What information security might look like in a decade
Global security best practices
5 handy WordPress security plug-ins
Facebook hit by phishing scam and banking Trojan combo
Understanding the risks of cloud computing

Ask the social engineer: Practice
Tuesday, 3 November 2009.
One reader wrote in asking: "How can one practice social engineering before using it in the wild?"

Answering is Chris "loganWHD" Hadnagy, the lead social engineer and developer of the social engineering framework.

Embracing tokenization: Payment without pain
Tuesday, 3 November 2009.
Today, it is expected that merchants accept electronic payments. It is more than expected that those payments are secure. No data leaks or breaches of any kind. The reality is many companies do not truly understand the security vulnerabilities that electronic payments present, nor the solutions on the market. They may think they are secure, but in fact are at great risk.

Worm infections in the enterprise rose by nearly 100%
Monday, 2 November 2009.
The latest Microsoft Security Intelligence Report, which indicates that worm infections in the enterprise rose by nearly 100 percent during the first half of 2009 over the preceding six months. Rogue security software remains a major threat to customers; however, 20 percent fewer customers were affected by rogue infections during the past six months.



Hard drive encryption with Dave Anderson
Malware threats, Windows 7 and cyber crime with Bo Olsen
Social networking privacy issues with Brian Honan
Fuzzing with Ari Takanen
Mac OS X security and forensics with Sean Morrissey
Worldwide surveillance and filtering with Rafal Rohozinski
SQL injection with Justin Clarke

Record levels of spam, malware and Web-based threats
Monday, 2 November 2009.
The number of new file-sharing sites hosting unauthorized, copyrighted content skyrocketed over the last three months, according to the latest report by McAfee. It also shows that spam, malware and Web-based threat creation has reached record levels in the last quarter, and that cybercriminals are extorting site-owners with threats of DDoS attacks.

A closer look at Acunetix Web Vulnerability Scanner 6.5
Thursday, 29 October 2009.
Acunetix Web Vulnerability Scanner is an automated web application security testing tool that audits your web applications by checking for exploitable vulnerabilities. Automated scans may be supplemented and cross-checked with the variety of manual tools to allow for comprehensive web site and web application penetration testing.

New trends in identity theft
Wednesday, 28 October 2009.
Identity theft is the fastest-growing crime in America. More than 70 million identities will be lost this year alone with as many as 3 million social security numbers being stolen. Simple credit monitoring is not enough - only 15% of identity theft is credit-related (85% of identity fraud happens outside the credit system).