SecureWorks Info Feed http://www.secureworks.com/ SecureWorks news, press releases, events, and research alerts. News: Online Crime Gang Stole Millions (washingtonpost.com) http://voices.washingtonpost.com/securityfix/2008/08/online_crime_gang_stole_millio.html http://voices.washingtonpost.com/securityfix/2008/08/online_crime_gang_stole_millio.html Event: 31st Annual National Directors' Convention http://www.secureworks.com/media/events/ August 05, 2008-August 08, 2008: SecureWorks will be Exhibiting at 31st Annual National Directors' Convention. Location: The Venetian, Las Vegas, NV. http://www.secureworks.com/media/events/#265 Blog: Speaking at DEFCON 16 http://www.secureworks.com/research/blog/index.php/2008/08/04/speaking-at-defcon-16 I'll be delivering two talks at DEFCON 16 in Las Vegas this Friday, August 8th. My first talk, The Wide World of WAFs, covers web applications firewalls and some PCI DSS background. In talk that afternoon, Snort Plug-in Development: Teaching an Old Pig New Tricks, I'll be releasing GPL licensed Snort plug-ins for ActiveX control detection and for detecting OpenSSH clients and servers using a broken Debian OpenSSL PRNG. http://www.secureworks.com/research/blog/?p=102 News Blog: Not encrypting laptop Clear-ly not a great idea http://www.secureworks.com/blog/index.php/2008/08/06/not-encrypting-laptop-clear-ly-not-a-great-idea According to news reports, an unencrypted laptop containing personal identification information for 33,000 registrants for the "Clear" program was stolen recently from an office at San Francisco International Airport. http://www.secureworks.com/blog/?p=101 News: Looking inside the Storm worm botnet (cnetnews.com) http://news.cnet.com/8301-1009_3-10009953-83.html http://news.cnet.com/8301-1009_3-10009953-83.html Event: Community Bankers Association of Ohio Annual Convention and Trade Show http://www.secureworks.com/media/events/ August 07, 2008-August 10, 2008: SecureWorks will be Exhibiting at Community Bankers Association of Ohio Annual Convention and Trade Show. Location: Sheraton Chicago Hotel and Towers, Chicago, IL. http://www.secureworks.com/media/events/#285 Blog: SAMI Is My Hero: MS08-033 Disassembled http://www.secureworks.com/research/blog/index.php/2008/07/29/sami-is-my-hero-ms08-033-disassembled My name is Bow Sineath and I have recently joined the SecureWorks Counter Threat Unitâ"¢ (CTU) as a security researcher. During my previous employment, I managed an IDS/IPS signature set and was responsible for acting on vulnerability intelligence that was, more often than not, very limited in public details. My experience in reverse engineering, source code analysis and countermeasure development is assisting SecureWorks in developing countermeasures that accurately protect our clients. http://www.secureworks.com/research/blog/?p=101 News Blog: The Week's Links: July 28 - August 1, 2007 http://www.secureworks.com/blog/index.php/2008/08/01/the-weeks-links-july-28-august-1-2007 A weekly feature highlighting news stories, reports and editorials of interest to IT and security managers. Also see stories including SecureWorks news, press releases, and research. http://www.secureworks.com/blog/?p=100 News: Middle East falls prey to Coreflood malware (itp.net) http://www.itp.net/news/527069-middle-east-falls-prey-to-coreflood-malware http://www.itp.net/news/527069-middle-east-falls-prey-to-coreflood-malware Event: DEFCON 16 http://www.secureworks.com/media/events/ August 08, 2008: SecureWorks will be Speaking at DEFCON 16. Location: , Las Vegas, NV. http://www.secureworks.com/media/events/#259 Blog: Cleaning Up E-Gold? Not Likely. http://www.secureworks.com/research/blog/index.php/2008/07/25/cleaning-up-e-gold-not-likely "On Monday, the Nevis, West Indies, company, its founder and two senior directors all agreed to plead guilty to various charges related to money laundering and the operation of an unlicensed money transfer business. The agreement ends a nearly four-year investigation into the company and its digital currency service, which -- because of the anonymity it provided account holders -- became a popular method for cybercriminals to turn ill-gotten proceeds into clean cash." http://www.secureworks.com/research/blog/?p=100 News Blog: The Week's Links: July 21 - July 25, 2007 http://www.secureworks.com/blog/index.php/2008/07/25/the-weeks-links-july-21-july-25-2007 A weekly feature highlighting news stories, reports and editorials of interest to IT and security managers. Also see stories including SecureWorks news, press releases, and research. http://www.secureworks.com/blog/?p=98 News: Russian hacker gang steals with impunity, says researcher (ComputerWorld) http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=knowledge_center&articleId=9111960&taxonomyId=1&intsrc=kc_top http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=knowledge_center&articleId=9111960&taxonomyId=1&intsrc=kc_top Event: DEFCON 16 http://www.secureworks.com/media/events/ August 08, 2008: SecureWorks will be Speaking at DEFCON 16. Location: , Las Vegas, NV. http://www.secureworks.com/media/events/#260 Blog: Police & Thieves http://www.secureworks.com/research/blog/index.php/2008/07/11/police-thieves The Unnamed Police Department (weâll just call them the UPD for short) is charged with keeping the peace in a major American metropolitan area. For a public safety website, theirs is quite advanced. Visitors can view dynamically generated maps showing the distribution of different classes of crimes, make anonymous tips to the narcotics squad, and even try to sign up to join the force. As those of us that work in information security well know, all that rich web functionality brings increased risk. http://www.secureworks.com/research/blog/?p=98 News Blog: The Week's Links: July 14 - July 18, 2007 http://www.secureworks.com/blog/index.php/2008/07/18/the-weeks-links-july-14-july-18-2007 A weekly feature highlighting news stories, reports and editorials of interest to IT and security managers. Also see stories including SecureWorks news, press releases, and research. http://www.secureworks.com/blog/?p=97 News: Russian gang suspected of hijacking computers for personal data (International Herald Tribune) http://www.iht.com/articles/2008/08/06/technology/hack.php http://www.iht.com/articles/2008/08/06/technology/hack.php Event: TechMixer University 2008 http://www.secureworks.com/media/events/ August 19, 2008: SecureWorks will be Speaking at TechMixer University 2008. Location: , Birmingham, AL. http://www.secureworks.com/media/events/#290 Blog: Dan Kaminsky Strikes Again With DNS Vulnerability http://www.secureworks.com/research/blog/index.php/2008/07/10/dan-kaminsky-strikes-again-with-dns-vulnerability This past Tuesday July 8th was a big day in information security. Accomplished security researcher Dan Kaminsky of IOActive announced a major new vulnerability in the DNS infrastructure underpinning the Internet. What is the vulnerability, you ask? We may all have to wait for Dan to tell us at the Black Hat Briefings security conference, kicking off on Wednesday August 6th. http://www.secureworks.com/research/blog/?p=97 News Blog: Identity Theft Red Flags Update http://www.secureworks.com/blog/index.php/2008/07/17/identity-theft-red-flags-update Thanks again to everyone who attended our recent "Red Flags Update" webcast. By popular demand, slides from the website can be downloaded here. http://www.secureworks.com/blog/?p=95