4/14/2008
Art Coviello kicked off RSA Conference 2008, his company's namesake information security conference, April 8 in San Francisco with a warning.
4/14/2008
A beta release of Windows Live OneCare 2.5, Microsoft's automated security suite for home users and small businesses, is available for testing from the Microsoft Connect Web site. Microsoft stated through its blog that there is little apparent difference between the beta and standard versions.
4/11/2008
Dartmouth's Institute for Information Infrastructure (I3P) recently transferred control of its 7,000-resource cyber security library to the Naval Postgraduate School (NPS) Center for Homeland Defense and Security in Monterey, CA.
4/11/2008
The Department of Homeland Security has issued the regulations that will govern the Real ID Act that sets standards for drivers' licenses across the country. How will it impact you and your campus?
4/10/2008
A breach of an ERP system at Antioch University forced the school to send letters out to more than 60,000 students, former students and staff members informing them that they could become victim to identity theft. The problems surfaced on February 13, 2008, when an anti-virus program detected a virus on one of Antioch's computers. Forensic software investigators hired by the university to examine its systems found that an unauthorized intruder had gained access to one of the computers on three occasions during 2007 and that an IRC bot had been installed.
4/10/2008
Microsoft Corp. this week initiated a call for action to address the future of security and privacy on the Internet. In a speech by Chief Research and Strategy Officer Craig Mundie, the company proposed "End to End Trust," a pitch for organizations, including vendors and user organizations, to work together to create a more secure and trusted online environment.
4/10/2008
Omnilert, which offers e2Campus, an emergency notification system for higher education, has created a marketing program that allows participants to collectively purchase the software at a group rate.
4/9/2008
Microsoft Corp.made available a public beta release of its Forefront security solution, code-named "Stirling." The software is an integrated security system designed to allow administrators to control, access, and manage security capabilities across an organization's IT infrastructure. It includes a central management console for security configuration and enterprise-wide visibility and works with other ForeFront products that secure clients, Exchange, SharePoint, and the next version of Internet Security and Acceleration Server (ISA Server).
4/9/2008
Anzen, an Alexandria, VA company that provides personal security training for public and corporate organizations, announced a new program to address safety in educational institutions. Called USA Safe Schools, the initiative provides schools with tools and training to reduce hostile threats to teachers and students.
4/9/2008
HP has introduced several products to address data protection and compliance in storage environments, including add-ons that do automated data encryption on tape drives and libraries. Among the offerings: a secure fabric switch; an encryption kit for tape autoloaders and libraries; integration of compliance and management appliances; and, a free online security assessment tool.
4/9/2008
A Spokane, WA company has developed a computer network-based alarm system that allows users to trigger an emergency alarm through their computers to send a silent alert to all other users logged into the same network. Pentad Systems' LANalarm could complement text messaging-based notification systems, which tend to have a lag between the time the emergency is communicated to administrators and the notification is actually sent out to participants.
4/8/2008
Microsoft released its latest security update, which includes eight cumulative patches addressing vulnerabilities in Office applications, Windows, and Internet Explorer.
4/8/2008
Security engineers in the Information Technology Security Office (ITSO) at Indiana University were at a loss when a user described a network-connected multifunctional printer that was acting strangely--even printing spam e-mail messages onto paper.
4/1/2008
A survey by Honeywell released in March reveals that although some organizations are integrating physical security measures such as video surveillance and access control with traditional IT security system, significant barriers to convergence still exist.
3/31/2008
Consulting and publishing firm Network Frontiers has released the Q1 2008 Unified Compliance Framework (UCF), a database used in compliance management systems. UCF maps hundreds of regulations, including privacy information, HIPPA, PCI-DDS and Medicaid/Medicare mandates, into a master hierarchal framework. This latest version of the UCF consolidates cross platform configuration management controls into a single set of controls.
3/31/2008
The MIT Kerberos Consortium has added Microsoft to its ranks of formal industry supporters. The company joined the group Monday as a founding sponsor, gaining a seat on the executive board, which also includes representatives from Apple, Sun, Google, and, of course, MIT itself. Microsoft's director of Windows Core Security, Slava Kavsan, will occupy the board seat.
3/27/2008
Information security provider Crossroads Systems this week released a new encryption module for its Crossroads Virtual TapeServer. The module, SecureVTS, is an integrated solution that provides security for backed-up data for compliance and business continuity.
3/24/2008
Astaro Corp. has announced a security appliance line that integrates URL filtering, malware detection, application control, and bandwidth optimization. The Astaro Web Gateway is deployed as a hardware or virtualized appliance and managed through a single browser-based graphical interface.
3/24/2008
Enterprises can now more easily determine which applications their employees run that require administrative rights, a condition that makes the environment more susceptible to malicious users and viruses and prevents compliance with regulations such as the Sarbanes-Oxley Act and HIPAA. BeyondTrust’s free Application Rights Auditor automatically identifies and reports Windows applications that need elevated user rights.
3/20/2008
Campus security takes many forms--emergency notification, monitoring for Web breaches, data privacy protection, video monitoring. But when was the last time you thought about the security offered by your school's doors?
3/19/2008
IBM announced new technology to secure "mashups," Web applications that pull information from multiple sources, such as Web sites, enterprise databases, or e-mails, to create one unified view. Mashups allow users to gain insight on complex situations but, as with all Web-based initiatives, security has been a concern.
3/19/2008
A chemical engineering student in Toronto faces expulsion from his school for running an online study group through Facebook. Chris Avenir, a first-year student at Ryerson University in Toronto, Ontario, said he joined the social networking group in fall 2007 to get help with the homework in one of his chemistry classes. Eventually, he became the administrator for the network, which grew to include 146 students.
3/18/2008
Texas Southern University (TSU) has chosen MIR3 as the emergency notification platform for its Houston campus.
3/14/2008
Umpqua Community College in Winchester, OR announced in February that its Moodle course management system had been hacked earlier in the year, potentially exposing student information. According to a statement from the college, there was no evidence that personal records had been affected. The school also noted that the IT department knew how the system had been compromised and had taken steps to address the security vulnerabilities, which included shutting Moodle down temporarily.
3/14/2008
Since you've encrypted the data on your laptop, it's safe even if your laptop is stolen, right? Wrong. Researchers at Princeton have demonstrated ways to hack your encrypted data using your own DRAMs against you.