Friday, November 7, 2014

IBM Enterprise Insight Analysis to counter cyber crime

IBM talked about its latest service with a goal to improve data gathering and cater the need to fight against cyber crime promptly and efficiently. IBM launched this service at IBM Insight conference held in Las Vegas. IBM i2 Enterprise Insight Analysis (EIA) uncover hidden patterns found in huge volumes of data within few seconds. It works on data-to-decision process that makes it more reliable findings against cyber threats than formal security analysis which may take long durations to find out. IBM i2 Enterprise Insight Analysis works on IBM Power Systems to investigate "non-obvious" connections between data and uncover hidden activities. <more>

Saturday, November 1, 2014

HIGH RISK Windows bug exploited in the wild

Except for Windows Server 2003 all remaining versions of Microsoft Windows are susceptible to 0-day flaw found in the OLE (Object Linking and Embedding) technology that allows remote code execution on the victim's machine. OLE is used in the Microsoft Office applications to create and edit data in multiple formats. The company is also aware of targeted attacks which can be exploited by using PowerPoint documents. Due to this, Microsoft has come up with a workaround dubbed 'Fix it'. Microsoft gives credit to cyber security researchers Drew Hintz, Shane Huntley, and Matty Pellegrino of the Google Security Team and Haifei Li and Bing Sun of the McAfee Security Team for finding and analyzing the vulnerability. Company also urged users to perform double-check before opening Office documents especially PowerPoint documents. <more>

Google supports 2FA security mechanism for USB

In order to secure user accounts, Google is providing additional support to physical USB through two-factor authentication mechanism. Google has already implemented 2FA verification mechanism for their accounts which ask for user to provide input one-time-use codes received via text message or generated through mobile application. According to Google Security product manager, USB uses security key which starts after verifying the legitimacy of Google website. The Security Key only works with Chrome version 38 and later that uses Universal 2nd Factor (U2F) developed by the FIDO Alliance. <more>