Security News

VA completes education claims system in time for fall semester

Nextgov.com News Articles - Fri, 09/03/2010 - 12:00am
Fully automated network works through complex calculations to determine veterans' tuition payments and housing allowances under the 2008 GI bill.
Categories: Security News

DHS to expand cybersecurity program for researchers

Nextgov.com News Articles - Fri, 09/03/2010 - 12:00am
Officials believe giving cyber specialists access to information about real-world network attacks could lead to better solutions to protecting computers.
Categories: Security News

Less than half of 'Net connections meet FCC speed goal

Nextgov.com News Articles - Fri, 09/03/2010 - 12:00am
A Federal Communications Commission report released on Thursday examining Internet access subscriptions found less than half of U.S. subscribers currently get broadband service that meets or exceeds speed targets set by the commission in its national broadband plan.
Categories: Security News

Agency aims to play matchmaker with new hiring tool

Nextgov.com News Articles - Thu, 09/02/2010 - 12:00am
The national intelligence office is developing a site that would pair job applicants with suitable federal vacancies.
Categories: Security News

Technology designed to speed hiring often hinders the process, survey shows

Nextgov.com News Articles - Thu, 09/02/2010 - 12:00am
HR specialists say incompatible systems and limited online tools make it difficult to match qualified candidates with jobs.
Categories: Security News

Soundbytes: ATC Modernization, DISA and Long Commutes

Nextgov.com News Articles - Thu, 09/02/2010 - 12:00am
A weekly roundup of comments from Nextgov.com. All comments are presented in their original, unedited form.
Categories: Security News

Scientists view cybersecurity as an intimidating conundrum

Nextgov.com News Articles - Thu, 09/02/2010 - 12:00am
Former National Science Foundation executive says technical issues and the enormity of the task make securing the Internet and networks 'the most difficult challenge' for researchers.
Categories: Security News

CBP failed to follow basic security practices to protect financial systems

Nextgov.com News Articles - Thu, 09/02/2010 - 12:00am
Administrators didn't review employees' rights to access files, enforce stringent password requirements, or block users from logging on after several failed attempts.
Categories: Security News

Cyber Costs Climb

Nextgov.com News Articles - Thu, 09/02/2010 - 12:00am
Push to secure data and systems creates multibillion-dollar market for contractors.
Categories: Security News

Dell Expands Security Solutions Portfolio, Unites with Trend Micro ...

Cyber Criminals Small Business - Wed, 09/01/2010 - 3:16pm
“According to the FBI, cybercriminals steal millions from small and midsize companies,” said ... general manager of Trend Micro Consumer and Small Business. ...

Cyber Thieves Steal Nearly $1,000,000 from University of Virginia College

Brian Krebs - Wed, 09/01/2010 - 12:02pm

Cyber crooks stole just shy of $1 million from a satellite campus of The University of Virginia last week, KrebsOnSecurity.com has learned.

The attackers stole the money from The University of Virginia’s College at Wise, a 4-year public liberal arts college located in the town of Wise in southwestern Virginia.

Kathy Still, director of news and media relations at UVA Wise, declined to offer specifics on the theft, saying only that the school was investigating a hacking incident.

“All I can say now is we have a possible computer hacking situation under investigation,” Still said. “I can also tell you that as far as we can tell, no student data has been compromised.”

According to several sources familiar with the case, thieves stole the funds after compromising a computer belonging to the university’s comptroller. The attackers used a computer virus to steal the online banking credentials for the University’s accounts at BB&T Bank, and initiated a single fraudulent wire transfer in the amount of $996,000 to the Agricultural Bank of China. BB&T declined to comment for this story.

Sources said the FBI is investigating and has possession of the hard drive from the controller’s PC. A spokeswoman at FBI headquarters in Washington, D.C. said that as a matter of policy the FBI does not confirm or deny the existence of investigations.

The attack on UVA Wise is the latest in a string of online bank heists targeting businesses, schools, towns and nonprofits. Last week, cyber thieves stole more than $600,000 from the Catholic Diocese of Des Moines, Iowa.

Recommended reading:

Target: Small Businesses

Charting the Carnage from Ebanking Fraud

eBanking Guidance for Banks and Businesses

Avoid Windows Malware: Bank on a Live CD

Categories: Security News

MS Fix Shores Up Security for Windows Users

Brian Krebs - Wed, 09/01/2010 - 12:07am

Microsoft has released a point-and-click tool to help protect Windows users from a broad category of security threats that stem from a mix of insecure default behaviors in Windows and poorly written third-party applications.

My explanation of the reason that this is a big deal may seem a bit geeky and esoteric, but it’s a good idea for people to have a basic understanding of the threat because a number of examples of how to exploit the situation have already been posted online. Readers who’d prefer to skip the diagnosis and go straight to the treatment can click here.

DLL Hijacking

Windows relies heavily on powerful chunks of computer code called “dynamic link libraries” or DLLs. Each of these DLLs performs a specific set of commonly-used functions, and they are designed so that Windows can share these functions with other third-party programs that may want to invoke them for their own purposes. Many third-party apps will load these DLLs or bring their own when they first start up and often while they’re already running.

Typically, DLLs are stored in key places, such as the Windows System (or System32) directory, or in the directory from which the application was loaded. Ideally, applications will let Windows know where to find the DLLs they need, but many do not.

The potential for trouble starts when an application requests a specific DLL that doesn’t exist on the system. At that point, Windows sets off searching for it — looking in the above-mentioned key places first. But eventually, if Windows doesn’t find the DLL there or in a couple of other places, it will look in the user’s current directory, which could be the Windows Desktop, a removable device such as a USB key, or a folder shared on a local or remote network.

And while an attacker may not have permission to write files to the Windows system or program directories, he may be able to supply his own malicious DLL from a local or remote file directory, according to the U.S. Computer Emergency Readiness Team.

Several months ago, experts from a Slovenian security firm warned that hundreds of third-party applications were vulnerable to remote attacks that could trick those apps into loading and running malicious DLLs. According to the Exploit Database — which has been tracking confirmed reports of applications that are vulnerable to this attack — vulnerable apps include Windows Live Mail, Windows Movie Maker, Microsoft Office Powerpoint 2007, Skype, Opera, Medialplayer Classic and uTorrent, to name just a few.

The FixIt Tool

Roughly one week ago, Microsoft released a workaround tool to help users and system administrators blunt the threat from all of this by blocking insecure DLLs from loading from remote and local file sharing locations. But the tool wasn’t exactly made for home users: After you installed and rebooted, you still had to manually set a key in the Windows registry, an operation that can cause serious problems for Windows if done imprecisely.

On Tuesday, Microsoft simplified things a tiny bit, by releasing one of its “FixIt” tools to make that registry fix so users don’t have to monkey around in there. Trouble is, you still need to have installed the initial workaround tool before you can install this point-and-click FixIt tool.

It’s tough to gauge whether DLL hijacking poses the same threat to home users that it does to users on larger enterprise networks. Microsoft maintains that this class of vulnerability does not enable a “driveby” or “browse-and-get-owned” zero-click attack, but the attack scenarios Redmond describes where a Windows user could get owned by this attack probably would work against a majority of average Windows users.

And while it may take some time for developers of vulnerable third-party apps to fix their code, Microsoft’s interim fix does add a measure of protection. If you’d like to take advantage of that protection, visit this link, scroll down to the Update Information tab, and click the package that matches your version of Windows. Install the fix and reboot Windows. Then visit this link, and click the FixIt icon in the center of the page and follow the installation prompts.

Further reading:

An excellent writeup on this from SANS Internet Storm Center incident handler Bojan Zdrnja.

A discussion thread about this on DSL Reports’ security forum.

Categories: Security News

NASA program to launch space shuttle workers into new jobs

Nextgov.com News Articles - Wed, 09/01/2010 - 12:00am
A competition for $35 million in grants would fund initiatives to help 9,000 contractors facing unemployment to find work in aviation and aerospace, clean technology, homeland security, IT and life sciences.
Categories: Security News

Veterans Affairs and CMS will launch projects for personal health records

Nextgov.com News Articles - Wed, 09/01/2010 - 12:00am
The initiatives could lead to almost a third of the public creating digital files to store their medical information.
Categories: Security News

E-file system to flag errors in claims of foreign earned income

Nextgov.com News Articles - Wed, 09/01/2010 - 12:00am
A new version will include an application to correct the erroneous tax exclusions, which cost the government $90 million in 2008.
Categories: Security News

Researchers slam lawmakers' websites as failing constituents

Nextgov.com News Articles - Wed, 09/01/2010 - 12:00am
Poor design, lack of interaction and a paucity of pertinent information keep elected officials from enriching democracy, a report concludes.
Categories: Security News

Industry group says 'significant progress' on net neutrality talks

Nextgov.com News Articles - Wed, 09/01/2010 - 12:00am
Information Technology Industry Council President and Chief Executive Officer Dean Garfield issued a progress report on Tuesday about his group's efforts to find some middle ground among stakeholders battling over network neutrality, saying there has been "significant progress" while declining to provide any details.
Categories: Security News

Companies begin offering faster airport screening

Nextgov.com News Articles - Wed, 09/01/2010 - 12:00am
The Transportation Security Administration appears to be taking a wait-and-see approach to the renewed effort.
Categories: Security News

Spain airports implement a multi-biometric solution

SecureIDNews - Tue, 08/31/2010 - 4:30pm

Airports in Barcelona and Madrid in Spain have installed self-service kiosks available for use by holders of Spanish citizen ID cards or European Community electronic passports, according to a Pro Security Zone article.

The kiosks, which are expected to relieve long lines for those traveling into the country, require a positive scan of both a cardholder’s face and fingerprint.

Read the full article at SecureIDNews…

Categories: Security News

HID Global releases new Fargo printers

SecureIDNews - Tue, 08/31/2010 - 8:46am


HID Global introduced a new line of direct-to-card FARGO printer/encoders. The new product line is made up of three models designed to meet the needs of small organizations to global enterprises. This is the first new line of printers introduced since HID purchased Fargo.

The line consists of the DTC1000 entry-level printer for small organizations; the professional-level DTC4000 printer for small- to medium-size organizations with more security and scalability requirements; and the advanced, DTC4500 professional printer for large corporations and government organizations with high-volume needs, says Ryan Park, senior product marketing manager for secure issuance at HID.

Read the full article at SecureIDNews…

Categories: Security News