<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
<channel>
	<title>softsecurity.com This day highlights</title>
	<link>http://www.softsecurity.com</link>
	<description>This day highlights</description>
	<language />
	<copyright />
	<pubDate>Fri, 12 Mar 2010 03:13:27 GMT</pubDate>
	<lastBuildDate>Fri, 12 Mar 2010 03:13:27 GMT</lastBuildDate>
	<category />
	<image />
	
	<item>
		<title>TSA worker tried to sabotage terror database, feds say</title>
		<link>http://softsecurity.com/news/highlights/tsa-worker-tried-to-sabotage-terror-database-feds-say.html</link>
		<description>One week after losing job
A former data analyst for the US Transportation Security Agency has been accused of trying to sabotage a terrorist screening database used to vet people with access to sensitive information and secure areas of the nation?s transportation network.?</description>
		<pubDate>Fri, 12 Mar 2010 01:59:20 GMT</pubDate>
	</item>
	<item>
		<title> Exploit for IE 0-day flaw published, patch still unavailable</title>
		<link>http://softsecurity.com/news/highlights/exploit-for-ie-0-day-flaw-published-patch-still-unavailable.html</link>
		<description>An Israeli hacker has created an exploit for the IE zero-day flaw that Microsoft warned about on Tuesday, and the code is already being inserted into the Metasploit Framework.
 
 According to Ryan Nar...</description>
		<pubDate>Fri, 12 Mar 2010 01:11:48 GMT</pubDate>
	</item>
	<item>
		<title>Microsoft plants Bing on Google-free Chinese Androids</title>
		<link>http://softsecurity.com/news/highlights/microsoft-plants-bing-on-google-free-chinese-androids.html</link>
		<description>Google apps 'postponed' on China carriers
Motorola will soon push Microsoft's Bing search engine onto Android phones in China, after announcing an alliance with the Redmond software giant that will see Bing appear on Androids across the globe.?&lt;a href=&quot;http://whitepapers.theregister.co.uk/paper/view/859/atth0s1n.pdf?td=rss&quot;&gt;The power of collaboration within unified communications&lt;/a&gt;
</description>
		<pubDate>Fri, 12 Mar 2010 00:37:13 GMT</pubDate>
	</item>
	<item>
		<title>Advanced Persistent Threats: Should your panties be in a bunch, and how do you un-bunch them?</title>
		<link>http://softsecurity.com/news/highlights/advanced-persistent-threats-should-your-panties-be-in-a-bunch-and-how-do-you-un-bunch-them.html</link>
		<description>Marketers are starting to abuse the APT (Advanced Persistent Threat) term but that doesn't dilute the true meaning of this adversary.&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;a href=&quot;http://ads.pheedo.com/click.phdo?s=7a8a3ca67ca90f182c9bdef94b36a0f1&amp;p=1&quot;&gt;&lt;img alt=&quot;&quot; style=&quot;border: 0;&quot; border=&quot;0&quot; src=&quot;http://ads.pheedo.com/img.phdo?s=7a8a3ca67ca90f182c9bdef94b36a0f1&amp;p=1&quot;/&gt;&lt;/a&gt;
&lt;img alt=&quot;&quot; height=&quot;0&quot; width=&quot;0&quot; border=&quot;0&quot; style=&quot;display:none&quot; src=&quot;http://a.rfihub.com/eus.gif?eui=2225&quot;/&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/zdnet/security/~4/fMMUYv02WUs&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Fri, 12 Mar 2010 00:00:21 GMT</pubDate>
	</item>
	<item>
		<title> New Federal IT security certification program</title>
		<link>http://softsecurity.com/news/highlights/new-federal-it-security-certification-program.html</link>
		<description>A new certification program specifically designed and tailored to help secure the nation’s Federal information technology systems was unveiled today.
 
 
 The certification program – called the Federa...</description>
		<pubDate>Thu, 11 Mar 2010 22:35:34 GMT</pubDate>
	</item>
	<item>
		<title>One-third of orphaned Zeus botnets find way home</title>
		<link>http://softsecurity.com/news/highlights/one-third-of-orphaned-zeus-botnets-find-way-home.html</link>
		<description>Cyber security's short-lived victory
The takedown of 100 servers used to control Zeus-related botnets may be a short-lived victory, security researchers said after discovering that about one-third of the orphaned channels were able to regain connectivity in less than 48 hours.?&lt;a href=&quot;http://whitepapers.theregister.co.uk/paper/view/892/legoland.pdf?td=rss&quot;&gt;Case Study: WhatsUp keeps Legoland turnstyles ringing&lt;/a&gt;
</description>
		<pubDate>Thu, 11 Mar 2010 22:04:10 GMT</pubDate>
	</item>
	<item>
		<title>Koobface gang refresh botnet to beat takedown</title>
		<link>http://softsecurity.com/news/highlights/koobface-gang-refresh-botnet-to-beat-takedown.html</link>
		<description>Twitter scourge changes pants
Command and Control servers associated with the infamous Koobface worms have gone through a complete refresh over the last fortnight. Russian net security firm Kaspersky Lab reckons the change up might be aimed at making takedown efforts by cybercrime fighters more difficult.?</description>
		<pubDate>Thu, 11 Mar 2010 18:32:16 GMT</pubDate>
	</item>
	<item>
		<title> Targeted attacks exploiting PDF bugs are soaring</title>
		<link>http://softsecurity.com/news/highlights/targeted-attacks-exploiting-pdf-bugs-are-soaring.html</link>
		<description>Adobe is having a hard time fighting its bad reputation when it comes to products riddled with vulnerabilities. Adobe Reader exploits seem the weapon of choice of many a cyber criminal - as can be att...</description>
		<pubDate>Thu, 11 Mar 2010 18:07:05 GMT</pubDate>
	</item>
	<item>
		<title> Q&amp;amp;A: Google hacking</title>
		<link>http://softsecurity.com/news/highlights/qampa-google-hacking.html</link>
		<description>Robert Abela is a Technical Manager at Acunetix and in this interview he discusses the importance of Google for security research, provides tips on Google for information gathering and more.
 
 Based ...</description>
		<pubDate>Thu, 11 Mar 2010 17:59:01 GMT</pubDate>
	</item>
	<item>
		<title>Is that a bot in your pocket? Or does it just look like one?</title>
		<link>http://softsecurity.com/news/highlights/is-that-a-bot-in-your-pocket-or-does-it-just-look-like-one.html</link>
		<description>Results from a research project titled MOBOTS: Pocketful of Pwnage, which was designed to show how easy it would be to create a large mobile botnet.&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;a href=&quot;http://ads.pheedo.com/click.phdo?s=25e210250c757c4ace59b4ebfd2fd31b&amp;p=1&quot;&gt;&lt;img alt=&quot;&quot; style=&quot;border: 0;&quot; border=&quot;0&quot; src=&quot;http://ads.pheedo.com/img.phdo?s=25e210250c757c4ace59b4ebfd2fd31b&amp;p=1&quot;/&gt;&lt;/a&gt;
&lt;img alt=&quot;&quot; height=&quot;0&quot; width=&quot;0&quot; border=&quot;0&quot; style=&quot;display:none&quot; src=&quot;http://a.rfihub.com/eus.gif?eui=2225&quot;/&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/zdnet/security/~4/dQxEEtrWUuo&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Thu, 11 Mar 2010 17:47:38 GMT</pubDate>
	</item>
	<item>
		<title>0-day exploits for IE flaw another reason to switch to IE8</title>
		<link>http://softsecurity.com/news/highlights/0-day-exploits-for-ie-flaw-another-reason-to-switch-to-ie8.html</link>
		<description>
    Microsoft &lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/981374.mspx&quot;&gt;confirmed on Tuesday&lt;/a&gt; a new flaw affecting version 6 and 7 of its Internet Explorer web browser that could allow remote code execution. The security advisory noted that targeted attacks using the flaw were already in the wild.
This information was confirmed by &lt;a href=&quot;http://www.avertlabs.com/research/blog/index.php/2010/03/09/targeted-internet-explorer-0day-attack-announced-cve-2010-0806/&quot;&gt;McAfee&lt;/a&gt;, reporting that exploitation of the flaw was originating from the domain topix21century dot com over both HTTP and HTTPS. The drive-by attacks install a &lt;a href=&quot;http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-031015-0224-99&quot;&gt;backdoor&lt;/a&gt; which connects to a command-and-control server. 
&lt;a href=&quot;http://www.symantec.com/connect/blogs/zero-day-attack-ie6-jssykipot-doesn-t-spare-retired-software&quot;&gt;Analysis by Symantec&lt;/a&gt; reveals that the exploit works effectively on IE6. IE7 tended to crash instead, and IE8 is, as stated in the Microsoft advisory, immune. The attack loads some malicious code, and then makes repeated changes to the HTML document eventually provoking execution of the malicious code.
The best solution is to upgrade to IE8, as one of the many improvements found in this browser also seals off the security hole. Failing that, enabling Data Execution Prevention in IE7 should provide some level of mitigation, as the current exploits do not circumvent DEP (though they could probably be combined with &lt;a href=&quot;http://skypher.com/index.php/2010/03/01/internet-exploiter-2-dep/&quot;&gt;DEP bypass techniques&lt;/a&gt;). Removing access to the file iepeers.dll using either of the mechanisms described in Microsoft's advisory prevents Internet Explorer from loading the flawed code, but may also break print and web folder functionality. Finally, disabling of scripting and ActiveX in the Internet and Local Intranet security zones should also provide protection against exploitation.
Microsoft has still made no indication whether this flaw will receive an out-of-band update, but with exploits in the wild and documented analysis of the exploit, clearly this flaw is something that needs fixing, and soon.    
        
    
     &lt;a href=&quot;http://arstechnica.com/microsoft/news/2010/03/0day-exploits-for-ie-flaw-another-reason-to-switch-to-ie-8.ars?comments=1&amp;amp;utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=rss#comments-bar&quot;&gt;Read the comments on this post&lt;/a&gt;
&lt;a href=&quot;http://feedads.g.doubleclick.net/~at/2qXiuDPLeMAnlG9AWujcp8xgvXo/0/da&quot;&gt;&lt;img src=&quot;http://feedads.g.doubleclick.net/~at/2qXiuDPLeMAnlG9AWujcp8xgvXo/0/di&quot; border=&quot;0&quot; ismap=&quot;true&quot;&gt;&lt;/img&gt;&lt;/a&gt;
&lt;a href=&quot;http://feedads.g.doubleclick.net/~at/2qXiuDPLeMAnlG9AWujcp8xgvXo/1/da&quot;&gt;&lt;img src=&quot;http://feedads.g.doubleclick.net/~at/2qXiuDPLeMAnlG9AWujcp8xgvXo/1/di&quot; border=&quot;0&quot; ismap=&quot;true&quot;&gt;&lt;/img&gt;&lt;/a&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/arstechnica/security/~4/zxQR0iBSIWQ&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Thu, 11 Mar 2010 17:45:00 GMT</pubDate>
	</item>
	<item>
		<title> Koobface worm doubles its number of command and control servers</title>
		<link>http://softsecurity.com/news/highlights/koobface-worm-doubles-its-number-of-command-and-control-servers.html</link>
		<description>The shut down and recovery of the Troyak-as command and control center (C&amp;amp;C) for the active Zeus botnet was good news for the whole IT security community.
 
 Unfortunately, as some botnets struggle, o...</description>
		<pubDate>Thu, 11 Mar 2010 16:50:19 GMT</pubDate>
	</item>
	<item>
		<title> It&amp;apos;s time to embrace the shift to the cloud</title>
		<link>http://softsecurity.com/news/highlights/itaposs-time-to-embrace-the-shift-to-the-cloud.html</link>
		<description>The software industry is entering another age of astonishing innovation. It&amp;apos;s a time when not only software is advancing at a fast pace, but so too are hardware devices – where power is increasing as ...</description>
		<pubDate>Thu, 11 Mar 2010 15:54:45 GMT</pubDate>
	</item>
	<item>
		<title>Estonian DDoS revenge worm crafter jailed</title>
		<link>http://softsecurity.com/news/highlights/estonian-ddos-revenge-worm-crafter-jailed.html</link>
		<description>Infection still spreading
An Estonian virus writer has been jailed for two and a half years for creating a Windows worm family that launched denial of service attacks on the websites of a local insurance firm and ISP.?</description>
		<pubDate>Thu, 11 Mar 2010 15:35:06 GMT</pubDate>
	</item>
	<item>
		<title> File sharing networks open door to identity theft</title>
		<link>http://softsecurity.com/news/highlights/file-sharing-networks-open-door-to-identity-theft.html</link>
		<description>According to the Washington Post, in any given second, nearly 22 million people around the globe are on peer-to-peer file-sharing networks downloading and swapping movies, software and documents over ...</description>
		<pubDate>Thu, 11 Mar 2010 14:43:46 GMT</pubDate>
	</item>
	<item>
		<title> Employees continue to put data at risk</title>
		<link>http://softsecurity.com/news/highlights/employees-continue-to-put-data-at-risk.html</link>
		<description>According to a Ponemon Institute study, business managers continue to pose the greatest threat to sensitive company information such as customer records, health information and other private data. Des...</description>
		<pubDate>Thu, 11 Mar 2010 14:27:11 GMT</pubDate>
	</item>
	<item>
		<title>Tories on cyber war: Waffle, mutter, waffle. Um, vote for us!</title>
		<link>http://softsecurity.com/news/highlights/tories-on-cyber-war-waffle-mutter-waffle.-um-vote-for-us.html</link>
		<description>'Computers. Clicking, typing. Email. I could go on'
Tory peer and shadow security minister Baroness Pauline Neville Jones has set out her party's thoughts on cyber war and defence. Unfortunately once the waffle is stripped away there's pretty much nothing there.?</description>
		<pubDate>Thu, 11 Mar 2010 14:22:58 GMT</pubDate>
	</item>
	<item>
		<title>Password reset questions dead easy to guess</title>
		<link>http://softsecurity.com/news/highlights/password-reset-questions-dead-easy-to-guess.html</link>
		<description>Your pet's name is Poochie? You're pwned
Guessing the answer to common password reset questions is far easier than previously thought, according to a new study by computer science researchers.?</description>
		<pubDate>Thu, 11 Mar 2010 14:18:29 GMT</pubDate>
	</item>
	<item>
		<title>Bogus Playstation emulators pack Trojan payload</title>
		<link>http://softsecurity.com/news/highlights/bogus-playstation-emulators-pack-trojan-payload.html</link>
		<description>'Will be around for a long time'
Retro gaming fans are being targeted in a new con designed to infect computers with a Trojan linked to scareware scams.?</description>
		<pubDate>Thu, 11 Mar 2010 12:49:25 GMT</pubDate>
	</item>
	<item>
		<title>PayPal restores Cryptome for real</title>
		<link>http://softsecurity.com/news/highlights/paypal-restores-cryptome-for-real.html</link>
		<description>Now go away
PayPal has finally made good on its pledge to restore Cryptome's account many hours after the firm's head of global communications told Register readers it had already done so.?</description>
		<pubDate>Thu, 11 Mar 2010 12:28:46 GMT</pubDate>
	</item>
	<item>
		<title>etc: Another botnet takes a beating as Kazakh ISP Troyak is taken offline, temporarily disabling most of the command-and-control servers for the Zeus network.</title>
		<link>http://softsecurity.com/news/highlights/etc-another-botnet-takes-a-beating-as-kazakh-isp-troyak-is-taken-offline-temporarily-disabling-most-of-the-command-and-control-servers-for-the-zeus-network..html</link>
		<description>
    Another botnet takes a beating as Kazakh ISP Troyak is taken offline, temporarily disabling most of the command-and-control servers for the Zeus network.    
        
                        &lt;strong&gt;Read More:&lt;/strong&gt;
                  &lt;a href=&quot;http://www.computerworld.com/s/article/9169039/Zeus_botnet_dealt_a_blow_as_ISP_Troyak_knocked_out?source=rss_news&quot;&gt;Computerworld&lt;/a&gt;,                 &lt;a href=&quot;http://www.abuse.ch/?p=2417&quot;&gt;abuse.ch&lt;/a&gt;            
          
     &lt;a href=&quot;http://arstechnica.com/security/news/2010/03/another-botnet-takes-a-beating.ars?comments=1&amp;amp;utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=rss#comments-bar&quot;&gt;Read the comments on this post&lt;/a&gt;
&lt;a href=&quot;http://feedads.g.doubleclick.net/~at/nz2SUypxUcembya4izF4xSqgQYA/0/da&quot;&gt;&lt;img src=&quot;http://feedads.g.doubleclick.net/~at/nz2SUypxUcembya4izF4xSqgQYA/0/di&quot; border=&quot;0&quot; ismap=&quot;true&quot;&gt;&lt;/img&gt;&lt;/a&gt;
&lt;a href=&quot;http://feedads.g.doubleclick.net/~at/nz2SUypxUcembya4izF4xSqgQYA/1/da&quot;&gt;&lt;img src=&quot;http://feedads.g.doubleclick.net/~at/nz2SUypxUcembya4izF4xSqgQYA/1/di&quot; border=&quot;0&quot; ismap=&quot;true&quot;&gt;&lt;/img&gt;&lt;/a&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/arstechnica/security/~4/4rQ4G3Mc8Mo&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Thu, 11 Mar 2010 05:05:29 GMT</pubDate>
	</item>
	<item>
		<title>Zeus botnets suffer mighty blow after ISP taken offline</title>
		<link>http://softsecurity.com/news/highlights/zeus-botnets-suffer-mighty-blow-after-isp-taken-offline.html</link>
		<description>One quarter of C&amp;amp;C channels vanish
At least a quarter of the command and control servers linked to Zeus-related botnets have suddenly gone quiet, continuing a recent trend of takedowns hitting some of the world's most nefarious cyber operations.?&lt;a href=&quot;http://whitepapers.theregister.co.uk/paper/view/696/smartprotection-whitepaper.pdf?td=rss&quot;&gt;Offloading malware protection to the cloud&lt;/a&gt;
</description>
		<pubDate>Thu, 11 Mar 2010 01:23:57 GMT</pubDate>
	</item>
	<item>
		<title>IE zero-day flaw leaks out; Exploit code published</title>
		<link>http://softsecurity.com/news/highlights/ie-zero-day-flaw-leaks-out-exploit-code-published.html</link>
		<description>Using obvious clues from a McAfee blog post, an Israeli hacker was able to pinpoint the latest Internet Explorer zero-day vulnerability and create working exploit code&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;a href=&quot;http://ads.pheedo.com/click.phdo?s=d34f0852a1e8a36cd9ab1c1bfb86a32a&amp;p=1&quot;&gt;&lt;img alt=&quot;&quot; style=&quot;border: 0;&quot; border=&quot;0&quot; src=&quot;http://ads.pheedo.com/img.phdo?s=d34f0852a1e8a36cd9ab1c1bfb86a32a&amp;p=1&quot;/&gt;&lt;/a&gt;
&lt;img alt=&quot;&quot; height=&quot;0&quot; width=&quot;0&quot; border=&quot;0&quot; style=&quot;display:none&quot; src=&quot;http://a.rfihub.com/eus.gif?eui=2225&quot;/&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/zdnet/security/~4/JNK6xNgbdLw&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Thu, 11 Mar 2010 01:22:12 GMT</pubDate>
	</item>
	<item>
		<title>Bad employee! 12% knowingly violate company IT policies</title>
		<link>http://softsecurity.com/news/highlights/bad-employee-12-knowingly-violate-company-it-policies.html</link>
		<description>
    
By now, it's practically a mantra that the biggest problem with corporate IT security is the employees themselves. However, we usually assume that's due to ignorant users or poorly enforced policies. Not so for a chunk of the US working population&amp;#8212;according to a survey conducted by Harris Interactive, 12 percent admitted to knowingly violating IT policy in order to get work done. 

The survey of 1,347 employed adults was conducted on behalf of &lt;a href=&quot;http://www.fiberlink.com/&quot;&gt;Fiberlink&lt;/a&gt;, a company that hawks services that &quot;help enterprises connect, control and secure laptops and mobile devices.&quot; Needless to say, the survey results fit perfectly into the company's agenda, but they are hardly surprising. After all, how many of us know someone who has left a work laptop in an unattended vehicle, sent unencrypted e-mails without permission, or reused the same three passwords over and over instead of choosing new ones every 90 days?

Fiberlink CEO Jim Sheward warned of the obvious. &quot;IT departments nationwide spend a lot of time and money on their compliance, usage, and access policies, but they only work if people follow the rules,&quot; he said in an e-mailed statement. [C]ompanies could face dangerous breaches that include the loss of sensitive data, competitive intelligence, or customers&amp;#8217; private information.&quot;

Harris' findings are supported by previous reports saying that &lt;a href=&quot;http://arstechnica.com/security/news/2008/07/leaky-employees-data-pose-bigger-security-risk-than-malware.ars&quot;&gt;leaky employees are a bigger threat than malware&lt;/a&gt;, that &lt;a href=&quot;http://arstechnica.com/security/news/2008/10/employees-not-it-responsible-for-most-corporate-data-loss.ars&quot;&gt;employees (not hackers) cause the most corporate data loss&lt;/a&gt;, and that &lt;a href=&quot;http://arstechnica.com/security/news/2009/07/it-admins-users-online-antics-greatest-threat-to-security.ars&quot;&gt;employees' online activities&lt;/a&gt; pose the greatest threat to IT security. With 12 percent of those people actively working outside of stated IT policy (and plenty more who do so out of ignorance), IT admins certainly have their work cut out for them if they want to maintain a tight ship.     
        
    
     &lt;a href=&quot;http://arstechnica.com/business/news/2010/03/bad-employee-12-knowingly-violate-company-it-policies.ars?comments=1&amp;amp;utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=rss#comments-bar&quot;&gt;Read the comments on this post&lt;/a&gt;
&lt;a href=&quot;http://feedads.g.doubleclick.net/~at/2Fn4aoy7aB0FmOnTrZ37SrescDA/0/da&quot;&gt;&lt;img src=&quot;http://feedads.g.doubleclick.net/~at/2Fn4aoy7aB0FmOnTrZ37SrescDA/0/di&quot; border=&quot;0&quot; ismap=&quot;true&quot;&gt;&lt;/img&gt;&lt;/a&gt;
&lt;a href=&quot;http://feedads.g.doubleclick.net/~at/2Fn4aoy7aB0FmOnTrZ37SrescDA/1/da&quot;&gt;&lt;img src=&quot;http://feedads.g.doubleclick.net/~at/2Fn4aoy7aB0FmOnTrZ37SrescDA/1/di&quot; border=&quot;0&quot; ismap=&quot;true&quot;&gt;&lt;/img&gt;&lt;/a&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/arstechnica/security/~4/5wCDJtMz95Y&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Thu, 11 Mar 2010 01:17:00 GMT</pubDate>
	</item>
	<item>
		<title> 13m users worldwide affected by Mariposa botnet</title>
		<link>http://softsecurity.com/news/highlights/13m-users-worldwide-affected-by-mariposa-botnet.html</link>
		<description>Following the worldwide shutdown of the Mariposa botnet last week, Panda Security reported today that the massive botnet had infected 13 million computers in 190 countries and 31,901 cities. 
 
 Accor...</description>
		<pubDate>Thu, 11 Mar 2010 00:03:35 GMT</pubDate>
	</item>
	<item>
		<title>Freshly patched Adobe PDF flaw under 'active attack'</title>
		<link>http://softsecurity.com/news/highlights/freshly-patched-adobe-pdf-flaw-under-active-attack.html</link>
		<description>Malicious hackers have pounced on a newly patched Adobe PDF Reader vulnerability to plant Trojan downloaders on tardy Windows users.&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;a href=&quot;http://ads.pheedo.com/click.phdo?s=18df89d1661e3a2cb65796dbfe673b81&amp;p=1&quot;&gt;&lt;img alt=&quot;&quot; style=&quot;border: 0;&quot; border=&quot;0&quot; src=&quot;http://ads.pheedo.com/img.phdo?s=18df89d1661e3a2cb65796dbfe673b81&amp;p=1&quot;/&gt;&lt;/a&gt;
&lt;img alt=&quot;&quot; height=&quot;0&quot; width=&quot;0&quot; border=&quot;0&quot; style=&quot;display:none&quot; src=&quot;http://a.rfihub.com/eus.gif?eui=2225&quot;/&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/zdnet/security/~4/UHpW8QUxLI0&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Wed, 10 Mar 2010 23:52:48 GMT</pubDate>
	</item>
	<item>
		<title>Hackers can locate and exploit the Energizer USB charger backdoor</title>
		<link>http://softsecurity.com/news/highlights/hackers-can-locate-and-exploit-the-energizer-usb-charger-backdoor.html</link>
		<description>Hackers using the freely available Metasploit tool can locate infected systems on the local network or gain access to a system running the Energizer backdoor.&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;a href=&quot;http://ads.pheedo.com/click.phdo?s=d64cf994121d6d12e1d306e110ab0315&amp;p=1&quot;&gt;&lt;img alt=&quot;&quot; style=&quot;border: 0;&quot; border=&quot;0&quot; src=&quot;http://ads.pheedo.com/img.phdo?s=d64cf994121d6d12e1d306e110ab0315&amp;p=1&quot;/&gt;&lt;/a&gt;
&lt;img alt=&quot;&quot; height=&quot;0&quot; width=&quot;0&quot; border=&quot;0&quot; style=&quot;display:none&quot; src=&quot;http://a.rfihub.com/eus.gif?eui=2225&quot;/&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/zdnet/security/~4/ZOuVk1VJFa8&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Wed, 10 Mar 2010 23:21:22 GMT</pubDate>
	</item>
	<item>
		<title>New Twitter Feature Looks For Malicious URLs</title>
		<link>http://softsecurity.com/news/highlights/new-twitter-feature-looks-for-malicious-urls.html</link>
		<description>Meanwhile, one in eight Twitter accounts is either malicious, suspicious, or suspended, according to a new report from Barracuda Networks
			
				
					
				  
			  
			</description>
		<pubDate>Wed, 10 Mar 2010 21:53:00 GMT</pubDate>
	</item>
	<item>
		<title> Most malicious websites are hosted in the US</title>
		<link>http://softsecurity.com/news/highlights/most-malicious-websites-are-hosted-in-the-us.html</link>
		<description>AVG Technologies unveiled the results of a research study which shows that – contrary to popular opinion – most malicious websites are hosted on US servers and not in other countries like China.
 
 Th...</description>
		<pubDate>Wed, 10 Mar 2010 21:52:49 GMT</pubDate>
	</item>
	<item>
		<title>LifeLock fined $12 million over lack of life-locking ability</title>
		<link>http://softsecurity.com/news/highlights/lifelock-fined-12-million-over-lack-of-life-locking-ability.html</link>
		<description>&lt;a href=&quot;http://arstechnica.com/tech-policy/news/2010/03/lifelock-cant-guarantee-id-theft-prevention-after-all-settles-with-ftc.ars?utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=rss&quot;&gt;
  &lt;img vspace=&quot;4&quot; hspace=&quot;4&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://static.arstechnica.com/assets/2010/01/identitytheft-thumb-230x130-11477-f.jpg&quot; /&gt;
  &lt;/a&gt;
        
    

Identity theft prevention service &lt;a href=&quot;http://www.lifelock.com/&quot;&gt;LifeLock&lt;/a&gt; is not as pristine as its reputation claims after all. The company agreed to pay out $12 million to settle charges with the Federal Trade Commission and 35 states, which had said that LifeLock's identity-theft-prevention claims were false and that the company actually made its own customer data available and unsecured from theft. As it turns out, there is no way to fully guarantee that identity theft won't happen, no matter what someone puts on the side of a truck. 

LifeLock has made a name for itself as the go-to service if you never want to have any part of your identity stolen, ever. The company claims to proactively protect your information against fraud, alert you to any kind of shady activity, and reduce credit card offers for $10-15 per month. Those who have seen LifeLock's trucks driving around their cities know that the company used to slap its CEO Todd Davis' social security number on the side of the vehicle along with a number of claims guaranteeing that its customers won't fall victim. (As an aside, Davis' identity allegedly &lt;a href=&quot;http://www.macsplaceonline.com/2007/09/25/reposted-ceo-of-lifelock-identity-stolen/&quot;&gt;ended up getting stolen&lt;/a&gt; in 2007.)
    
          &lt;a href=&quot;http://arstechnica.com/tech-policy/news/2010/03/lifelock-cant-guarantee-id-theft-prevention-after-all-settles-with-ftc.ars?utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=rss&quot; title=&quot;Click here to continue reading this article&quot;&gt;&lt;img src=&quot;http://static.arstechnica.com/mt-static/plugins/ArsTheme/images/read-more.jpg&quot; alt=&quot;Read the rest of this article...&quot;&gt;&lt;/a&gt;      
        
    
     &lt;a href=&quot;http://arstechnica.com/tech-policy/news/2010/03/lifelock-cant-guarantee-id-theft-prevention-after-all-settles-with-ftc.ars?comments=1&amp;amp;utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=rss#comments-bar&quot;&gt;Read the comments on this post&lt;/a&gt;
&lt;a href=&quot;http://feedads.g.doubleclick.net/~at/VFW-Ik1QsUnGB0H4lDnDZfbZVuU/0/da&quot;&gt;&lt;img src=&quot;http://feedads.g.doubleclick.net/~at/VFW-Ik1QsUnGB0H4lDnDZfbZVuU/0/di&quot; border=&quot;0&quot; ismap=&quot;true&quot;&gt;&lt;/img&gt;&lt;/a&gt;
&lt;a href=&quot;http://feedads.g.doubleclick.net/~at/VFW-Ik1QsUnGB0H4lDnDZfbZVuU/1/da&quot;&gt;&lt;img src=&quot;http://feedads.g.doubleclick.net/~at/VFW-Ik1QsUnGB0H4lDnDZfbZVuU/1/di&quot; border=&quot;0&quot; ismap=&quot;true&quot;&gt;&lt;/img&gt;&lt;/a&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/arstechnica/security/~4/0Yyu1Q6ckNk&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Wed, 10 Mar 2010 21:37:00 GMT</pubDate>
	</item>
</channel>
</rss>