cybersecurity

Report: Conficker worm beaten but not gone

The Conficker worm may have been squashed, but this nasty piece of malware is still squirming around millions of computers around the world.

Those were the findings of the Conficker Working Group, a collection of antivirus vendors and several other parties that joined forces in 2009 and 2010 to try to stomp out the worm.

Releasing a "Lessons Learned" document (PDF) yesterday, the CWG claimed success in ultimately stopping Conficker from communicating with its creator, thus preventing it from updating into newer and more dangerous variants. The group seemed especially proud of the way the various organizations and … Read more

OECD: Cyberwar risk is exaggerated

While governments need to prepare for cyberattacks involving espionage or malware, the likelihood of a sophisticated attack like Stuxnet is small, according to a study by the Organisation for Economic Co-operation and Development.

In a cyberwarfare report (PDF) released today, the OECD said that the risk of a catastrophic attack on critical national systems has been exaggerated. The majority of cyberattacks are low-level and cause inconvenience rather than serious or long-term disruption, according to a co-author of the report, professor Peter Sommer of the London School of Economics.

"There are many scare stories, which, when you test, don't … Read more

Obama to hand Commerce Dept. authority over cybersecurity ID

STANFORD, Calif.--President Obama is planning to hand the U.S. Commerce Department authority over a forthcoming cybersecurity effort to create an Internet ID for Americans, a White House official said here today.

It's "the absolute perfect spot in the U.S. government" to centralize efforts toward creating an "identity ecosystem" for the Internet, White House Cybersecurity Coordinator Howard Schmidt said.

That news, first reported by CNET, effectively pushes the department to the forefront of the issue, beating out other potential candidates, including the National Security Agency and the Department of Homeland Security. The move … Read more

Cybersecurity bill gives DHS power to punish tech firms

Democratic politicians are proposing a novel approach to cybersecurity: fine technology companies $100,000 a day unless they comply with directives imposed by the U.S. Department of Homeland Security.

Legislation introduced this week would allow DHS Secretary Janet Napolitano to levy those and other civil penalties on noncompliant companies that the government deems "critical," a broad term that could sweep in Web firms, broadband providers, and even software companies and search engines.

"This bill will make our nation more secure and better positions DHS--the 'focal point for the security of cyberspace'--to fulfill its critical homeland … Read more

People feel safer on a PC than on a mobile device

If you feel safer online using your PC instead of your mobile phone, you are not alone.

A majority 87 percent of people polled for a new study think their home PCs offer better defense against viruses, malware, and hackers than do their mobile phones. Released today by the National Cyber Security Alliance and Symantec, the study (PDF) also discovered that people may be overconfident in the power of their computers to protect them as less than half are using full security software.

Though only 24 percent of those polled said they feel very safe using their home computers to … Read more

Study finds support for presidential Net 'kill switch'

If the U.S. were hit by a severe cyberattack, would you want the president to be able to control or even shut down portions of the Internet?

A majority 61 percent of Americans polled by Unisys for a new security study believes the president should have the power to control or effectively "kill" portions of the Internet if key U.S. systems (military, financial, electrical) were hit by a malicious cyberattack from a foreign government.

These findings from the latest biannual Unisys Security Index suggest that the public may support a pending cybersecurity bill that would give … Read more

White House gets so-so grades on privacy

Although it has touted privacy as a key concern, the White House isn't faring as well as it should in that area, at least according to a report card from a noted privacy group.

Released last week by the Electronic Privacy Information Center (EPIC), the 2010 privacy report card (PDF) gave the Obama administration a grade of C in consumer privacy, a B in medical privacy, a D in civil liberties, and a B in cybersecurity. Offered by a group of privacy experts at a Capitol Hill briefing, the 2010 report card reflects lower grades in a couple of … Read more

Panda Antivirus debuts for the Mac

Panda Security has launched its latest product, this one geared specifically for Mac users.

The security firm today unveiled Panda Antivirus for the Mac, designed to defend Mac OS and OS X users against viruses, spyware, adware, and other forms of malware. In addition to scanning e-mail and local files on the Mac, the new software will prevent Mac users from unknowingly sending malware-infected documents to friends and colleagues running Windows or Linux, Panda said.

Moving beyond the computer, the software will also scan iPhones, iPads, and iPods to make sure those portable gadgets aren't delivering malware to other … Read more

AVG's challenge: Getting people to protect themselves (Q&A)

As the CEO of security vendor AVG, J.R. Smith oversees a lineup of antivirus products used by 110 million customers around the world. And while those people may be relatively secure from the latest malware threats, Smith feels a greater effort is needed to reach out to the many who aren't protected.

A lot of computer users think they're protected with antivirus software but actually aren't, believes Smith, while others just don't seem to take security seriously enough, assuming that their banks and other companies they do business with will protect them.

Beyond just basic … Read more

Most infrastructure firms feel ready for cyberattacks

Nearly half of those who work in critical infrastructure systems worldwide expect their company to be targeted by a computer attack over the next year, a new survey has found.

About one-third of the respondents say their company is "extremely" prepared to deal with it, according to the survey (PDF) released today by security company Symantec.

Another 36 percent to 41 percent (depending on the type of attack) say their company is "somewhat" prepared to deal with attacks that range from attempted theft and modification or destruction of data to shutting down computer networks and manipulating … Read more