Constantin26 Oct. 11 04:39
  • Adobe to fix Flash flaw that allows webcam spying

    Adobe is working on a fix for a Flash Player vulnerability that can be exploited via clickjacking techniques to turn on people's webcams or microphones without their knowledge.

    Written by Lucian Constantin21 Oct. 11 01:18
  • SpyEye steals banking codes by sending them to wrong phone

    Researchers from browser security vendor Trusteer have identified a new variant of the SpyEye financial Trojan that tricks online banking users into changing the phone numbers associated with their accounts.

    Written by Lucian Constantin07 Oct. 11 01:27
  • XSS web attacks could live forever, researcher warns

    Websites that accidentally distribute rogue code could find it harder to undo the damage if attackers exploit widespread browser support for HTML5 local storage and an increasing tendency for heavy users of Web apps never to close their browser.

    Written by Lucian Constantin05 Oct. 11 01:55
  • GlobalSign plans to reopen Tuesday despite web server hack

    GlobalSign expects to bring its certificate-issuing systems back online on Monday, and resume business Tuesday, it said over the weekend. The U.S. certificate authority (CA) stopped issuing new SSL certificates last Tuesday in order to audit its security, after being named as a target by the hacker who claimed to have attacked Dutch CA DigiNotar.

    Written by John Ribeiro12 Sept. 11 17:38
  • Google's two-step authentication goes worldwide

    Google <a href="http://googleblog.blogspot.com/2011/07/2-step-verification-stay-safe-around.html">said Thursday</a> that it has rolled out its two-step authentication sign-in system to 40 languages across over 150 countries.

    Written by John Ribeiro29 July 11 14:47
[]