<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Laptop Security Blog &#187; security news</title>
	<atom:link href="http://blog.absolute.com/tag/security-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.absolute.com</link>
	<description>Laptop Security blog by Absolute Software</description>
	<lastBuildDate>Fri, 12 Mar 2010 15:00:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Don&#8217;t Press F1 Key</title>
		<link>http://blog.absolute.com/dont-press-f1-key/</link>
		<comments>http://blog.absolute.com/dont-press-f1-key/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 17:00:51 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Web Security]]></category>
		<category><![CDATA[security news]]></category>
		<category><![CDATA[warning]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=2126</guid>
		<description><![CDATA[Microsoft has issued a security advisory for Windows XP users that pressing the F1 key when prompted to online could put users at risk for a hack.
The F1 key vulnerability exists because of an un-patched vulnerability in Internet Explorer that would allow hackers to hijack the source PC.
Microsoft is investigating new public reports of a [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has issued a <a href="http://www.microsoft.com/technet/security/advisory/981169.mspx">security advisory</a> for Windows XP users that pressing the F1 key when prompted to online could put users at risk for a hack.</p>
<p>The F1 key vulnerability exists because of an un-patched vulnerability in Internet Explorer that would allow hackers to hijack the source PC.</p>
<blockquote><p>Microsoft is investigating new public reports of a vulnerability in VBScript that is exposed on supported versions of Microsoft Windows 2000, Windows XP, and Windows Server 2003 through the use of Internet Explorer. Our investigation has shown that the vulnerability cannot be exploited on Windows 7, Windows Server 2008 R2, Windows Vista, or Windows Server 2008. The main impact of the vulnerability is remote code execution. We are not aware of attacks that try to use the reported vulnerabilities or of customer impact at this time.</p></blockquote>
<p>Microsoft may supply a security patch for this vulnerability in an upcoming patch release. No date or confirmation of this patch is available.</p>
<p>Via <a href="http://www.networkworld.com/podcasts/360/2010/030210-nw360-daily.html">network world</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/dont-press-f1-key/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security News Roundup</title>
		<link>http://blog.absolute.com/security-news-roundup-2/</link>
		<comments>http://blog.absolute.com/security-news-roundup-2/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 16:00:37 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Security Links]]></category>
		<category><![CDATA[security news]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1430</guid>
		<description><![CDATA[There have been a number of very useful articles out in the last week or so. Too many to share one at a time. So, I thought I&#8217;d put together another link post to point you towards some very useful articles:

Eric Geier writes for InformIT some &#8220;Tips to Secure your Home Wi-Fi Network&#8220;
Bruce Schneier also [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0415800.gif" alt="" width="192" height="192" />There have been a number of very useful articles out in the last week or so. Too many to share one at a time. So, I thought I&#8217;d put together another link post to point you towards some very useful articles:</p>
<ul>
<li>Eric Geier writes for InformIT some &#8220;<a href="http://www.informit.com/articles/article.aspx?p=1358662">Tips to Secure your Home Wi-Fi Network</a>&#8220;</li>
<li>Bruce Schneier also has a new article out about securing your data while traveling that&#8217;s worth some consideration: &#8220;<a href="http://www.wired.com/politics/security/commentary/securitymatters/2009/07/securitymatters_0715">Protect Your Laptop Data From Everyone, Even Yourself</a>&#8220;.</li>
<li>Another thoughtful article on SafeKids.com by Larry Magid: &#8220;<a href="http://www.safekids.com/2009/07/14/how-to-stop-cyberbullying/">How to stop cyberbullying.</a>&#8220;</li>
<li>Forbes.com&#8217;s Amanda Berlin puts together an article on &#8220;<a href="http://www.forbes.com/2009/07/01/online-reputation-protect-leadership-careers-networking.html">How to Protect Your Online Reputation.</a>&#8220;</li>
<li>NetworkWorld continues their IT Best Practices series with this article by Linda Musthaler and Brian Musthaler: &#8220;<a href="http://www.networkworld.com/newsletters/techexec/2009/070609bestpractices.html">The notification chain when a breach is suspected</a>&#8220;</li>
</ul>
<p>If you find any articles you think would interest the readers here, <a href="mailto:arieanna@gmail.com">let me know</a>!</p>
<p><em>Image: Clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/security-news-roundup-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft&#8217;s 6th Security Intelligence Report</title>
		<link>http://blog.absolute.com/microsofts-6th-security-intelligence-report/</link>
		<comments>http://blog.absolute.com/microsofts-6th-security-intelligence-report/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 16:14:32 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[breach statistics]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Laptop Security]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[security news]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1275</guid>
		<description><![CDATA[Microsoft just released the 6th volume of its Security Intelligence Report (SIR), which provides perspective on the changing threat landscape in terms of software vulnerability, malware, and the changing face of threats and countermeasures.
The SIR indicates that malicious software infected different versions of Windows at different rates. Vista was less infected than other service packs, [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft just released the 6th volume of its <strong><a href="http://www.microsoft.com/security/portal/sir.aspx">Security Intelligence Report</a></strong> (SIR), which provides perspective on the changing threat landscape in terms of software vulnerability, malware, and the changing face of threats and countermeasures.</p>
<p>The SIR indicates that malicious software infected different versions of Windows at different rates. <strong>Vista was less infected</strong> than other service packs, all versions of Windows XP having higher infection rates. The data, which is based on millions of Windows users, indicates that total vulnerability disclosures was on the decline while the number of high severity disclosures was increasing each quarter. More than <strong>90% of vulnerabilities disclosed affected applications or browsers</strong> (vs the Operating System).</p>
<p>In the second half of 2008, there was a <strong>rise in rogue security software</strong>, which is software that poses as being anti-malware or anti-spyware, when indeed may do nothing or be malware itself. Be sure to download your software just from trusted sources!</p>
<p>The report looks at data breach incidents from the <a href="about:blank">OSF Data Loss database</a>, indicating that the second half of 2008 could blame <strong>33.5% of all data loss incidents on equipment theft, including that of laptops</strong>. Adding in equipment loss, and that total goes up to 50%. Be sure to secure your laptops and be able to see if computers have the latest software updates with our <a href="http://www.absolute.com/laptop-security-solutions.asp">Computrace laptop security solution</a>.</p>
<div style="text-align:center;"><img src="http://blog.absolute.com/wp/wp-content/uploads/data-loss.jpg" border="0" alt="data-loss.jpg" width="500" height="233" /></div>
<p><strong>SIR Volume 6, which tracks data between July and December 2008, can be <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=aa6e0660-dc24-4930-affd-e33572ccb91f&amp;displaylang=en">downloaded here</a>.</strong></p>
<p>Via <a href="http://blogs.technet.com/mmpc/archive/2009/04/08/whos-at-risk-on-the-internet-today.aspx">technet</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/microsofts-6th-security-intelligence-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4 Great Security Lists</title>
		<link>http://blog.absolute.com/4-great-security-lists/</link>
		<comments>http://blog.absolute.com/4-great-security-lists/#comments</comments>
		<pubDate>Mon, 23 Feb 2009 18:38:56 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Security Links]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[Laptop Security]]></category>
		<category><![CDATA[security news]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1057</guid>
		<description><![CDATA[Sometimes there&#8217;s so much good advice out there that it&#8217;s impossible to cover it all. Rather than miss out on some of these gems, I&#8217;m going to point out some good list-based articles that have caught my attention, highlighting the salient points of each.
Laptop Security Is a Three-Legged Stool &#8211; Intel
This list fits in snugly [...]]]></description>
			<content:encoded><![CDATA[<p>Sometimes there&#8217;s so much good advice out there that it&#8217;s impossible to cover it all. Rather than miss out on some of these gems, I&#8217;m going to point out some good list-based articles that have caught my attention, highlighting the salient points of each.</p>
<p><strong><a href="http://communities.intel.com/openport/community/openportit/vproexpert/blog/2009/01/28/laptop-security-is-a-three-legged-stool">Laptop Security Is a Three-Legged Stool</a> &#8211; Intel</strong></p>
<p>This list fits in snugly with our own motto of &#8220;<a href="http://www.absolute.com/laptop-security-solutions.asp">mutli-layered laptop security</a>&#8221; at Absolute, which we talk about <a href="http://www.absolute.com/resources/laptop-security-tips.asp">here</a>. For now, check out the &#8220;3 legs&#8221; of laptop security:</p>
<ol>
<li>Physical Security</li>
<li>Data Protection</li>
<li>Protection Solution</li>
</ol>
<p><strong><a href="http://www.csoonline.com/article/480589/_Dirty_Tricks_Social_Engineers_Favorite_Pick_Up_Lines">9 Dirty Tricks: Social Engineers&#8217; Favorite Pick-Up Lines</a> &#8211; CSO Online</strong></p>
<p>These are tactics employed by criminals (cyber and otherwise) to scam you out of personal information or money or to gain access. The list had 8 tricks, not 9, but who&#8217;s counting? ;)</p>
<ol>
<li>&#8220;I&#8217;m traveling in London and I&#8217;ve lost my wallet. Can you wire some money?&#8221;</li>
<li>&#8220;Someone has a secret crush on you! Download this application to find who it is!&#8221;</li>
<li>&#8220;Did you see this video of you? Check out this link!&#8221;</li>
<li>&#8220;This is Chris from tech services. I&#8217;ve been notified of an infection on your computer.&#8221;</li>
<li>&#8220;Hi, I&#8217;m from the rep from Cisco and I&#8217;m here to see Nancy.&#8221;</li>
<li>&#8220;Can you hold the door for me? I don&#8217;t have my key/access card on me.&#8221;</li>
<li>&#8220;You have not paid for the item you recently won on eBay. Please click here to pay.&#8221;</li>
<li>&#8220;You&#8217;ve been let go. Click here to register for severance pay. &#8220;</li>
</ol>
<p><strong><a href="http://www.csoonline.com/article/480175/_Tips_for_Managing_Security_in_a_Recession">5 Tips for Managing Security in a Recession</a> &#8211; CSO Online</strong></p>
<p>Another great look at how to prioritize your security spending and planning this year.</p>
<ol>
<li>Prioritize based on risk/reward</li>
<li>Have the right mix of people on your team</li>
<li>Build repeatable processes</li>
<li>Create an optimal shared cost strategy</li>
<li>Automate and outsource wisely</li>
</ol>
<p><strong><a href="http://www.informit.com/articles/article.aspx?p=1324439">Top 5 Security Resolutions for New PCs</a> &#8211; InformIT</strong></p>
<p>If you&#8217;ve just bought a new computer, take some quick security steps before you start using it! Here are 5 resolutions to take:</p>
<ol>
<li>I Will Patch My Systems</li>
<li>I Will Use Common Security Tools</li>
<li>I Will Back Up My Data</li>
<li>I Will Secure My Wireless Router</li>
<li>I Won’t Write Down My Passwords</li>
</ol>
<p style="text-align: left;">And to end off the great tips offered in these articles, walk the lighter side with this ID-theft-themed <a href="http://dilbert.com/strips/comic/2008-12-07/">Dilbert comic</a>.<a title="Dilbert.com" href="http://dilbert.com/strips/comic/2008-12-07/"><br />
</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/4-great-security-lists/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>25 Most Dangerous Programming Errors</title>
		<link>http://blog.absolute.com/25-most-dangerous-programming-errors/</link>
		<comments>http://blog.absolute.com/25-most-dangerous-programming-errors/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 16:34:34 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Business Security]]></category>
		<category><![CDATA[Technology Advice]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[security news]]></category>
		<category><![CDATA[security organization]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=910</guid>
		<description><![CDATA[The US National Security Agency (NSA), the Department of Homeland Security, Microsoft, Symantec and a group of more than 30 other cyber security organizations have formed a group to outline the most dangerous software programming errors.
The group has jointly released a consensus list of the 25 most dangerous programming errors &#8211; and how to fix [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0439607.gif" border="0" alt="" width="111" height="111" />The US National Security Agency (NSA), the Department of Homeland Security, Microsoft, Symantec and a group of more than <a href="http://www.sans.org/top25errors/#s1">30 other</a> cyber security organizations have formed a group to outline the most dangerous software programming errors.</p>
<p>The group has jointly <a href="http://www.sans.org/top25errors/">released</a> a consensus list of the <strong>25 most dangerous programming errors</strong> &#8211; and how to fix them. These programming errors lead to security bugs and can enable cyber espionage and cyber crime &#8211; most errors are not well understood, nor is their avoidance taught by computer science programs. The press release also indicates that these errors are not frequently tested by organizations developing software for sale. This list is, therefore, a <strong>big step forward in making software more secure</strong>.</p>
<blockquote><p>&#8220;There appears to be broad agreement on the programming errors. Now it is time to fix them. First we need to make sure every programmer knows how to write code that is free of the Top 25 errors, and then we need to make sure every programming team has processes in place to find, fix, or avoid these problems and has the tools needed to verify their code is as free of these errors as automated tools can verify.&#8221; &#8211; <em>SANS Director, Mason Brown</em></p></blockquote>
<p>According to the release,<strong> just 2</strong> out of these 25 programming errors led to more than<strong> 1.5 million website security breaches in 2008</strong>. The 25 errors represent the worst things that can happen when software is being written &#8211; and will give a minimum set of coding errors that should be eradicated before software gets to the consumer.</p>
<p>The programming errors include sending sensitive information in clear text and hard-coding security passwords into programs. The<strong> errors fall into three categories:</strong> insecure interaction between components, risky resource management and porous defenses. You can read more <a href="http://www.sans.org/top25errors/#s4">here</a> or <a href="http://cwe.mitre.org/top25/">here</a>.</p>
<p>Via <a href="http://www.pcworld.com/article/156894/nsa_helps_name_most_dangerous_programming_mistakes.html">PC World</a> ; <em>Clipart via Microsoft / Presentation Pro</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/25-most-dangerous-programming-errors/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security News Roundup</title>
		<link>http://blog.absolute.com/security-news-roundup/</link>
		<comments>http://blog.absolute.com/security-news-roundup/#comments</comments>
		<pubDate>Sat, 03 Jan 2009 04:31:41 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Security Links]]></category>
		<category><![CDATA[security news]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=879</guid>
		<description><![CDATA[There have been a number of great news items in the security field in the past couple of weeks. So, this post will share some that I found particularly interesting or useful.
The Center for Strategic &#38; International Studies (CSIS) Commission on Cybersecurity for the 44th Presidency has released its final report, &#8220;Securing Cyberspace for the [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/uploads/computerblackandwhite.jpg" alt="" />There have been a number of great news items in the security field in the past couple of weeks. So, this post will share some that I found particularly interesting or useful.</p>
<p>The Center for Strategic &amp; International Studies (CSIS) Commission on Cybersecurity for the 44th Presidency has released its final report, &#8220;<a href="http://www.csis.org/component/option,com_csis_pubs/task,view/id,5157/"><strong>Securing Cyberspace for the 44th Presidency</strong></a>.&#8221; The report indicates the importance of Cybersecurity as a national security issue, that privacy and civil liberties should be reflected in cubersecurity issues, and that a national security strategy is necessary.</p>
<p>Control Risks has <a href="http://www.control-risks.com/default.aspx?page=1338">released</a> its annual <strong><a href="http://www.control-risks.com/default.aspx?page=1315">RiskMap report for 2009</a>.</strong> The RiskMap provides an assessment of global and regional political and security risks that businesses are likely to face in the upcoming year. Read more about that <a href="http://www.csoonline.com/special/slideshows/globalrisks2009/index">here</a> and <a href="http://www.csoonline.com/article/472423/_Global_Risks_to_Business_in_">here</a>.</p>
<p>Roger Grimes at InfoWorld sets out the <a href="http://weblog.infoworld.com/securityadviser/archives/2008/12/the_only_two_th.html?source=rss">two primary things</a> you need to know in order to <strong>secure your home computer</strong> (or home business computer). Although he talks about anti-virus programs, his two main pieces of advice involve being smart (don&#8217;t download it if you don&#8217;t trust it) and to patch your system regularly &#8211; he does recommend the commercial version of <a href="http://www.secunia.com/">Secunia&#8217;s</a> Software Inspector for this. Keep reading <a href="http://weblog.infoworld.com/securityadviser/archives/2008/12/the_only_two_th.html?source=rss">here</a>.</p>
<p>There&#8217;s an interesting article by Tom Olzak at <a href="http://blogs.techrepublic.com.com/security/?p=716">Tech Republic </a>asking if state and federal <strong>breach notification mandates are unreasonable.</strong> I&#8217;ve always been a huge proponent of national legislation as key; I believe consumers need to be informed of breaches in order to mitigate their risk and choose which companies they choose to trust. Tom agrees with this, and argues against statements to the contrary made by Chris Wolf, an attorney and head of the Proskauer Rose (Washington, D.C.) law firm’s privacy and security group. You can read the article <a href="http://blogs.techrepublic.com.com/security/?p=716">here</a>.</p>
<p>Also an interesting read from informIT, an article entitled &#8220;<a href="http://www.informit.com/articles/article.aspx?p=1315431">Software [In]security: Software Security Top 10 Surprises</a>&#8220;.</p>
<p align="center"><strong>Have you found any security reports or news to be an interesting read of late? If so, do share the link in the comments!</strong></p>
<p><em>Image <a href="http://morguefile.com/archive/?display=73163&amp;">anitapatterson</a> @morguefile</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/security-news-roundup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
