Quick pick

NIS2

NIS2

11 posts
ISO 27001

ISO 27001

19 posts
AI & ML

AI & ML

7 posts
SSDLC

SSDLC

13 posts
(isc)2 CSSLP

(ISC)2 Blog post: Vulnerability disclosure: a new business model?

Original: http://blog.isc2.org/isc2_blog/2013/01/vulnerability-disclosure-a-new-business-model.html   We all see in the mass media every day that software is vulnerable and that this is bad. But, few know what is happening behind the scene, until the news get out. There are two ways to disclosure a vulnerability: the most common one is to make a “full disclosure”, but there is […]

General

The BKA/Ransom Trojan comes now with child pornography

The so called “BKA Trojan” (BKA stands for German Federal Criminal Police) malware which is also known as the Ransom trojan in other countries, has found a more convincing way to fool computer users to pay. Now, together with other eight possible misdeeds,  the user is accused of hosting and distributing child pornography materials from his computer. […]

General

Security update for Apple: iOS 6.1 fixes browser flaws

Apple has released a new version of iOS, the operating system that powers the iPhone, iPad, iPod. The new version fixes 20 security flaws related to the Safari browser. Some of the vulnerabilities were allowing bypassing of authentication, cross-site scripting attacks, privilege escalations, arbitrary code execution, memory corruptions. Last but not least, the  compromised Türktrust certificates were revoked. […]

General

Malware delivered with fake hotel reservations

We wrote last week about Malware delivered with fake Craigslist fax-to-email notifications.This week’s malware delivery mechanism is a fake email notification from the well-known online hotel reservations portal booking.com.   The malware is delivered when you click on “Print Booking Details” via an archive which should contain the form with the reservation details. In order […]

General

Malware delivered with fake Craigslist fax-to-email notifications

If you receive such a message containing an HTML page attached, don’t open it. The email pretends to come from “craigslist – automated message, do not reply <robot@craigslist.org>” and has the subject ”Efax Corporate”. What I find interesting is that the fraudsters didn’t even bother to write JS code to detect if the script runs in […]

CSSLP News

Added in searchsecurity.de (ISC)2 Corner

http://www.searchsecurity.de/specials/security_corner/isc2/ My cooperation with SearchSecurity.de is finally showing something. I was addded on the (ISC)2 Security Corner:                       Sorin Mustaca, Avira Operations GmbH & Co. KG Sorin Mustaca, (ISC)²-zertifizierter CSSLP, CompTIA Security+,Project+, ist seit 2000 in der IT Sicherheitsindustrie und seit 2003 bei Avira tätig. […]