Chuck Miller

 
Online Editor
 

Recent Articles

Foiling web app attacks

October 08, 2009

"There's a web app attack for that," might be a suitable ad slogan for cybercriminals these days, reports Chuck Miller.
 

PayPal suspends hacker's account after bogus SSL post

October 07, 2009

PayPal has suspended the account of a researcher who had demonstrated a proof-of-concept for an attack on SSL certificates. The action Tuesday followed the earlier release of a forged SSL certificate into the wild.
 

Microsoft acknowledges Windows Live ID breach

October 05, 2009

Microsoft confirmed Monday that the credentials of thousands of Microsoft Windows Live ID accounts were posted online late last week.
 

WCL partners with OPSWAT

October 02, 2009

West Coast Labs (WCL), an independent test facility for information security products and services, has partnered with OPSWAT, a provider of development tools that power software application manageability. The alliance will allow for the incorporation of data from WCL's Checkmark Certification program into the OPSWAT OESIS Framework, a development toolkit for managing endpoint security applications. — CAM
 

Payload spam volume rockets to new heights

October 02, 2009

After leveling off during the past two years, the amount of spam laden with virus payloads has spiked, according to a new report.
 

SC World Congress 2009 adds RSA, Cisco keynotes

October 02, 2009

The SC World Congress Conference and Expo, scheduled for Oct. 13-14 in New York, has added two new feature speakers. Art Coviello, president of RSA, The Security Division of EMC, and Joel McFarland, senior manager of product management at Cisco, will be focusing on trends driving organizations' rapid movement to the cloud, and the implications for security professionals.
 

Express Scripts data breach may have hit 700,000 victims

October 01, 2009

Hundreds of thousands of members of a pharmacy benefit management firm may have had their information exposed to extortionists.
 

Wave search "poisoned"

September 30, 2009

Google searches on terms related to its new collaboration and communications platform, Google Wave, are leading to a rogue anti-virus programs, according to the Websense Security Labs. Users seeking information on how to sign up for Wave, which currently is by invite-only, have been victimized by manipulated search results that lead to sites designed to trick victims into paying for a security solution that doesn't work. Searches for Microsoft's new Security Essentials consumer anti-virus product also have led to "poisoned" results. — CAM
 

Adware pushers evolve into malware distribution channel

September 30, 2009

An industry built on serving adware has become a full-fledged malware distribution channel.
 

Fake IRS email spam continues to strike users

September 29, 2009

A fake email notice from the IRS contains the pernicious Zeus information-stealing trojan.