
Together, Firefox and Internet Explorer are brewing up some security trouble. That’s the latest update from security researchers who initially laid the blame on Microsoft’s Internet Explorer for the latest zero-day exploit that also can afflict those using the Firefox Web browser.
Users could face a "highly critical" risk if they have both IE and Firefox version 2.0, or later, loaded on their computer. The trouble begins when browsing a malicious site while using IE and it registers a "firefoxurl://" URI (uniform resource identifier) handler, which allows the browser to interact with specific resources on the Web. As a result, users may find their systems remotely compromised.
Earlier Tuesday, security researcher Thor Larholm, who discovered the IE flaw, and security research giant Symantec put much of the blame on IE, while Secunia’s Thomas Kristensen, chief technology officer, attributed the problem to Firefox versions 2.0 or later.

IBM announced that it is granting universal and perpetual access to certain intellectual property that might be necessary in implementing more than 150 standards designed to make software interoperable.
One likely result of this pledge to commercial and open source communities is that it will be easier for more computing devices and software to be compatible with one another. The move, which IBM believes is the largest of its kind, is also designed to spur industry innovation, while discouraging litigation.
The software specifications and protocols involved in the pledge underpin industry standards, such as those reflected in Web Services: programming, transactions and data exchanged on the Internet and Web. These are typically under, or moving toward, stewardship by standards groups such as the World Wide Web Consortium and OASIS.

Quantum announced the GoVault Data Protection Solution. Designed for small businesses and branch offices, GoVault is a fast, simple and highly reliable disk-based, all-in-one storage solution. It includes a tabletop or server-embedded intelligent dock and two rugged, removable cartridges for on-site and off-site data protection. In addition, GoVault includes backup software for Windows featuring unique data de-duplication technology that reduces the number of cartridges required for backups by as much as 20:1 over alternative tape- and disk-backup products and, thereby, provides a significant cost advantage.

IBM announced the results of a survey of customers that found the decision to adopt a service oriented architecture strategy has moved away from the realm of IT staffers to business executives. SOA is a business strategy that helps a company reuse existing technology to more closely align it with business goals, helping to result in greater efficiencies, cost savings and productivity.
The survey was conducted for IBM by the Link Group and consisted of a sampling of customers at the IBM Impact 2007 event, IBM’s inaugural worldwide SOA customer event with more than 4,200 attendees. The survey indicates that participating respondents are overwhelmingly making the decision to move to an SOA. However, to realize these benefits, the survey also found that there is an increasing need for training staff so they possess the unique combination of both business and IT skills. Additionally, the survey revealed that IT budgets for SOA projects are on the rise and SOA is being used to meet new business challenges.

Although large commercial vendors made early strides into the market for SOA software, open-source components are rapidly finding their way into the picture.
Vendors such as Iona Technologies, Red Hat, MuleSource, WSO2, Sun Microsystems and even IBM are pushing open-source components as key pieces of service-oriented architecture implementations.
To solidify its move into the open-source SOA world, Iona acquired LogicBlaze in April. Now the company will show off the fruits of that acquisition July 9 with several new initiatives designed to give customers the products, services and support programs–as well as opportunities for community participation–required to successfully incorporate open-source technology into SOA deployments, said Eric Newcomer, chief technology officer at Iona.

During the 2004 presidential campaign, Jeremy Poteet watched as the candidate’s site he had worked to secure went up. Just 16 minutes later, the site was attacked.
But this high-profile site deftly deflected these attacks and the others that followed because Poteet had anticipated–and then protected against–the kinds of exploits he knew would be coming. How did he know? Quite simply, he’s a hacker, and thinking like a hacker–and getting to know the tools that hackers use–is one of the most effective ways to protect your company from being exploited.
Poteet, chief security officer at AppDefense, is the type of hacker commonly referred to as a white-hat hacker or security researcher–someone who digs for system holes to point out where trouble could occur. Black-hat hackers are just the opposite–people who try to gain access to systems and the data on them for nefarious purposes. In the past, most hackers were in it for fun or for bragging rights.

Blacklists have their place for detecting and identifying malicious content and activity, with the whole signature-based malware detection industry effectively being built around the concept that blacklists are reliable mechanisms. The only problem is that they aren’t.
They certainly are an important element of security models, but the last couple of decades of security research has shown that they quickly become ineffective in the face of a rapidly evolving threat.
Blacklists of known spam-generating IPs and malware-serving sites, we start to see significant problems emerge with this particular approach to protection.
Many mail server administrators will have encountered at least one period where they have found their IP on an RBL (Real Time Block List) alongside IPs that have seen to be spewing spam across networks (or they could have just had AOL mailing list subscribers who find it easier to report as spam than unsubscribe from something they manually subscribed to). With the use of dynamic IP addresses and virtual hosts, many have found that if they have a bad network neighbor, they can be hit with the same blocking (we’ve had it happen a few times) from indiscriminate RBL maintainers.
Even important registries are not immune from arbitrary blockage and ongoing annoyance from poorly developed RBLs.

We just finished the full edit of this article. It must have taken us three or four times longer than it normally takes because we just couldn’t stop laughing. This may be the funniest article we’ve ever run. And it’s so, sadly, so true for us all.
Read this DominoPower article.

Lenovo has launched software to comprehensively delete data on PC hard drives, after surveys revealed a widespread failure to remove sensitive data from hard drives on PCs slated for disposal.
With the now-in-force WEEE directive, PC disposal and recycling will be more organized. A Lenovo-sponsored survey suggests that up to 30 percent of discarded PCs may contain sensitive data. An earlier BT-sponsored report reached much the same conclusion.

The notorious Mpack hacker toolkit is installing malware that carries out its chores–including spewing spam–from within the Windows kernel, making it extremely difficult for security software to detect it, Symantec said Thursday.
The Trojan horse that Symantec has dubbed "Srizbi" is being dropped onto some PCs by the multi-exploit Mpack, a ready-to-use attack application that until recently has been selling for around $1,000. Responsibility for a large-scale attack launched from thousands of hijacked Web sites last month was pinned on Mpack, as was a follow-up campaign waged from compromised Internet porn sites.