Optimal Security : the Lumension Blog

Subscribe

Think You Have It Covered With WSUS? Think Again…

As noted in our July blog post “Adjust Your Defense to the Changing Threat Vector,” third party applications now pose the greatest risk to network security. Simply turning on WSUS and patching the underlying OS and Microsoft applications leaves you woefully exposed.  The bad guys know they can improve the success of an attack by [...]

Ben Franklin’s Endpoint Security Advice

Ben Franklin dished out some pretty good security advice in his day. In fact, he was one of the most well known security professionals of his time. Many of you may realize it was Franklin that coined the saying ‘An ounce of prevention is worth a pound of cure’ but what you might not know [...]

Employees Will Steal Your Data – Are You Protecting the Right Stuff?

We in the security industry talk a lot about the risks of data theft and/or loss, especially by an insider. A quick look through the recent entries into the Open Security Foundation’s DataLossDB makes that case more concrete, be it via an innocent mistake (like losing a laptop) or outright theft (like the Countrywide case, [...]

August 2010 Patch Tuesday Security Briefing

Paul Henry, Forensics and Security Analyst, provides his insights in this August 2010 Patch Tuesday Security Briefing.

Afraid of Change: Getting Users to Upgrade from XP to Win7

 
 
SC Magazine UK’s online news editor, Dan Raywood asks Don Leatham, senior director of solutions and strategy at Lumension about the value – and dangers – of running outdated operating systems.
Q: If we researched operating systems, it is likely we would find a lot of people running ‘outdated’ operating systems. What is the best [...]

Microsoft Prepares Out Of Band Patch For “Globe Trotting” LNK File Issue

As more malware writers began to incorporate the Microsoft LNK issue (CVE-2010-2568) into their malicious code, Microsoft last week published a workaround and is [...]

Adjust Your Defenses to the Changing Threat Vector

While our budget-constrained defenses remain relatively static, the threat vector continues to change. Historically in network security, attackers seem to regularly stay one step ahead of defenders. I have watched the arms race unfold for more than two decades as attackers worked their way up the OSI stack from network layer attacks like the infamous [...]

Yes Virginia, Mac’s Can Get Viruses

Before getting flamed as an Apple basher, first let me state that I like Apple products. I am not foolishly going to disregard the risks of the environment we live / work in today however. In my business and personal life I own 3 Apple laptops, 4 Apple desktops, 2 iPads and 2 iPhones. Along [...]

Novel New USB Attack

News about a new attack via USB flash drive, known as Stuxnet.B, is surfacing. The Belarusian antivirus company VirusBlokAda recently discovered it and published a report on it. There are several points about this attack which make it both novel and unique, even though infection / propagation via USB flash drives is very common. To [...]

July 2010 Patch Tuesday Security Briefing

Paul Henry, Forensics and Security Analyst, provides his insights in this July 2010 Patch Tuesday Security Briefing.