<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>    
    <title>Fortinet Blog | News and Threat Research - All Posts</title>
    <link>http://blog.fortinet.com//feed/index.xml</link>
    <language>en</language>
    <copyright>Copyright 2013 Fortinet Inc. All Rights Reserved</copyright>
    <pubDate>Tue, 14 May 2013 08:18:23 -0700</pubDate>
    <atom:link href="http://blog.fortinet.com//feed/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
    <title>Cutting Wires, Costs: A Look at Creating Wireless Efficiencies</title>
    <description>Wireless network infrastructure - for anyone in business, it&amp;#8217;s a necessary evil and, perhaps ironically, one that isn&amp;#8217;t short on infrastructure.

You need a controller and wireless routers or access points - lots of them &amp;#8211; enabling wireless networks to join an existing wired network. You&amp;#8217;ll have to invest in a site planner/survey tool, or risk incorrectly guessing where the APs should go.

Users need to learn the new WLAN management system, integrate it into the server...</description>
    <pubDate>Tue, 14 May 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Cutting-Wires--Costs--A-Look-at-Creating-Wireless-Efficiencies</link>
    <guid>http://blog.fortinet.com/Cutting-Wires--Costs--A-Look-at-Creating-Wireless-Efficiencies</guid>
    </item>

    <item>
    <title>App Security Wins Move at Snail's Pace</title>
    <description>Of 200 enterprise security professionals recently surveyed by Enterprise Strategy Group, 79 percent report Web application security attacks in the past year. In a late April Network World blog on the topic, Jon Oltsik, a principal analyst at ESG, said the study also found thieves attacked Web application features and functions such as application authentication, configuration management, application authorization and session management.

Oltsik says the good news is that there&amp;#8217;s more em...</description>
    <pubDate>Tue, 14 May 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/App-Security-Wins-Move-at-Snail---s-Pace</link>
    <guid>http://blog.fortinet.com/App-Security-Wins-Move-at-Snail---s-Pace</guid>
    </item>

    <item>
    <title>Patch Tuesday On the Way!</title>
    <description>Another Patch Tuesday is upon us, and both Microsoft and Adobe have important patches that you should implement right away if you&amp;#8217;re impacted.

Adobe&amp;#8217;s big patch fixes a ColdFusion exploit that allows an attacker to access files located on a server with ColdFusion installed. There should also be a fix to Adobe Acrobat Reader.

You can read Adobe&amp;#8217;s security advisory here.

On the Microsoft side, we should see at least 10 patches that cover over 30 vulnerabilities which impact...</description>
    <pubDate>Mon, 13 May 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Patch-Tuesday-On-the-Way-</link>
    <guid>http://blog.fortinet.com/Patch-Tuesday-On-the-Way-</guid>
    </item>

    <item>
    <title>1,000 malicious Android samples per day</title>
    <description>&amp;#8220;Is mobile malware really an issue?&amp;#8221; is probably among the most frequent questions my friends ask me regarding my work. I usually like to answer indirectly with a graph as below: 



Figure 1. Evolution of malicious Android samples. Light blue curve is the number of known Android samples in our databases. Dark blue line is the average number of new Android samples we received per day.

Yes, we currently have over 150,000 Android samples, and they currently come in at a rate of 1,0...</description>
    <pubDate>Mon, 13 May 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/1-000-malicious-Android-samples-per-day</link>
    <guid>http://blog.fortinet.com/1-000-malicious-Android-samples-per-day</guid>
    </item>

    <item>
    <title>Microsoft Releases IE8 Fix-It Patch</title>
    <description>Are you using Internet Explorer 8? If so, you need to read on.

A recent zero-day exploit being actively used in the wild and was likely the cause of a watering-hole attack that was launched from the US Department of Labor.

To help IE8 users mitigate any further exposure to attacks from this flaw, Microsoft released a quick fix solution to address the exploit.

Microsoft is still working on a complete fix for the exploit. In the interim, if you&amp;#8217;re using IE8, click here to head to Micro...</description>
    <pubDate>Thu, 09 May 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Microsoft-Releases-IE8-Fix-It-Patch</link>
    <guid>http://blog.fortinet.com/Microsoft-Releases-IE8-Fix-It-Patch</guid>
    </item>

    <item>
    <title>Finding Similarities and Differences at DEX Level</title>
    <description>Some time ago, I analyzed two similar samples of Android/Smsilence.A!tr.spy, a fake Vertu application that spies on its victim. One of the samples was targeting a Japanese audience, while the other sample was for Korean end-users. I was interested in finding their similarities (and differences).  At (decompiled) source code level, I identified for instance a similarity: both samples check incoming SMS messages and download another payload if the message body contains the keyword 113, or delet...</description>
    <pubDate>Mon, 06 May 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Finding-Similarities-and-Differences-at-DEX-Level</link>
    <guid>http://blog.fortinet.com/Finding-Similarities-and-Differences-at-DEX-Level</guid>
    </item>

    <item>
    <title>Network World's Security Threat Landscape - May 2013</title>
    <description>In this monthly video series focusing on the latest digital security threats, Keith Shaw and Fortinet&amp;#8217;s Derek Manky discuss the recent Twitter hack on the Associated Press, the Spamhaus arrests and DNS amplification, and the latest Android hacks.
   </description>
    <pubDate>Thu, 02 May 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Network-World---s-Security-Threat-Landscape-----May-2013</link>
    <guid>http://blog.fortinet.com/Network-World---s-Security-Threat-Landscape-----May-2013</guid>
    </item>

    <item>
    <title>M2M Attracts Enterprises, Risks and All</title>
    <description>Machine-to-machine (M2M) communications applications are working their way beyond traditional utility, traffic control and telemedicine industries, as enterprises search for ways it can benefit their businesses despite some real risks.

ZDNet&amp;#8217;s Tim Lohman recently penned an article about how the automated communication of data between connected devices, M2M, is envisioned more and more by CIOs as delivering real value, cost savings and innovation in management.

Lohman says now that net...</description>
    <pubDate>Fri, 26 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/M2M-Attracts-Enterprises--Risks-and-All-</link>
    <guid>http://blog.fortinet.com/M2M-Attracts-Enterprises--Risks-and-All-</guid>
    </item>

    <item>
    <title>IDC BYOD Survey Shows Mobile Malware is the Top Concern</title>
    <description>Just a few years ago, the bring-your-own-device (BYOD) to work trend was just starting to give IT administrators cause for concern.

Flash forward to today: BYOD has not only reached a tipping point, but is accelerating at a dizzying pace. With this momentum comes elevated fears and a torrent of threats, proven by the latest BYOD and mobility figures from research firm IDC in its Mobile Security Survey 2013. None of these statistics should come as a surprise.

Mobile malware is a top concern ...</description>
    <pubDate>Fri, 26 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/IDC-BYOD-Survey-Shows-Mobile-Malware-is-the-Top-Concern-</link>
    <guid>http://blog.fortinet.com/IDC-BYOD-Survey-Shows-Mobile-Malware-is-the-Top-Concern-</guid>
    </item>

    <item>
    <title>Cyberattack Tracker Zeroes in on Firewall Vulnerabilities</title>
    <description>Deutsche Telekom&amp;#8217;s interactive, real-time map of global cyberattacks reveals the bulk of recent attacks &amp;#8211; 27.3 million in February alone &amp;#8211; were against the Server Message Block (SMB), aka the Common Internet File System (CIFS).

Reuven Harrison, CTO and co-founder of Tufin, a security and lifecycle management company and Fortinet solution partner, wrote in a blog that the map&amp;#8217;s revelations are significant. This attack vector, he explains, operates across an application...</description>
    <pubDate>Wed, 24 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Cyberattack-Tracker-Zeroes-in-on-Firewall-Vulnerabilities</link>
    <guid>http://blog.fortinet.com/Cyberattack-Tracker-Zeroes-in-on-Firewall-Vulnerabilities</guid>
    </item>

    <item>
    <title>Secure malware??</title>
    <description>Over the past two weeks, we&amp;#8217;ve seen a big influx of Android malware samples coming our way from Korea.

Upon closer examination of the samples, we saw some differences between them and decided to classify them into different variants.

The first variant Android/Malapp.A!tr.spy ironically calls itself &amp;#8220;SmsProctect&amp;#8221;(misspelt) while spying on incoming SMS messages on the victim&amp;#8217;s phone.

In addition it also steals JPEG image files stored on the victim&amp;#8217;s phone.

Adde...</description>
    <pubDate>Tue, 23 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Secure-malware--</link>
    <guid>http://blog.fortinet.com/Secure-malware--</guid>
    </item>

    <item>
    <title>Access Management: Five Tips</title>
    <description>Access management is a crucial function for every organization with an Internet connectionand it&amp;#8217;s a lot harder these days. The explosion of remote workers and mobile devices has complicated and confused once-rudimentary access management functions, while the popularity of social media and other Web 2.0 sites have added a more challenging dimension to the work environment.

With this in mind, here are a few tips for access management that might ease the process.

Do Inventory Organizati...</description>
    <pubDate>Tue, 23 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Access-Management--Five-Tips</link>
    <guid>http://blog.fortinet.com/Access-Management--Five-Tips</guid>
    </item>

    <item>
    <title>Tragic Spam</title>
    <description>Whenever something awful happens in the world, both the good and the bad come to the surface: bad guys doing bad things like we saw in Boston last week, and good guys rushing to random people&amp;#8217;s aid in the wake of the explosions.  At FortiGuard, we&amp;#8217;ve seen an uptick in bad guys trying to take advantage of people&amp;#8217;s desire to find our more by tailoring spam messages that when opened, will infect your machine with malware.

Some of the spams have subjects like: &amp;#8220;2 Explosio...</description>
    <pubDate>Sun, 21 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Tragic-Spam</link>
    <guid>http://blog.fortinet.com/Tragic-Spam</guid>
    </item>

    <item>
    <title>O-TTPS and You</title>
    <description>At FortiGuard, we take our duty to protect our customers from threats, malware, zero-day exploits and other forms of cyberattacks very seriously. Our customers can sleep well knowing that 24 hours a day we are always on guard and stationed on the front lines keeping their networks safe and secure.

The new Open Trusted Technology Provider Standard (O-TTPS) will help in protecting our customers. As stated in their publication: &amp;#8220;The O-TTPS is an open standard containing a set of organizat...</description>
    <pubDate>Wed, 17 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/o-ttps-and-you</link>
    <guid>http://blog.fortinet.com/o-ttps-and-you</guid>
    </item>

    <item>
    <title>W32/Kryptik.AX!tr - A Masterful FTP Trojan</title>
    <description>A few days ago I received an interesting email message:



Just your typical phishing email. Normally, I would just dump it into our signature automation processors and move on to the next piece of malicious code. This one was intriguing, though: within hours we received a handful of other samples similar to this, and having a couple extra hours in my day, I figured I&amp;#8217;d stop and take a good look at it.

The malware arrived packed with UPX and once unpacked I discovered it had its own me...</description>
    <pubDate>Wed, 17 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/W32-Kryptik-AX-tr---A-Masterful-FTP-Trojan</link>
    <guid>http://blog.fortinet.com/W32-Kryptik-AX-tr---A-Masterful-FTP-Trojan</guid>
    </item>

    <item>
    <title>APTs: One Layer Is Not Enough</title>
    <description>One in five security professionals recently surveyed by ISACA say its organization has experienced an advanced persistent threat (APT) attack.

While the term APT is used with increasing frequency when discussing security threats, ISACA found there&amp;#8217;s still confusion as to what an APT is and how to manage the risks associated with it. The ISACA&amp;#8217;s Advanced Persistent Threat Awareness report, released in mid-February, includes input from 1,551 information security professionals repre...</description>
    <pubDate>Wed, 17 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/APTs--One-Layer-Is-Not-Enough</link>
    <guid>http://blog.fortinet.com/APTs--One-Layer-Is-Not-Enough</guid>
    </item>

    <item>
    <title>Bitcoin and the ZeroAccess Botnet</title>
    <description>Botnets for years have been leveraged as a cybercrime tool to commit any variety of nefarious activity ranging from Website defacement and DDoS to the proliferation of malware and theft of sensitive information.

Lately, the cyber community can add one more to the list mining the digital currency Bitcoin.

In the new Bitcoin heists, the botnets that take over a victim&amp;#8217;s computer aren&amp;#8217;t intended to steal a victim&amp;#8217;s money - although they are certainly capable of doing that, to...</description>
    <pubDate>Fri, 12 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Bitcoin-and-the-ZeroAccess-Botnet-</link>
    <guid>http://blog.fortinet.com/Bitcoin-and-the-ZeroAccess-Botnet-</guid>
    </item>

    <item>
    <title>Email, Privacy and You... a Look Inside SB 467</title>
    <description> For geeks like me, 1986 was a great year&amp;#8230; IBM unveiled their &amp;#34;PC Convertible laptop&amp;#34;, the &amp;#34;first MS-DOS virus, Brain,&amp;#34; was released, and the &amp;#34;Electronic Communications Privacy Act of 1986 (ECPA)&amp;#34; was enacted. And, why is this so important? Because 27 years later, laptops, computer viruses and this piece of legislation all impact just about everyone in one way or another.

But, this article is about email, privacy and you. What does the ECPA have to do with that?...</description>
    <pubDate>Thu, 11 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Email--Privacy-and-You----a-Look-Inside-SB-467</link>
    <guid>http://blog.fortinet.com/Email--Privacy-and-You----a-Look-Inside-SB-467</guid>
    </item>

    <item>
    <title>Analyst Commentary - Security Appliance Growth Continues</title>
    <description>There was a flurry of news articles out recently highlighting some interesting data points from IDC. In particular, according to IDC, worldwide factory revenue from security appliances was up 7.2% year on year to $2.3 billion, as unit shipments increased 5.2% to 538,428.

Granted, Q4 is generally the strongest quarter in the tech industry, so it should be no surprise to most to see a strong finish to the year.

&amp;#34;Fortinet saw the largest revenue growth among the top five vendors at 27.2%,&amp;...</description>
    <pubDate>Wed, 10 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/Analyst-Commentary-----Security-Appliance-Growth-Continues</link>
    <guid>http://blog.fortinet.com/Analyst-Commentary-----Security-Appliance-Growth-Continues</guid>
    </item>

    <item>
    <title>Windows XP-iration</title>
    <description>After April 08,2014, the Extended Support for Windows XP will expire and Microsoft will cease to issue any more updates or patches. It will have a significant impact on Windows XP users, particularly in terms of vulnerabilities and exploits.

If you just bought a computer recently and it came with a copy of Windows 7 or 8, you don&amp;#8217;t need to worry about Microsoft&amp;#8217;s Windows XP expiration deadline.

Systems running Windows XP after the expiration date may be exposed to malware exploi...</description>
    <pubDate>Tue, 09 Apr 2013 00:00:00 -0700</pubDate>
    <link>http://blog.fortinet.com/windows-xp-iration</link>
    <guid>http://blog.fortinet.com/windows-xp-iration</guid>
    </item>

  </channel>
</rss>