<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/css/rss20.xsl" type="text/xsl"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/" xmlns:pheedo="http://www.pheedo.com/namespace/pheedo">
	<channel>
		<title>Security Bytes</title>
		<link>http://itknowledgeexchange.techtarget.com/security-bytes</link>
		<description>A SearchSecurity.com blog</description>
		<pubDate>Tue, 21 Feb 2012 17:46:20 +0000</pubDate>
		<generator>http://wordpress.org/?v=2.6.2</generator>
		<language>en</language>
		<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9; </copyright>
		<managingEditor>contactus@itknowledgeexchange.com ()</managingEditor>
		<webMaster>contactus@itknowledgeexchange.com()</webMaster>
		<category></category>
		<itunes:keywords></itunes:keywords>
		<itunes:subtitle></itunes:subtitle>
		<itunes:summary>A SearchSecurity.com blog</itunes:summary>
		<itunes:author></itunes:author>
		<itunes:category text="Society &amp; Culture"/>
		<itunes:owner>
			<itunes:name></itunes:name>
			<itunes:email>contactus@itknowledgeexchange.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://itknowledgeexchange.techtarget.com/security-bytes/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg"/>
		<image>
			<url>http://itknowledgeexchange.techtarget.com/security-bytes/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
			<title>Security Bytes</title>
			<link>http://itknowledgeexchange.techtarget.com/security-bytes</link>
			<width>144</width>
			<height>144</height>
		</image>
		<atom:link rel="hub" href="http://www.pheedo.com/api/hub/"/>
		<atom:link rel="self" href="http://feeds.pheedo.com/SecurityBytes" type="application/rss+xml"/>
		<item>
			<title>Kaspersky buys out equity firm; keeps security company private</title>
			<link>http://www.pheedcontent.com/click.phdo?i=7867d33d89e89ccb67c58793106a5618</link>
			<pheedo:origLink>http://itknowledgeexchange.techtarget.com/security-bytes/kaspersky-buys-out-equity-firm-keeps-security-company-private/</pheedo:origLink>
			<comments>http://itknowledgeexchange.techtarget.com/security-bytes/kaspersky-buys-out-equity-firm-keeps-security-company-private/#comments</comments>
			<pubDate>Fri, 03 Feb 2012 21:44:51 +0000</pubDate>
			<dc:creator>Michael S. Mimoso</dc:creator>
			<category><![CDATA[Eugene Kaspersky]]></category>
			<category><![CDATA[Kaspersky Lab]]></category>
			<category><![CDATA[security IPO]]></category>
			<category><![CDATA[General Atlantic]]></category>
			<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-bytes/kaspersky-buys-out-equity-firm-keeps-security-company-private/</guid>
			<description><![CDATA[
CANCUN, Mexico &#8212; Kaspersky Labs cofounder and chief executive Eugene Kaspersky announced today that the Russian security company will not pursue an initial public offering in the forseeable future and will buy back the shares it sold to a private equity firm brought in 13 months ago to pursue an IPO.
In January 2011, General Atlantic bought 20% of Kaspersky, [...]<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:2d18aaec8fd11dde0ec6ad420a635a6d:xTIc%2FOom%2Fy3IMFosYEaPeEPlnNLFJBG5ZwuuoiZR32ayDFU4IMUQ25e%2FMRW1X7lu2dNC%2FpgO%2Feul1Ps%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:5636b5d8be70ae3c2d84c8fbd02b571b:9hTZmqF7m03dWjq82kam%2F4j3CSd2W2M9UqG0PxAXwkjIiGIXGP4DEajleGxVTdBNvgLHqn%2B6Hv2uPfs%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:9a3925c8906c1f313341328a41c3173d:pIeOI0kQF%2Fo%2Fl1L2Nk%2BQd0CyZUvbQXURJxEtWiZQiyyg5LLgfSd5D%2BgJkE5Wg3dMGQKa2i6CkPSK7g%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:f8dcd12c90e33b7aa69ec5a705f87539:S9k42bPUNxoOEM6M3d%2FU%2BJ1Fuc33T4spCid8cw2zXE30%2BpvxuIeIc9covUrmD6jnfwRVE9mbWFteAg%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=7867d33d89e89ccb67c58793106a5618&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=7867d33d89e89ccb67c58793106a5618&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></description>
			<content:encoded><![CDATA[
<p>CANCUN, Mexico &#8212; Kaspersky Labs cofounder and chief executive Eugene Kaspersky announced today that the Russian security company will not pursue an initial public offering in the forseeable future and will buy back the shares it sold to a private equity firm brought in 13 months ago to pursue an IPO.</p>
<p>In January 2011, General Atlantic bought 20% of Kaspersky, valued at about $200 million, from Eugene Kaspersky and his ex-wife Natalya. GA was brought in at the time to seek acquisition opportunities and set Kaspersky Lab up for an initial public offering.</p>
<p>&#8220;It&#8217;s quite a big deal, the biggest deal of my life,&#8221; Kaspersky said at the Kaspersky Security Analyst Summit 2012. &#8220;The company will stay private and stay focused on IT security.&#8221;</p>
<p>Kaspersky said the main motivation for the buy-back was the preservation of the company culture.</p>
<p>&#8220;IT security has to be flexivble and innovating. My impression is that being private is the right way because you don&#8217;t need to report [finances],&#8221; Kaspersky said. &#8220;I like the way company is going and the spirt of the company. To change their basic design, I&#8217;m afraid is dangerous. We are not going to change our ways, spirit, culture, emotion or strategy.&#8221;</p>
<p>Kaspersky said he could see the company branch beyond its core consumer and enterprise antimalware expertise. The company has a worldwide stable of security researchers with offices in 29 countries. Kaspersky said the company is profitable (less than 20% year over year growth), and promised to remain as transparent as possible in its financial disclosures.</p>
<p>&#8220;[If public], there are much more reports and governance and a longer decision-making process,&#8221; Kaspersky said. &#8220;I have the same feeling that I read in Richard Branson&#8217;s book that when you go public, the company goes slower. I don&#8217;t want that.&#8221;</p>

<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:2d18aaec8fd11dde0ec6ad420a635a6d:xTIc%2FOom%2Fy3IMFosYEaPeEPlnNLFJBG5ZwuuoiZR32ayDFU4IMUQ25e%2FMRW1X7lu2dNC%2FpgO%2Feul1Ps%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:5636b5d8be70ae3c2d84c8fbd02b571b:9hTZmqF7m03dWjq82kam%2F4j3CSd2W2M9UqG0PxAXwkjIiGIXGP4DEajleGxVTdBNvgLHqn%2B6Hv2uPfs%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:9a3925c8906c1f313341328a41c3173d:pIeOI0kQF%2Fo%2Fl1L2Nk%2BQd0CyZUvbQXURJxEtWiZQiyyg5LLgfSd5D%2BgJkE5Wg3dMGQKa2i6CkPSK7g%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:f8dcd12c90e33b7aa69ec5a705f87539:S9k42bPUNxoOEM6M3d%2FU%2BJ1Fuc33T4spCid8cw2zXE30%2BpvxuIeIc9covUrmD6jnfwRVE9mbWFteAg%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=7867d33d89e89ccb67c58793106a5618&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=7867d33d89e89ccb67c58793106a5618&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-bytes/kaspersky-buys-out-equity-firm-keeps-security-company-private/feed/</wfw:commentRss>
		</item>
		<item>
			<title>Faith in webmasters&#8217; security rewarded-kinda</title>
			<link>http://www.pheedcontent.com/click.phdo?i=e770cc751e3a683483e7c4c3494d297a</link>
			<pheedo:origLink>http://itknowledgeexchange.techtarget.com/security-bytes/faith-in-webmasters-security-rewarded-kinda/</pheedo:origLink>
			<comments>http://itknowledgeexchange.techtarget.com/security-bytes/faith-in-webmasters-security-rewarded-kinda/#comments</comments>
			<pubDate>Fri, 03 Feb 2012 01:12:00 +0000</pubDate>
			<dc:creator>Michael S. Mimoso</dc:creator>
			<category><![CDATA[Kaspersky]]></category>
			<category><![CDATA[drive-by downloads]]></category>
			<category><![CDATA[malware]]></category>
			<category><![CDATA[infected websites]]></category>
			<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-bytes/faith-in-webmasters-security-rewarded-kinda/</guid>
			<description><![CDATA[
CANCUN, Mexico &#8212; Kaspersky Labs senior security research Stefan Tanase knows all about the old adage &#8220;You never know until you ask.&#8221;
Tanase conducted an experiment recently where he emailed the webmasters of 100 websites infected with malware informing them of the problem asking in return only for some data on the infections in the form [...]<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:3b44393be8758e69667afb7b2db177e3:Vb6uJhfXjF3y%2Bpz5rf%2BtG7ILKXl693O6GXnCUjkH1AXSG0xku%2BsDcaQKfCefA1RTohMLiFSXAaX1yO4%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:49340f50af901e495e09c73135554988:RoV96clCXvQYxpZrPBoKPsl4I2CjF3X2y00D3SMsbcZRREWExjEDQm9p9pa9GkhgmaT9qUt%2BH%2BZIPZg%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:611c9a2ba3a9e7e55245e5c525b79d46:tAkuJca0pb5ULddamf0EMX5fNFQV4xHHn2bWlQT6vkqzr155VENNz%2Fzx1YRF8zjl2%2B4NYyS9VEmYww%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:18c3b807a38253c91304ad69d2729906:s1ALyMwS1iApSYiWXd7bEKjOb%2FdH8mJtji5ufapGH5FyApemqBiKCQm77vRjMlhmYDKAJEHKoLCvtw%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=e770cc751e3a683483e7c4c3494d297a&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=e770cc751e3a683483e7c4c3494d297a&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></description>
			<content:encoded><![CDATA[
<p>CANCUN, Mexico &#8212; Kaspersky Labs senior security research Stefan Tanase knows all about the old adage &#8220;You never know until you ask.&#8221;</p>
<p>Tanase conducted an experiment recently where he emailed the webmasters of 100 websites infected with malware informing them of the problem asking in return only for some data on the infections in the form of log entries. What Tanase got in return was a big fat zero, as in no replies.</p>
<p>Undeterred, Tanase said Wednesday during the Kaspersky Lab Security Analyst Summit 2012, that he emailed another 200 and actually got a 3% reply rate time on his second attempt.</p>
<p>&#8220;The assumption I made is that webmasters don&#8217;t know their sites are infected,&#8221; he said. &#8220;The reality is that webmasters don&#8217;t care if their sites are infected.&#8221;</p>
<p>Tanase said he knows 52% of his emails reached their destination; 48% bounced back to him.</p>
<p>Of the three percent who did reply, one came from a monestary and a priest who asked for help in cleaning up the websites and under what conditions. Another respondent came from an advertising agency that wasn&#8217;t interested because the infected site in question was an old site no longer in use. Another, from an industrial equipment supplier, said they didn&#8217;t have a dedicated IT person on staff, but offered to send Tanase an administrative username and password and wondered if he could help&#8211;a major security fail.</p>
<p>The experiment, however, wasn&#8217;t a total bust; 3% may have replied, but upon a second scan, 5% had removed the malware from their sites.</p>
<p>&#8220;They may not have replied,&#8221; Tanase said, &#8220;but they did clean up their site.&#8221;</p>

<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:3b44393be8758e69667afb7b2db177e3:Vb6uJhfXjF3y%2Bpz5rf%2BtG7ILKXl693O6GXnCUjkH1AXSG0xku%2BsDcaQKfCefA1RTohMLiFSXAaX1yO4%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:49340f50af901e495e09c73135554988:RoV96clCXvQYxpZrPBoKPsl4I2CjF3X2y00D3SMsbcZRREWExjEDQm9p9pa9GkhgmaT9qUt%2BH%2BZIPZg%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:611c9a2ba3a9e7e55245e5c525b79d46:tAkuJca0pb5ULddamf0EMX5fNFQV4xHHn2bWlQT6vkqzr155VENNz%2Fzx1YRF8zjl2%2B4NYyS9VEmYww%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:18c3b807a38253c91304ad69d2729906:s1ALyMwS1iApSYiWXd7bEKjOb%2FdH8mJtji5ufapGH5FyApemqBiKCQm77vRjMlhmYDKAJEHKoLCvtw%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=e770cc751e3a683483e7c4c3494d297a&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=e770cc751e3a683483e7c4c3494d297a&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-bytes/faith-in-webmasters-security-rewarded-kinda/feed/</wfw:commentRss>
		</item>
		<item>
			<title>Typosquatter hive targets holiday shoppers</title>
			<link>http://www.pheedcontent.com/click.phdo?i=d1db68fd65cec8b6863f59bf2a835698</link>
			<pheedo:origLink>http://itknowledgeexchange.techtarget.com/security-bytes/typosquatter-hive-targets-holiday-shoppers/</pheedo:origLink>
			<comments>http://itknowledgeexchange.techtarget.com/security-bytes/typosquatter-hive-targets-holiday-shoppers/#comments</comments>
			<pubDate>Tue, 20 Dec 2011 15:25:13 +0000</pubDate>
			<dc:creator>admin</dc:creator>
			<category><![CDATA[typosquatting]]></category>
			<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-bytes/typosquatter-hive-targets-holiday-shoppers/</guid>
			<description><![CDATA[
Every year the holiday season is a boon to typosquatters using scams to phish unsuspecting users of sensitive information or peddle rogue antivirus software.
By Hillary O&#8217;Rourke, Contributor
With the hassle of finding the best deal and coping with the constant crowds, online shopping has never been more popular for the holiday season. But with that ease [...]<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:cd14242a362fb1528e91798be0a43efd:d%2FsR81RU%2FdQb3s9ClljTGYR69eUl63e9mrkS1W5LdCX8ZfmMw2o%2FrbBcvjrts0fQfBv46yiURgWYiD8%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:63f11cca9bd2e367c735229bb72d8817:ymNbEuHWeQPuz014O%2BwFDpgeu86EOVoHbz7z3xWfjIquDrabRDRqSWrSZTdR4w9TlITwd1WFfpTAFgo%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:ea0b9e2ac6b311adefc892dfab8d9a71:xaA5fULtrMLXpFXjNVe2UKL9G%2BisuKLsK42XXsSQT%2F1bR4ZO45gMimSqfXe1cti06HZheWvSWi8Zlg%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:cf8fddd4545d691784b9167a71f4452b:XgjFxPWxa7EhLTJsVWGiiUp%2BTx5k3%2F7Ai0AF6%2FV%2BAGwoZyjnM02lHcaF6%2Bbp1AN%2Fj5HS6%2FeKL7EGpg%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=d1db68fd65cec8b6863f59bf2a835698&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=d1db68fd65cec8b6863f59bf2a835698&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></description>
			<content:encoded><![CDATA[
<p><strong>Every year the holiday season is a boon to <a title="Typosquatters plague enterprises" href="http://searchsecurity.techtarget.com/news/2240083592/Typosquatters-continue-to-plague-enterprises-trap-victims" target="_blank">typosquatters</a> using scams to phish unsuspecting users of sensitive information or peddle rogue antivirus software.</strong></p>
<p>By Hillary O&#8217;Rourke, Contributor</p>
<p>With the hassle of finding the best deal and coping with the constant crowds, online shopping has never been more popular for the holiday season. But with that ease comes a warning from Websense: keep an eye out for online scams, particularly typosquatted sites.</p>
<p>Researchers at security research company Websense, Inc. are warning online holiday shoppers of typosquatted online domains, domains that cybercriminals have registered that are virtual but malicious copies of familiar sites in hopes of taking advantage of those who misspell the URL.</p>
<p>Websense researchers have claimed they’ve recently found more than <a title="A typosquat hostname list for Xmas " href="http://community.websense.com/blogs/securitylabs/archive/2011/12/08/a-typosquat-hostname-list-for-xmas_2D00_.aspx?cmpid=prnr12.13.11">2,000 typosquatted online domains</a> set up. Websense published a <a href="http://community.websense.com/cfs-filesystemfile.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/securitylabs/3324.typo_5F00_list_5F00_.txt" target="_blank">list of domains</a> it found as part of a network of typosquatters, attempting to pose as a legitimate UK brand-name sites.  Websense said it has a &#8220;list of hundreds of hosts that are part of a typosquat hive (the hive  itself contains thousands of hosts), and all of them are hosted in the  US. We call it a hive because all of the listed hosts have a connection,  and were most likely set up by the same cybercriminals.&#8221;</p>
<p>Researchers are also claiming that although the brand names may be spelled correctly in the domain, cybercriminals have created sites with the “.org” or “.net” domain suffixes as well. They added that they’ve seen a recent influx of these <a href="http://searchfinancialsecurity.techtarget.com/news/1360611/Online-scammers-exploit-bank-brands-and-consumers-financial-woes" target="_blank">fraudulent domains</a> in preparation for the holiday season.</p>
<p>The attackers often use these websites in fake emails and phishing sites in an attempt to lure consumers to claim online coupons. After a user clicks on the provided link, a pop-up shows up in another window with a different offer.</p>
<blockquote><p>It&#8217;s important to remember that legitimate websites and the companies  behind them sometimes employ a strategy of buying typosquat hosts that  are similar to their site&#8217;s name. This is a good strategy for  successful websites, as those companies usually understand the dangers  of typosquatting and how their brand name can be affected and  abused. Kudos go to Amazon, which registered a good number of potential  typosquat hosts, including aqmazon (dot) com, amaxzon (dot) com, amzon (dot) com, and many  more. These are all <strong>GOOD hosts </strong>registered by Amazon itself, leaving no chance for abuse as long as they remain registered to Amazon.</p></blockquote>
<p>Typosquatting is used to quickly gain advertising revenue from sites receiving a high volume of accidental traffic. More recently, however, it’s often more about collecting as much information as the cybercriminals can get. With the holiday season in full swing, cybercriminals should expect to see success in both of those areas.</p>
<p>As the Websense says, it’s all “to ensnare the unaware.”</p>

<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:cd14242a362fb1528e91798be0a43efd:d%2FsR81RU%2FdQb3s9ClljTGYR69eUl63e9mrkS1W5LdCX8ZfmMw2o%2FrbBcvjrts0fQfBv46yiURgWYiD8%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:63f11cca9bd2e367c735229bb72d8817:ymNbEuHWeQPuz014O%2BwFDpgeu86EOVoHbz7z3xWfjIquDrabRDRqSWrSZTdR4w9TlITwd1WFfpTAFgo%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:ea0b9e2ac6b311adefc892dfab8d9a71:xaA5fULtrMLXpFXjNVe2UKL9G%2BisuKLsK42XXsSQT%2F1bR4ZO45gMimSqfXe1cti06HZheWvSWi8Zlg%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:cf8fddd4545d691784b9167a71f4452b:XgjFxPWxa7EhLTJsVWGiiUp%2BTx5k3%2F7Ai0AF6%2FV%2BAGwoZyjnM02lHcaF6%2Bbp1AN%2Fj5HS6%2FeKL7EGpg%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=d1db68fd65cec8b6863f59bf2a835698&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=d1db68fd65cec8b6863f59bf2a835698&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-bytes/typosquatter-hive-targets-holiday-shoppers/feed/</wfw:commentRss>
		</item>
		<item>
			<title>Nitro attackers sending malicious emails using Symantec report</title>
			<link>http://www.pheedcontent.com/click.phdo?i=df8a0c742e7a2857c6afcdee660e7fbb</link>
			<pheedo:origLink>http://itknowledgeexchange.techtarget.com/security-bytes/nitro-attackers-sending-malicious-emails-using-symantec-report/</pheedo:origLink>
			<comments>http://itknowledgeexchange.techtarget.com/security-bytes/nitro-attackers-sending-malicious-emails-using-symantec-report/#comments</comments>
			<pubDate>Wed, 14 Dec 2011 16:56:54 +0000</pubDate>
			<dc:creator>admin</dc:creator>
			<category><![CDATA[cyberattacks]]></category>
			<category><![CDATA[email security]]></category>
			<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-bytes/nitro-attackers-sending-malicious-emails-using-symantec-report/</guid>
			<description><![CDATA[
By Hillary O&#8217;Rourke, Contributor
The cybercriminals responsible for the Nitro attacks have certainly showed audacity in their latest move: Sending malicious emails claiming to be from security vendor Symantec with the company’s own report on those Nitro attacks. 
According to a Symantec blog post, the group, which is currently targeting chemical companies, is using the same [...]<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:4ad101ff98d8a83b4222ad4f4ace0532:lmQ2BtnxRg3TUEXohL3oyDdUgaWE4Mavt2o3eC9SHBMyoGJlDCqKN7toYlET6bkWQpP8LUgsCOWcqNQ%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:6a8589bd0d049b46dc648bc40c5a1d17:PrWI%2FZDBwRig%2BOPYkFc%2FbhsE%2F%2BbLjfmWovljCsaoDmuvMGXRWJ7GqNMIm1AE%2BQn99v4udX7UHsF8Wkw%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:5751830e98e16b58513d2de5f43e3b64:y1l5ukvjBd5SoFxxo%2BelASkSs75L5IRqV0GwykJgs%2FQwMtRXZ%2BXMT%2Fsdsy7PKXFGkE8UmBBycOZueg%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:40bbf51e2fdb1215f7211d5f428eb291:1bw8Q2shzgyPRFifwvqS%2FLVj6pXTGrWsZ2Uf%2BeIr7RQfglI7FfIeTEEzUL%2BH6kDoNGCV%2FIeQd%2B%2F4XA%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=df8a0c742e7a2857c6afcdee660e7fbb&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=df8a0c742e7a2857c6afcdee660e7fbb&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></description>
			<content:encoded><![CDATA[
<p>By Hillary O&#8217;Rourke, Contributor</p>
<p>The cybercriminals responsible for the Nitro attacks have certainly showed audacity in their latest move: Sending malicious emails claiming to be from security vendor Symantec with the company’s own report on those Nitro attacks. </p>
<p>According to a Symantec blog post, the group, which is currently targeting chemical companies, is using the same social engineering techniques they have used in previous attacks, but lately they have been sending malicious emails that are created to look like they were sent by Symantec’s technical support department. </p>
<p>“They are sending targets a password-protected archive, through email, which contains a malicious executable,” explained Symantec researchers keeping a close watch on the group&#8217;s attack techniques. “The executable is a variant of the Poison IVY and the email topic is some form of upgrade to popular software, or a security update.”</p>
<p>The security vendor originally exposed the gang in a report released on Nov. 1 on the Nitro attacks that began in July and lasted until September. Those attacks also involved emails carrying a variant of the Poison Ivy backdoor and were specially crafted for each targeted company. According to the blog post, they are still using the same hosting provider for their command and control (C&amp;C) servers.</p>
<p>The Symantec blog post explains one of the emails ‘offers protection from “poison Ivy Trojan’!”</p>
<p>The fraudulent emails come with an attachment called “the_nitro_attackspdf.7z” with an archive containing a file called “the_nitro_attackspdf.exe.” According to the blog post, the large space between “pdf” and “.exe.” is to trick a user into thinking the attachment is a PDF.<br />
When the attachment is opened, the executable creates a file called Isass.exe, more commonly known as Poison IVY, and then creates a PDF file that is none other than Symantec’s Nitro Attacks whitepaper (PDF). </p>
<p>“The attackers, in an attempt to lend some validity to their email, are sending a document to targets that describes their very own activity,” Symantec said.</p>

<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:4ad101ff98d8a83b4222ad4f4ace0532:lmQ2BtnxRg3TUEXohL3oyDdUgaWE4Mavt2o3eC9SHBMyoGJlDCqKN7toYlET6bkWQpP8LUgsCOWcqNQ%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:6a8589bd0d049b46dc648bc40c5a1d17:PrWI%2FZDBwRig%2BOPYkFc%2FbhsE%2F%2BbLjfmWovljCsaoDmuvMGXRWJ7GqNMIm1AE%2BQn99v4udX7UHsF8Wkw%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:5751830e98e16b58513d2de5f43e3b64:y1l5ukvjBd5SoFxxo%2BelASkSs75L5IRqV0GwykJgs%2FQwMtRXZ%2BXMT%2Fsdsy7PKXFGkE8UmBBycOZueg%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:40bbf51e2fdb1215f7211d5f428eb291:1bw8Q2shzgyPRFifwvqS%2FLVj6pXTGrWsZ2Uf%2BeIr7RQfglI7FfIeTEEzUL%2BH6kDoNGCV%2FIeQd%2B%2F4XA%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=df8a0c742e7a2857c6afcdee660e7fbb&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=df8a0c742e7a2857c6afcdee660e7fbb&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-bytes/nitro-attackers-sending-malicious-emails-using-symantec-report/feed/</wfw:commentRss>
		</item>
		<item>
			<title>Symantec launches mobile security evaluation, app assessment services</title>
			<link>http://www.pheedcontent.com/click.phdo?i=650539b5038f4ff48f04326287f103f2</link>
			<pheedo:origLink>http://itknowledgeexchange.techtarget.com/security-bytes/symantec-launches-mobile-security-evaluation-app-assessment-services/</pheedo:origLink>
			<comments>http://itknowledgeexchange.techtarget.com/security-bytes/symantec-launches-mobile-security-evaluation-app-assessment-services/#comments</comments>
			<pubDate>Tue, 06 Dec 2011 15:27:03 +0000</pubDate>
			<dc:creator>Robert Westervelt</dc:creator>
			<category><![CDATA[mobile security]]></category>
			<category><![CDATA[mobile applications]]></category>
			<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-bytes/symantec-launches-mobile-security-evaluation-app-assessment-services/</guid>
			<description><![CDATA[
Security assessment reviews an organization’s mobile security policies and technologies, evaluating the mobile security posture against a set of 15 core elements.
Symantec’s consulting team is launching a mobile security assessment service, designed to assess a business’ mobile security policies and defensive technologies.
The new service is an extension of the Symantec Security Program Assessment. Symantec created [...]<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:41a5fb4d1be4d87b14f63347aea15641:5kukegqfHZ4xblMJXl4end0AdiAD5l7oSKL%2BMFZdgB5ddbuXge5ieKaUjYc6n5SEWw7Hd6VEnASs1cU%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:3d18afb9d2a2f79c15be4870005e7be2:dO4e5aHUKPg3DsijltGCl%2FB04IwWMj3T6u5TjHWp%2FtjA1HH6YmWCf%2BUeVZ%2FO4%2FTslG4zXPcBKxCDQDQ%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:16a01f5538d1fef00549f69b309160a6:g5rVuvTcykwbeaOqbsBT5f2pGSGE%2Bsv8FKYAYOMRHR9YjxKPEztqoT2yu06dB94e%2Fl3exFqUSn6cyQ%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:8a52a460b60eaadabea9642f4947dc7c:3PWOvYtS5M2VG0mMBmajVoAZFDc4Fop%2FApM5QLI9qZqbNcYurBLhCuHEC7wI0tBRFxoynbdntvycqA%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=650539b5038f4ff48f04326287f103f2&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=650539b5038f4ff48f04326287f103f2&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></description>
			<content:encoded><![CDATA[
<p><strong>Security assessment reviews an organization’s mobile security policies and technologies, evaluating the mobile security posture against a set of 15 core elements.</strong></p>
<p>Symantec’s consulting team is launching a <a title="Symantec Mobile Security Assessment" href="http://www.symantec.com/business/services/detail/detail.jsp?pcid=consulting_services&amp;pvid=svc_msa_suite&amp;om_ext_cid=biz_socmed_twitter_facebook_marketwire_linkedin_2011Dec_worldwide_mobilesecurityassessmentsuite" target="_blank">mobile security assessment service</a>, designed to assess a business’ mobile security policies and defensive technologies.</p>
<p>The new service is an extension of the Symantec Security Program Assessment. Symantec created a Mobile Security Framework that is designed to evaluate how a business addresses mobile device security from a governance, intelligence and infrastructure perspective. Among the 15 core elements that make up the framework are policies, standards and awareness, asset inventory and ownership, application security and monitoring and reporting metrics.</p>
<p>Symantec’s mobile assessment service is one of many available to enterprises. Security vendors have been quick to offer a variety of mobile services and products because businesses have been inundated with employees bringing in personal devices that they expect to connect to the corporate network. For example, McAfee, Verizon Business, IBM and other firms provide a variety of consulting services that can evaluate security programs and more specifically, an organization’s mobile security posture. Experts have been touting ways to <a title="Mobile security policy writing" href="http://searchsecurity.techtarget.com/tip/How-to-write-an-effective-enterprise-mobile-device-security-policy" target="_blank">write effective mobile security policies</a> to address the influx. Technologies are available to address <a href="http://searchsecurity.techtarget.com/news/2240110848/Without-enforcement-a-mobile-device-security-policy-alone-falls-short" target="_blank">policy enforcement across platforms</a> and control access to sensitive data.</p>
<p>In an interview with&nbsp;<a href="http://SearchSecurity.com" title="http://SearchSecurity. " target="_blank">SearchSecurity.com</a>, Franklin Witter, manager of security business practices at Symantec, said his consulting team will use a series of surveys, workshops and interviews to understand the organization’s risk tolerance and practices and technologies already in place.  “We want to understand the business use case for mobile technology in the enterprise,” Witter said.</p>
<p>The goal is to lay out a security plan that addresses the strengths and weaknesses inherent in each mobile platform, Witter said. Organizations will get a better understanding of the gaps in their current state of maturity.</p>
<p>Witter said Symantec clients that have undergone a full security program assessment have been asking for a more focused mobile evaluation. “Our advisory team takes a product agnostic approach,” Witter said. “We’re not solely focused on Symantec products.”</p>
<p>The Symantec Mobile Security Assessment Suite costs about $40,000. Organizations that undergo the review are given a final written report and scorecard illustrating the organization’s mobile security readiness. The report also provides recommendations and an action plan to address existing gaps.<br />
Mobile Application Assessment Service</p>
<p>Symantec also rolled out an application assessment service designed to test mobile apps for a variety of coding errors that could lead to data leakage or a costly data breach. Witter said the testing will be offered in either a white-box or black-box testing. The cost of the evaluation will depend on the scope of the project, he said.</p>
<p>The application assessment service has been operating for about a year. Symantec is seeing an increase in businesses designing custom applications for either employee use or for their customers.</p>
<p>The assessment can identify issues with authentication and authorization, data validation, session management, encryption, auditing and logging and the business logic of a mobile application. It can be performed in conjunction with a penetration assessment to provide a more deeper view of vulnerabilities.</p>

<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:41a5fb4d1be4d87b14f63347aea15641:5kukegqfHZ4xblMJXl4end0AdiAD5l7oSKL%2BMFZdgB5ddbuXge5ieKaUjYc6n5SEWw7Hd6VEnASs1cU%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:3d18afb9d2a2f79c15be4870005e7be2:dO4e5aHUKPg3DsijltGCl%2FB04IwWMj3T6u5TjHWp%2FtjA1HH6YmWCf%2BUeVZ%2FO4%2FTslG4zXPcBKxCDQDQ%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:16a01f5538d1fef00549f69b309160a6:g5rVuvTcykwbeaOqbsBT5f2pGSGE%2Bsv8FKYAYOMRHR9YjxKPEztqoT2yu06dB94e%2Fl3exFqUSn6cyQ%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:8a52a460b60eaadabea9642f4947dc7c:3PWOvYtS5M2VG0mMBmajVoAZFDc4Fop%2FApM5QLI9qZqbNcYurBLhCuHEC7wI0tBRFxoynbdntvycqA%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=650539b5038f4ff48f04326287f103f2&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=650539b5038f4ff48f04326287f103f2&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-bytes/symantec-launches-mobile-security-evaluation-app-assessment-services/feed/</wfw:commentRss>
		</item>
		<item>
			<title>Rapid7 massive VC funding opens door to acquisitions, expansion and maybe IPO?</title>
			<link>http://www.pheedcontent.com/click.phdo?i=1a017ba4c9dcc8a45b6332e950491fdd</link>
			<pheedo:origLink>http://itknowledgeexchange.techtarget.com/security-bytes/rapid7-massive-vc-funding-opens-door-to-acquisitions-expansion-and-maybe-ipo/</pheedo:origLink>
			<comments>http://itknowledgeexchange.techtarget.com/security-bytes/rapid7-massive-vc-funding-opens-door-to-acquisitions-expansion-and-maybe-ipo/#comments</comments>
			<pubDate>Thu, 17 Nov 2011 19:24:47 +0000</pubDate>
			<dc:creator>Michael S. Mimoso</dc:creator>
			<category><![CDATA[Metasploit Framework]]></category>
			<category><![CDATA[Metasploit Project]]></category>
			<category><![CDATA[Rapid7]]></category>
			<category><![CDATA[vulnerability management]]></category>
			<category><![CDATA[penetration testing]]></category>
			<category><![CDATA[VC funding]]></category>
			<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-bytes/rapid7-massive-vc-funding-opens-door-to-acquisitions-expansion-and-maybe-ipo/</guid>
			<description><![CDATA[
Vulnerability management company Rapid7, commercial home of the Metasploit Project, announced today it has secured $50 million in venture funding from Technology Crossover Ventures of Palo Alto, Calif. The company said it will use the money for new hires, international expansion and to explore acquisitions. Bigger picture, Rapid7 could also position itself for an initial [...]<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:6808bddb1e51a0beeb2b7d481cf79e87:ntn1caP3z%2FSPV5ZsPorgcpLg6Q8smU7b1cQ5aYhgXbwRF62fLVd%2BhZ47Uaw%2F%2FazImD%2F5Jrbrhi%2F%2BGAs%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:c76c2ab843a5b464b41c83078768b536:r%2FHzAYjaOw1vTG8yLGNMxQ9BDWrLCnIZhC6jAS6T%2FMkbkKuGRKS1DDnD21maQnDRVCdqctXPOKoxpm0%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:1caeb63de327c1a291d2408a57105d33:LyJ5MsQa6ETB1nC2VfNzIy9Z9eLt%2FQhYzUyOiXpZ1mapCu06oe%2FWAH%2FBkA6nA9q60NuQANZ%2BF6WBjw%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:34e24c8109b1962ce4e1d2a4a0e230d8:eZpPrtyG8VTI1c79WemZRpZQLhiNIrz%2BBDSPHMJ56cIojmv4vc9PQNfUAXOmN4AdS1oYUFXHQddIUw%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=1a017ba4c9dcc8a45b6332e950491fdd&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=1a017ba4c9dcc8a45b6332e950491fdd&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></description>
			<content:encoded><![CDATA[
<p class="MsoNormal"><span>Vulnerability management company Rapid7, commercial home of the Metasploit Project, announced today it has secured $50 million in venture funding from Technology Crossover Ventures of Palo Alto, Calif. The company said it will use the money for new hires, international expansion and to explore acquisitions. Bigger picture, Rapid7 could also position itself for an initial public offering, something CEO Mike Tuchen would not address in an interview with&nbsp;<a href="http://SearchSecurity.com" title="http://SearchSecurity. " target="_blank">SearchSecurity.com</a>. </span></p>
<p class="MsoNormal"><span>“This will help us accelerate our ability to drive product innovation, expand our operations internationally and also go shopping,” Tuchen said. “We plan to pursue strategic acquisitions that would line up with our business. We think we have a unique portfolio in the assessment business, which is a strategically important area for us as a vendor and an important problem for companies to solve.”</span></p>
<p class="MsoNormal"><span>Rapid7’s flagship product is its Nexpose vulnerability management platform, which scans networks, applications and databases for vulnerabilities. Rapid7 also houses the <a href="http://searchsecurity.techtarget.in/tip/Metasploit-tutorial-part-1-Inside-the-Metasploit-framework"><span style="color: blue">Metasploit Project</span></a> and the <a href="http://searchsecurity.techtarget.com/tip/Screencast-Penetration-testing-with-Metasploit"><span style="color: blue">Metasploit Framework</span></a>, a platform used by penetration testers and vulnerability assessment products to execute exploits against targets. Tuchen said Metasploit, backed by its large, active open source community, was an important piece of the puzzle for investors.</span></p>
<p class="MsoNormal"><span>“$50 million validates what we’re doing as a company and the interest in security as a sector and Rapid 7 as a company,” Tuchen said, adding that up to a half-dozen VC firms were interested in investing in Rapid7, which help push the number to $50 million. </span></p>
<p class="MsoNormal"><span>Tuchen said his top priority for the immediate future is hiring talent to stock a new innovation center at its Boston headquarters, grow engineering teams in California and Texas and staff new international offices in London and Hong Kong. </span></p>
<p class="MsoNormal"><span>“It’s all about hiring, and getting the right team and leadership in place and building and scaling out our engineering teams and finding the right leader in EMEA,” Tuchen said. “I’ll be busy hiring, and in my spare time, doing a little shopping.”</span></p>
<p class="MsoNormal"><span>Rapid7 said it has grown revenue more than 900 percent over the past four years, boasting 10 quarters of record revenue through Q3 of this year. The company said it has more than 1,700 customers worldwide and is a growing company in a market whose predicted revenue, according to IDC, is expected to top $5.2 billion by 2015. </span></p>
<p class="MsoNormal"><span>Technology Crossover Ventures general partner Tim McAdam will become the newest member of Rapid7’s board of directors. TCV is a new investor in Rapid7; Bain Capital Ventures is Rapid7’s other VC investor. </span></p>

<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:6808bddb1e51a0beeb2b7d481cf79e87:ntn1caP3z%2FSPV5ZsPorgcpLg6Q8smU7b1cQ5aYhgXbwRF62fLVd%2BhZ47Uaw%2F%2FazImD%2F5Jrbrhi%2F%2BGAs%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:c76c2ab843a5b464b41c83078768b536:r%2FHzAYjaOw1vTG8yLGNMxQ9BDWrLCnIZhC6jAS6T%2FMkbkKuGRKS1DDnD21maQnDRVCdqctXPOKoxpm0%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:1caeb63de327c1a291d2408a57105d33:LyJ5MsQa6ETB1nC2VfNzIy9Z9eLt%2FQhYzUyOiXpZ1mapCu06oe%2FWAH%2FBkA6nA9q60NuQANZ%2BF6WBjw%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:34e24c8109b1962ce4e1d2a4a0e230d8:eZpPrtyG8VTI1c79WemZRpZQLhiNIrz%2BBDSPHMJ56cIojmv4vc9PQNfUAXOmN4AdS1oYUFXHQddIUw%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=1a017ba4c9dcc8a45b6332e950491fdd&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=1a017ba4c9dcc8a45b6332e950491fdd&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-bytes/rapid7-massive-vc-funding-opens-door-to-acquisitions-expansion-and-maybe-ipo/feed/</wfw:commentRss>
		</item>
		<item>
			<title>Cloud security among PCI Council 2012 special interest groups</title>
			<link>http://www.pheedcontent.com/click.phdo?i=ae8815432f5a0663ae1c735fdcd452bf</link>
			<pheedo:origLink>http://itknowledgeexchange.techtarget.com/security-bytes/cloud-security-among-pci-council-2012-special-interest-groups/</pheedo:origLink>
			<comments>http://itknowledgeexchange.techtarget.com/security-bytes/cloud-security-among-pci-council-2012-special-interest-groups/#comments</comments>
			<pubDate>Wed, 16 Nov 2011 17:42:56 +0000</pubDate>
			<dc:creator>Michael S. Mimoso</dc:creator>
			<category><![CDATA[PCI Special Interest Groups]]></category>
			<category><![CDATA[PCI Cloud SIG]]></category>
			<category><![CDATA[PCI ECommerce Security SIG]]></category>
			<category><![CDATA[PCI Risk Assessment SIG]]></category>
			<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-bytes/cloud-security-among-pci-council-2012-special-interest-groups/</guid>
			<description><![CDATA[
The PCI Security Standards Council announced the latest slate of special interest groups that it will prioritize next year. Merchants, financial institutions, service providers and others voted on a variety of potential SIGs before settling on cloud, ecommerce security and risk assessment.
This is the first time SIG selection was put to a vote, and more [...]<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:0ff83a8be0354351b11472eec9dc210c:usXrBhdEj%2BsmU0s86ZqhnsmjALA7fwMvvAT0rgbSq9ayDLX53rf9dqBVZ2SB%2By%2Bf2cPFTCRS8rqKAmk%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:5275dc65406a693cae25e40d3ea6d6f4:sj1cxpCH4bTXNb5BgBcj11dygnTKc2uKbX%2Fw4ImjhbY2cjhRmcc%2BlyS%2BZHYpbeB22BGrd2GZZYCzNnU%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:f1d6e117dd8707d323067c00bd551825:GN4qdc4RwrNSStDbevJw4E4d6dHN3%2FCi1e5qdZ%2FDeXlA1jSciXAx2%2BJfAQXNbvau1GtCbRNraHW%2FeQ%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:1368c6542315e2432f5ca72833b3db18:eehXMzNl1TRlHh3TbGTA3TmLhk6daFENdy1zIBgjrQ3dVK5TLcVnL%2B6UlKPwVDChGyEGg66qC%2F1Y%2Bw%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=ae8815432f5a0663ae1c735fdcd452bf&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=ae8815432f5a0663ae1c735fdcd452bf&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></description>
			<content:encoded><![CDATA[
<p>The PCI Security Standards Council announced the latest slate of special interest groups that it will prioritize next year. Merchants, financial institutions, service providers and others voted on a variety of potential SIGs before settling on cloud, ecommerce security and risk assessment.</p>
<p>This is the first time SIG selection was put to a vote, and more than 500 were cast, close to a quarter of the SSC&#8217;s participating organizations, said Jeremy King, European director of the PCI SSC, who added that one-third of the votes cast came from outside North America.</p>
<p>PCI SIGs are essentially forums for feedback on topics that ultimately is turned into guidance for interpreting and implementing existing or new mandates to the standard, the SSC said in a release. This year, the SSC released guidance on <a href="http://searchsecurity.techtarget.com/tip/Analysis-PCI-Tokenization-Guidelines-offer-clarity-but-questions-remain">tokenization</a>, <a href="http://searchsecurity.techtarget.com/news/2240086590/PCI-Council-issues-point-to-point-encryption-validation-requirements">point-to-point encryption </a>and <a href="http://searchcloudsecurity.techtarget.com/tip/What-the-PCI-virtualization-guidance-means-for-PCI-compliance-in-the-cloud">virtualization</a>.</p>
<p>SIGs are made up of merchants, payment processors and qualified security assessors. SIGs must complete their efforts and deliver a guidance document within one year.</p>
<p>This year, voters had seven potential SIGs to choose from, and were asked to select a top three. The seven, according to the <a href="http://storefrontbacktalk.com/securityfraud/vote-now-why-retailers-really-should-help-select-pci-sigs/">Storefront BackTalk blog</a>, were: administrative access to systems and devices; how to write a risk assessment; patch management; ecommerce guidelines; <a href="http://searchsecurity.techtarget.com/answer/Cloud-computing-PCI-compliance-Is-it-possible">PCI in the cloud</a>; small business and PCI; and managing hosted service providers.</p>

<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:0ff83a8be0354351b11472eec9dc210c:usXrBhdEj%2BsmU0s86ZqhnsmjALA7fwMvvAT0rgbSq9ayDLX53rf9dqBVZ2SB%2By%2Bf2cPFTCRS8rqKAmk%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:5275dc65406a693cae25e40d3ea6d6f4:sj1cxpCH4bTXNb5BgBcj11dygnTKc2uKbX%2Fw4ImjhbY2cjhRmcc%2BlyS%2BZHYpbeB22BGrd2GZZYCzNnU%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:f1d6e117dd8707d323067c00bd551825:GN4qdc4RwrNSStDbevJw4E4d6dHN3%2FCi1e5qdZ%2FDeXlA1jSciXAx2%2BJfAQXNbvau1GtCbRNraHW%2FeQ%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:1368c6542315e2432f5ca72833b3db18:eehXMzNl1TRlHh3TbGTA3TmLhk6daFENdy1zIBgjrQ3dVK5TLcVnL%2B6UlKPwVDChGyEGg66qC%2F1Y%2Bw%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=ae8815432f5a0663ae1c735fdcd452bf&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=ae8815432f5a0663ae1c735fdcd452bf&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-bytes/cloud-security-among-pci-council-2012-special-interest-groups/feed/</wfw:commentRss>
		</item>
		<item>
			<title>Report: &#8216;R&#38;D is under attack&#8217; from China, Russia</title>
			<link>http://www.pheedcontent.com/click.phdo?i=020c5a52d19f59cfb8632b6955b33ab5</link>
			<pheedo:origLink>http://itknowledgeexchange.techtarget.com/security-bytes/report-rd-is-under-attack-from-china-russia/</pheedo:origLink>
			<comments>http://itknowledgeexchange.techtarget.com/security-bytes/report-rd-is-under-attack-from-china-russia/#comments</comments>
			<pubDate>Thu, 03 Nov 2011 13:49:47 +0000</pubDate>
			<dc:creator>admin</dc:creator>
			<category><![CDATA[cyberespionage]]></category>
			<category><![CDATA[RSA SecurID]]></category>
			<category><![CDATA[china]]></category>
			<category><![CDATA[Russia]]></category>
			<category><![CDATA[Congress]]></category>
			<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-bytes/report-rd-is-under-attack-from-china-russia/</guid>
			<description><![CDATA[
According to a U.S. intelligence report made available to Congress, foreign nations and other actors are using cyberespionage to take sensitive technology and trade data, and those actions pose a threat to American interests.
Reuters reported Thursday that in a report titled &#8220;Foreign Spies Stealing US Economic Secrets in Cyberspace,&#8221; the Office of the National Counterintelligence [...]<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:ddc1943ca28d9f320f2ecd7dd6c39a01:w6bkNSzJp2oIXPBC1TsRggXmXzIwC%2Bx0a02ir25FOX3nVgnaZjVGNNXM%2BQYVclSUH8gkvaC0H%2Bvjicg%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:3446c56c28f6f12765b0d11d9406b65a:0hczHQcusNOmgC2o0Wgu2PODJuSIZPgQGgbL%2BdGn0N74W4JZi5BV7o1w0rKvSadG9eG0u8eTRaebZ0c%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:b8a60d5d912acf146d9518a7aa8eec0f:ka9GVAe2Tg8%2B9nmSOqvwYfvk24heLK0GaPw8QOX6L5jQQObMGKurjM%2FwQmBay%2F4AN4L0hluQtMTqHA%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:ea757e2ab990beb28fa7f9ad5f184773:eoBX5kNDLegFLyPAe3hYvOY0gCbw1l1CmS%2BuGPqVvbeWvN90A%2FJF8pGYSx6ex7WZGTLjhX%2B5IP2tvg%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=020c5a52d19f59cfb8632b6955b33ab5&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=020c5a52d19f59cfb8632b6955b33ab5&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></description>
			<content:encoded><![CDATA[
<p>According to a U.S. intelligence report made available to Congress, foreign nations and other actors are using cyberespionage to take sensitive technology and trade data, and those actions pose a threat to American interests.</p>
<p><a href="http://" target="_blank">Reuters reported</a> Thursday that in a <span>report </span><span>titled &#8220;Foreign Spies Stealing US Economic Secrets in Cyberspace,&#8221; </span><span>the Office of the National Counterintelligence confirmed that </span><span>foreign intelligence services, corporations and individuals have increased their efforts to take research and development data relating to U.S. technologies. These efforts include remote data downloads, transferring data to portable devices and via email.<br />
</span></p>
<p>The report, covering 2009-2001, was developed using data <span>from intelligence agencies, think tanks, academia and </span><span>what it called &#8220;private sector&#8221; resources. </span>It referred to numerous sources being involved in cyberespionage against U.S. interests, but called out only Russia and China by name.</p>
<p>Though the report failed to link China to specific events, such as the <a href="http://searchsecurity.techtarget.com/news/1529523/RSA-SecurID-breach-began-with-spear-phishing-attack">RSA SecurID attack</a> earlier this year, it represents a tacit acknowledgment that China&#8217;s involvement in cyberespionage represents a serious ongoing problem for U.S. companies.</p>
<p><span>&#8220;Chinese actors are the world&#8217;s most active and persistent perpetrators of economic espionage,&#8221; </span><span>the Office of the National Counterintelligence wrote in the report. </span><span>&#8220;China and Russia view themselves as strategic  competitors of the United States and are the most aggressive collectors  of U.S. economic information and technology.&#8221;</span></p>

<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:ddc1943ca28d9f320f2ecd7dd6c39a01:w6bkNSzJp2oIXPBC1TsRggXmXzIwC%2Bx0a02ir25FOX3nVgnaZjVGNNXM%2BQYVclSUH8gkvaC0H%2Bvjicg%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:3446c56c28f6f12765b0d11d9406b65a:0hczHQcusNOmgC2o0Wgu2PODJuSIZPgQGgbL%2BdGn0N74W4JZi5BV7o1w0rKvSadG9eG0u8eTRaebZ0c%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:b8a60d5d912acf146d9518a7aa8eec0f:ka9GVAe2Tg8%2B9nmSOqvwYfvk24heLK0GaPw8QOX6L5jQQObMGKurjM%2FwQmBay%2F4AN4L0hluQtMTqHA%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:ea757e2ab990beb28fa7f9ad5f184773:eoBX5kNDLegFLyPAe3hYvOY0gCbw1l1CmS%2BuGPqVvbeWvN90A%2FJF8pGYSx6ex7WZGTLjhX%2B5IP2tvg%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=020c5a52d19f59cfb8632b6955b33ab5&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=020c5a52d19f59cfb8632b6955b33ab5&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-bytes/report-rd-is-under-attack-from-china-russia/feed/</wfw:commentRss>
		</item>
		<item>
			<title>Secunia brings own spin to vulnerability rewards programs</title>
			<link>http://www.pheedcontent.com/click.phdo?i=59c2323cced103f66ccd5938c2264404</link>
			<pheedo:origLink>http://itknowledgeexchange.techtarget.com/security-bytes/secunia-brings-own-spin-to-vulnerability-rewards-programs/</pheedo:origLink>
			<comments>http://itknowledgeexchange.techtarget.com/security-bytes/secunia-brings-own-spin-to-vulnerability-rewards-programs/#comments</comments>
			<pubDate>Wed, 02 Nov 2011 13:38:36 +0000</pubDate>
			<dc:creator>Michael S. Mimoso</dc:creator>
			<category><![CDATA[Secunia]]></category>
			<category><![CDATA[Secunia Vulnerability Coordination Reward Program]]></category>
			<category><![CDATA[bug bounty]]></category>
			<category><![CDATA[vulnerability management]]></category>
			<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-bytes/secunia-brings-own-spin-to-vulnerability-rewards-programs/</guid>
			<description><![CDATA[
Another day, another vulnerability reporting reward program. Kinda.
Secunia, a vulnerability management vendor from Denmark, is the latest to join the bounty brigade, but it is bringing its spin to the market. Secunia&#8217;s new Secunia Vulnerability Coordination Reward Program is another platform for researchers to report software security flaws, but Secunia goes a step further and offers [...]<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:3106fbfa18326c73022d34c8783ab659:DPlAORrQFyY43mp8pZ0o%2Fts7YrmRyLfzqhNDjwcJkJucCSQjeMqJxD9tGwZ0lwmsYNWAKZnJL%2Ba4Sqc%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:dcff30f36ed6008898d21a027b8a1c02:26ZjCO909qEBgrROdOdm%2FsNqgot%2Fyc4j0WIThtYsbgxthIKjXGE4adX3iKJuWs54RWztDULxJeGoOwI%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:e4cbe71326d57b2cb64ccf16d20e3328:K7b3pnT878M%2FTe9bdOCoI9q7oao%2FFCqjpMrhWZu6UboEeH5AGIVxf24DvSsRa5aqYr1%2FDLXBzEm41w%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:18aa2b63123fd9e2403257ea0d98eeff:%2B9yGMWnSojy0JW0AGFOppZvCaU6qKblLWqAIorb8K9n8PiPP5%2FSrDrvjjAvyGwriVpzt%2B5XRiJBi9A%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=59c2323cced103f66ccd5938c2264404&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=59c2323cced103f66ccd5938c2264404&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></description>
			<content:encoded><![CDATA[
<p>Another day, another vulnerability reporting reward program. Kinda.</p>
<p>Secunia, a vulnerability management vendor from Denmark, is the latest to join the bounty brigade, but it is bringing its spin to the market. Secunia&#8217;s new Secunia Vulnerability Coordination Reward Program is another platform for researchers to <a href="http://searchsecurity.techtarget.com/magazineContent/The-Pipe-Dream-of-No-More-Free-Bugs">report software security flaws</a>, but Secunia goes a step further and offers to handle the reporting process to the affected vendor. Software vendors have varied and sundry reporting processes and Secunia hopes to help researchers skip the hassle, according to Carsten Eiram, chief security specialist at Secunia.</p>
<p>&#8220;Most other schemes pay researchers for their discoveries, and, while these offerings are excellent for researchers, the companies are, naturally, very selective in which vulnerabilities they wish to purchase and coordinate,&#8221; he wrote in a release from the company. &#8221;This leaves a huge gap for researchers, who either do not want to sell their vulnerabilities or discover vulnerabilities not fulfilling the requirements of the existing initiatives, but who would still like an independent third party to confirm their discoveries and handle coordination.&#8221;</p>
<p><span lang="EN-GB"><a href="http://searchsecurity.techtarget.com/news/1526734/TippingPoint-Zero-Day-Initiative-fixes-record-number-of-vulnerabilities">TippingPoint&#8217;s Zero Day Initiative (ZDI)</a> and VeriSign&#8217;s iDefense Labs Vulnerability Contributor Program are probably the most well known bug-bounty programs offered by security companies., <a href="http://searchsecurity.techtarget.com/news/1522981/Google-extends-bounty-program-for-Web-application-bugs">Google</a>, <a href="http://searchsecurity.techtarget.com/news/1517158/Microsoft-Vulnerability-disclosure-will-be-coordinated-rather-than-responsible">Microsoft </a>and <a href="http://searchsecurity.techtarget.com/news/1525173/Mozilla-extends-bug-bounty-to-Web-application-vulnerabilities">Mozilla </a>also have their own twists on bug bounties. ZDI, for example, pays researchers for previously unpatched bugs and then develops signatures for its intrusion prevention products to give its customers first crack at protection. It also works with the affected vendor, and once a patch is ready, a joint advisory on the vulnerability is prepared. </span></p>
<p><span lang="EN-GB">Secunia says it will provide detailed information on vulnerabilities to the affected vendors and will participate in the patch process by providing feedback on fixes and confirming patches resolve the issue in question. Secunia hopes to establish itself as a trusted, independent third party in the vulnerability remediation process. In addition, the company says it will not notify its customers in advance as ZDI would. Instead, a public advisory would be the first notification of a vulnerability. </span></p>
<p><span lang="EN-GB">Secunia has established certain conditions for vulnerabiilties to be considered: the vulnerability must not be already publicly known; it must have been found in a stable product, in</span><span lang="EN-GB"><span lang="EN-GB">the latest version that is actively supported by the vendor. Secunia&#8217;s research team must also be able to confirm the vulnerability. </span></span></p>
<p><span lang="EN-GB"><span lang="EN-GB">Secunia said its rewards will include merchandise and accommodations and entry into major security conferences. </span></span></p>
<p><span lang="EN-GB"></span></p>

<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:3106fbfa18326c73022d34c8783ab659:DPlAORrQFyY43mp8pZ0o%2Fts7YrmRyLfzqhNDjwcJkJucCSQjeMqJxD9tGwZ0lwmsYNWAKZnJL%2Ba4Sqc%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:dcff30f36ed6008898d21a027b8a1c02:26ZjCO909qEBgrROdOdm%2FsNqgot%2Fyc4j0WIThtYsbgxthIKjXGE4adX3iKJuWs54RWztDULxJeGoOwI%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:e4cbe71326d57b2cb64ccf16d20e3328:K7b3pnT878M%2FTe9bdOCoI9q7oao%2FFCqjpMrhWZu6UboEeH5AGIVxf24DvSsRa5aqYr1%2FDLXBzEm41w%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:18aa2b63123fd9e2403257ea0d98eeff:%2B9yGMWnSojy0JW0AGFOppZvCaU6qKblLWqAIorb8K9n8PiPP5%2FSrDrvjjAvyGwriVpzt%2B5XRiJBi9A%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=59c2323cced103f66ccd5938c2264404&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=59c2323cced103f66ccd5938c2264404&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-bytes/secunia-brings-own-spin-to-vulnerability-rewards-programs/feed/</wfw:commentRss>
		</item>
		<item>
			<title>Windows zero-day flaw used in Duqu attacks</title>
			<link>http://www.pheedcontent.com/click.phdo?i=212ece44b5faaca22bc191f37a05eae4</link>
			<pheedo:origLink>http://itknowledgeexchange.techtarget.com/security-bytes/windows-zero-day-flaw-used-in-duqu-attacks/</pheedo:origLink>
			<comments>http://itknowledgeexchange.techtarget.com/security-bytes/windows-zero-day-flaw-used-in-duqu-attacks/#comments</comments>
			<pubDate>Tue, 01 Nov 2011 23:11:52 +0000</pubDate>
			<dc:creator>Marcia Savage</dc:creator>
			<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-bytes/?p=1949</guid>
			<description><![CDATA[
Security researchers said Tuesday the Duqu Trojan used a Word document that exploits a Microsoft zero-day vulnerability in order to infect computers. Microsoft said it&#8217;s working to address the flaw.
Researchers at the Laboratory of Cryptography and System Security (CrySys) in Budapest, Hungary, uncovered the installer file, the Word document, which Symantec researchers said exploits a [...]<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:e7cefd242c03dcecd6205a5bf0ba3e84:7Wlm0Vf8E6kYn8xgqAmeWg7BarwsptR%2F%2Bs6FZsSvhign8j%2Fql0nwtEjAN7kNKhsjb1OiJDXJUvcDi90%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:f2848264fb5d06ee2bfd479c82282317:cBZStp9GH2F6kg0%2F4oM3y4uXQzL%2FwTMQAviNXbgWSaYA6hYnVwOLyjMg%2BUM3Yks3eVwDL461K2965VM%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:432aab509928cf2d0d287f2a98852b8b:C7U2YuTquCUIrxGDGMxj33K1cffogWeESmo%2BkbcK4cZOwm9%2FMctaINPgEB1Ul9Sf96%2FSpYAdEZyNqA%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:7dded839f36fba863912a18724e86b61:gnBeMqkRrPokerxHWaQp5L%2BRyb3Tg5jvbuyPCKwxseIPHC7N6gGrMRLz57wv82mJfgj1LZf4nxcnNw%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=212ece44b5faaca22bc191f37a05eae4&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=212ece44b5faaca22bc191f37a05eae4&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></description>
			<content:encoded><![CDATA[
<p>Security researchers said Tuesday the Duqu Trojan used a Word document that exploits a Microsoft zero-day vulnerability in order to infect computers. Microsoft said it&#8217;s working to address the flaw.</p>
<p>Researchers at the Laboratory of Cryptography and System Security (CrySys) in Budapest, Hungary, uncovered the installer file, the Word document, which Symantec researchers said exploits a previously unknown kernel vulnerability. Symantec issued a report last month that detailed the <a href="http://searchsecurity.techtarget.com/news/2240102018/New-Duqu-malware-shares-Stuxnet-code-similarities" target="_self">similarities between Duqu and the notorious Stuxnet malware.</a> Designed to steal data, Duqu was discovered on the systems of industrial component manufacturers.</p>
<p>In an email statement, Jerry Bryant, group manager of response communications for Microsoft Trustworthy Computing, said, &#8220;Microsoft is collaborating with our partners to provide protections for a vulnerability used in targeted attempts to infect computers with the Duqu malware. We are working diligently to address this issue and will release a security update for customers through our security bulletin process.&#8221;</p>
<p>According to Symantec, the Word document was designed to target specific organizations. Symantec researchers noted that this installer is the only one recovered to date; attackers may have used other methods to spread Duqu. There are no robust workarounds but most security vendors already detect and block the main Duqu files, <a href="http://www.symantec.com/connect/w32-duqu_status-updates_installer-zero-day-exploit" target="_self">Symantec said in a blog post Tuesday.</a></p>
<p>The number of confirmed Duqu infections remains limited, but have been confirmed in six possible organizations in eight countries, including France, India, and Iran, according to Symantec.</p>
<p>According to Reuters, computer investigators in India have seized the computer equipment believed to have hosted the <a href="http://itknowledgeexchange.techtarget.com/security-bytes/duqu-trojan-investigation-indian-authorities-seize-web-hosting-provider-servers/" target="_self">command-and-control server connected to Duqu.</a></p>

<br clear="both" style="clear: both;"/>
<br clear="both" style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:e7cefd242c03dcecd6205a5bf0ba3e84:7Wlm0Vf8E6kYn8xgqAmeWg7BarwsptR%2F%2Bs6FZsSvhign8j%2Fql0nwtEjAN7kNKhsjb1OiJDXJUvcDi90%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://images.pheedo.com/images/mm/digg_64x16.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:f2848264fb5d06ee2bfd479c82282317:cBZStp9GH2F6kg0%2F4oM3y4uXQzL%2FwTMQAviNXbgWSaYA6hYnVwOLyjMg%2BUM3Yks3eVwDL461K2965VM%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://images.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:432aab509928cf2d0d287f2a98852b8b:C7U2YuTquCUIrxGDGMxj33K1cffogWeESmo%2BkbcK4cZOwm9%2FMctaINPgEB1Ul9Sf96%2FSpYAdEZyNqA%3D%3D'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http://images.pheedo.com/images/mm/delicious.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedcontent.com/hostedMorselClick.php?hfmm=v3:7dded839f36fba863912a18724e86b61:gnBeMqkRrPokerxHWaQp5L%2BRyb3Tg5jvbuyPCKwxseIPHC7N6gGrMRLz57wv82mJfgj1LZf4nxcnNw%3D%3D'><img border='0' title='Add to Google' alt='Add to Google' src='http://images.pheedo.com/images/mm/google.png'/></a>
<br clear="both" style="clear: both;"/>
<a href="http://ads.pheedo.com/click.phdo?s=212ece44b5faaca22bc191f37a05eae4&p=1"><img alt="" style="border: 0;" border="0" src="http://ads.pheedo.com/img.phdo?s=212ece44b5faaca22bc191f37a05eae4&p=1"/></a>
<img alt="" height="0" width="0" border="0" style="display:none" src="http://tags.bluekai.com/site/5148"/><img alt="" height="0" width="0" border="0" style="display:none" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&adv=wouzn4v&fmt=3"/>]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-bytes/windows-zero-day-flaw-used-in-duqu-attacks/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
<!-- cached -->
