SecureWorks Info Feed http://www.secureworks.com/ SecureWorks news, press releases, events, and research alerts. News: Researchers Raise Alarm Over New Iteration of Coreflood Botnet (Dark Reading) http://www.darkreading.com/document.asp?doc_id=159874&WT.svl=news2_1 http://www.darkreading.com/document.asp?doc_id=159874&WT.svl=news2_1 Event: Black Hat USA 2008 http://www.secureworks.com/media/events/ August 02, 2008-August 07, 2008: SecureWorks will be Speaking at Black Hat USA 2008. Location: , Las Vegas, NV. http://www.secureworks.com/media/events/#201 Blog: Police & Thieves http://www.secureworks.com/research/blog/index.php/2008/07/11/police-thieves The Unnamed Police Department (weâll just call them the UPD for short) is charged with keeping the peace in a major American metropolitan area. For a public safety website, theirs is quite advanced. Visitors can view dynamically generated maps showing the distribution of different classes of crimes, make anonymous tips to the narcotics squad, and even try to sign up to join the force. As those of us that work in information security well know, all that rich web functionality brings increased risk. http://www.secureworks.com/research/blog/?p=98 News Blog: The Week's Links: July 14 - July 18, 2007 http://www.secureworks.com/blog/index.php/2008/07/18/the-weeks-links-july-14-july-18-2007 A weekly feature highlighting news stories, reports and editorials of interest to IT and security managers. Also see stories including SecureWorks news, press releases, and research. http://www.secureworks.com/blog/?p=97 Announcement: SecureWorks to Resell Sourcefireâs Enterprise Threat Management Solutions http://www.secureworks.com/media/press_releases/20080718-sourcefire ATLANTA – July 18, 2008 - SecureWorks®, one of the market's leading Security-as-a-Service (SaaS) providers, has expanded its relationship with Snort® creator and open source innovator Sourcefire, Inc. Previously, SecureWorks managed and monitored Sourcefire's security solutions and will now resell all Sourcefire® Enterprise Threat Management (ETM) solutions. SecureWorks is now a one-stop shop for clients and prospects that need managed security services and wish to purchase Sourcefire's ETM offerings. http://www.secureworks.com/media/press_releases/20080718-sourcefire Threat Analysis: Coreflood Removal for the Network Administator http://www.secureworks.com/research/threats/coreflood-removal http://www.secureworks.com/research/threats/coreflood-removal News: Researchers Raise Alarm Over New Iteration of Coreflood Botnet (Dark Reading) http://www.darkreading.com/document.asp?doc_id=159874&WT.svl=news2_1 http://www.darkreading.com/document.asp?doc_id=159874&WT.svl=news2_1 Event: 31st Annual National Directors' Convention http://www.secureworks.com/media/events/ August 05, 2008-August 08, 2008: SecureWorks will be Exhibiting at 31st Annual National Directors' Convention. Location: The Venetian, Las Vegas, NV. http://www.secureworks.com/media/events/#265 Blog: Dan Kaminsky Strikes Again With DNS Vulnerability http://www.secureworks.com/research/blog/index.php/2008/07/10/dan-kaminsky-strikes-again-with-dns-vulnerability This past Tuesday July 8th was a big day in information security. Accomplished security researcher Dan Kaminsky of IOActive announced a major new vulnerability in the DNS infrastructure underpinning the Internet. What is the vulnerability, you ask? We may all have to wait for Dan to tell us at the Black Hat Briefings security conference, kicking off on Wednesday August 6th. http://www.secureworks.com/research/blog/?p=97 News Blog: Identity Theft Red Flags Update http://www.secureworks.com/blog/index.php/2008/07/17/identity-theft-red-flags-update Thanks again to everyone who attended our recent "Red Flags Update" webcast. By popular demand, slides from the website can be downloaded here. http://www.secureworks.com/blog/?p=95 Announcement: Community Bankers Association of Oklahoma Endorses SecureWorks as Their IT Security Services Provider of Choice http://www.secureworks.com/media/press_releases/20080630-cbao Atlanta, GA - and Oklahoma City, OK., - June 30, 2008 Community Bankers Association of Oklahoma (CBAO) has endorsed the services of SecureWorks, one of the market’s leading Security as a Service providers. The endorsement will allow CBAO and SecureWorks to work together to promote IT security services to CBAO’s member banks. http://www.secureworks.com/media/press_releases/20080630-cbao Threat Analysis: SecureWorks Advisory - Multiple DNS Implementations Vulnerable to Cache Poisoning - Action Recommended http://www.secureworks.com/research/threats/securityadvisory http://www.secureworks.com/research/threats/securityadvisory News: Fake news headlines are the latest spam Storm (Technology Live) http://blogs.usatoday.com/technologylive/ http://blogs.usatoday.com/technologylive/ Event: Black Hat http://www.secureworks.com/media/events/ August 06, 2008-August 07, 2008: SecureWorks will be Exhibiting at Black Hat. Location: Caesar's Palace, Las Vegas, NV. http://www.secureworks.com/media/events/#264 Blog: It Can Happen to Anyone http://www.secureworks.com/research/blog/index.php/2008/07/10/it-can-happen-to-anyone Writing good antivirus software is hard. Just ask the developer at a major antivirus company who was infected with the Coreflood trojan on his personal computer for over a year. Perhaps he was just testing their product, but it seems odd to have allowed the trojan to capture some of his personal information. http://www.secureworks.com/research/blog/?p=96 News Blog: Attack of the Disgruntled Network Admin http://www.secureworks.com/blog/index.php/2008/07/17/attack-of-the-disgruntled-network-admin In a CLM of epic proportions (and with possible legal consequences), a network administrator for the City of San Francisco cut off access for some of the âhigher upsâ in the cityâs Department of Technology. Courtesy of SFGate: http://www.secureworks.com/blog/?p=96 Announcement: SecureWorks Revolutionizes Security Information Management with New, On-Demand Service: Touted as the industryâs first on-demand solution to help organizations better manage information security and comply with regulatory standards http://www.secureworks.com/media/press_releases/20080513-simondemand ATLANTA, GA., May 13, 2008 - SecureWorks®, one of the market's leading Security as a Service providers, announces a new service – Security Information Management (SIM) On-Demand™ – that will revolutionize how organizations manage security information, meet regulatory requirements and demonstrate compliance with PCI, SOX, GLBA, FFIEC, HIPAA, NERC CIP and other regulations. SecureWorks' new SIM On-Demand is a software-as-a-service (SaaS) offering that provides the first sustainable solution for collecting and analyzing logs and alerts from security devices and information assets in real time without having to install and manage SIM software or hardware. Unlike traditional SIM product offerings, SecureWorks clients also have instant access to certified security experts at SecureWorks' Security Operations Center for 24x7x365 support should they have any questions. http://www.secureworks.com/media/press_releases/20080513-simondemand Threat Analysis: Coreflood/AFcore Trojan Analysis http://www.secureworks.com/research/threats/coreflood http://www.secureworks.com/research/threats/coreflood News: Protecting Yourself on Public Networks (Inc.) http://www.inc.com/partners/at&t/articles/20080530/protecting.html http://www.inc.com/partners/at&t/articles/20080530/protecting.html Event: 2008 Technology Conference http://www.secureworks.com/media/events/ August 07, 2008: SecureWorks will be Speaking at 2008 Technology Conference. Location: Sea Trail Gold Resort and Conference Center, Sunset Beach, NC. http://www.secureworks.com/media/events/#236 Blog: False Positives in the Legal System http://www.secureworks.com/research/blog/index.php/2008/07/02/false-positives-in-the-legal-system Recently Lori Drew was charged with violating the Computer Fraud and Abuse Act for signing the up for a MySpace account under a fake name. While the larger circumstances were quite shocking (and have been covered enough I don't think I need to go into them), she was charged for nothing more than pretending to be someone else on the Internet. http://www.secureworks.com/research/blog/?p=95 News Blog: The Week's Links: July 7 - July 11, 2007 http://www.secureworks.com/blog/index.php/2008/07/11/the-weeks-links-july-7-july-11-2007 A weekly feature highlighting news stories, reports and editorials of interest to IT and security managers. Also see stories including SecureWorks news, press releases, and research. http://www.secureworks.com/blog/?p=94 Announcement: SecureWorks Launches New Retained Incident Response Service to Assist Organizations in Handling Information Security Incidents http://www.secureworks.com/media/press_releases/20080423-incidenthandling ATLANTA, GA., April 23, 2008 - SecureWorks, a leading Security as a Service provider, announced its new Retained Computer Incident Response Service. The service is designed to help organizations prepare for and respond to cyber security incidents such as phishing, hacker attacks, etc. During the one year retainer contract period, clients can choose to apply the retainer and select from up to nine services in the categories of incident response & forensics, planning & analysis and testing & capability analysis. This service and many others are delivered by SecureWorks' Professional Services team and the Counter Threat Unit™, SecureWorks' applied security research team. http://www.secureworks.com/media/press_releases/20080423-incidenthandling Threat Analysis: New extortion scam aimed at banks in the European Union http://www.secureworks.com/research/threats/extortion http://www.secureworks.com/research/threats/extortion News: Have You Fixed Your Company's DNS Servers? (PC World) http://www.pcworld.com/businesscenter/blogs/larkin_on_the_web/148569/have_you_fixed_your_companys_dns_servers.html http://www.pcworld.com/businesscenter/blogs/larkin_on_the_web/148569/have_you_fixed_your_companys_dns_servers.html Event: Community Bankers Association of Ohio Annual Convention and Trade Show http://www.secureworks.com/media/events/ August 07, 2008-August 10, 2008: SecureWorks will be Exhibiting at Community Bankers Association of Ohio Annual Convention and Trade Show. Location: Sheraton Chicago Hotel and Towers, Chicago, IL. http://www.secureworks.com/media/events/#285 Blog: Down the JavaScript Rabbit Hole http://www.secureworks.com/research/blog/index.php/2008/07/01/down-the-javascript-rabbit-hole In the last weeks, the SecureWorks Counter Threat Unitâ"¢ noticed a significant uptick in the volume of mass SQL injection attacks. What follows is a small part of an in-depth analysis we undertook to better understand these attacks. http://www.secureworks.com/research/blog/?p=94 News Blog: "SIEM tools come up short" http://www.secureworks.com/blog/index.php/2008/07/10/siem-tools-come-up-short Thatâs the title of a review by Greg Shipley over at Network World that evaluated SIEM / SIM products from several midmarket vendors such as NetIQ, TriGeo and Q1Labs. Long story short, the reviewed products didnât live up to expectations: http://www.secureworks.com/blog/?p=93 Announcement: SecureWorks Wins SC Magazine's Readers' Trust Award for Best Managed Security Service for Three Years Running http://www.secureworks.com/media/press_releases/20080411-scawardwin Atlanta, GA., April 11, 2008 - SecureWorks, one of the market's leading Security as a Service providers, was recognized this week with the 2008 Readers' Trust Award for "Best Managed Security Service" for the third year in a row. The announcement was made at the exclusive, SC Magazine Awards Gala, held in conjunction with the annual RSA Conference. This year, SecureWorks' Managed Security Service competed against those from MessageLabs, MX Logic, Solutionary and Symantec to win the "Best Managed Security Service" award. SC Magazine readers representing IT's most knowledgeable security professionals selected SecureWorks' Managed Security Services from among the industries' finest solutions. http://www.secureworks.com/media/press_releases/20080411-scawardwin Threat Analysis: Tax Court Phishing/Whaling Emails Used to Install Spyware http://www.secureworks.com/research/threats/ustaxcourts http://www.secureworks.com/research/threats/ustaxcourts