The right way to secure the Internet of things

Credit: VLADGRIN Stung by file-encrypting malware, researchers fight back

Jose Vildoza's 62-year-old father was using his old Windows computer when a warning in broken English flashed on the screen: your files have been encrypted.

Vildoza's father, who speaks Spanish, didn't understand the warning, which demanded payment in order to decrypt the files. When Vildoza looked at it, he knew it was bad. And he became angry. Microsoft to start blocking adware that lacks easy uninstall

Microsoft has toughened its criteria for classifying programs as adware and gave developers three months to conform with the new principles or risk having their programs blocked by the company's security products.

The most important change in Microsoft's policy is that adware programs will be blocked by default starting July 1. In the past such programs were allowed to run until users chose one of the recommended actions offered by the company's security software. You want to know who has access to what? Good luck

Credit: iStockphoto A clear-eyed guide to Mac OS X's actual security risks

Apple's Mac computers and its OS X operating system have enjoyed a reputation of being relatively secure over the years. But in fact, experts say, the Apple OS has had security issues that might have been downplayed only because the vulnerabilities were not exploited. Stop DNS-based DDoS attacks, once and for all

There's no disputing that DNS is a critical component of computer networking. However, if they fall into the wrong hands, these network tools can be abused to generate a DDoS attack -- one of the most destructive weapons on the Internet. These seemingly simple barrages have taken down big names across the Internet, and you don't want to be one of the victims. Researchers bypass protections in Microsoft's EMET anti-exploitation tool

Security researchers managed to bypass the protections offered by Microsoft's EMET (Enhanced Mitigation Experience Toolkit), a utility designed to detect and block software exploits, and concluded that the tool would not be effective against determined attackers. We shall fight on the landing grounds. We shall fight in the fields and in the streets. We shall fight in the hills. We shall never surrender," said Winston Churchill in his famous June 1940 speech in the face of Nazi attacks on England. Target credential theft highlights third-party vendor risk

Target's disclosure that credentials stolen from a vendor were used to break into its network and steal 40 million credit- and debit-card numbers highlights the fact that a company's security is only as strong as the weakest link in its supply chain. The processes and tools behind a true APT campaign

APTs are both nightmares and the stuff of legend for business leaders and security managers across the globe. In this series, CSO will examine the processes and tools used by attackers during these types of campaigns, and various mitigating factors.

[Spear phishing paves road for advanced persistent threats] Should you switch to a supersecure operating system?

A reader recently wrote me to ask how I felt about Qubes, an operating system conceptualized and co-created by Joanna Rutkowska, founder and CEO of Invisible Things Lab. Safari sandboxes Flash Player to protect OS X Mavericks

Adobe has worked with Apple to sandbox Flash Player under Safari in OS X Mavericks, restricting the ability of attackers to exploit any vulnerabilities they might find in the browser plug-in. A sandbox is a mechanism that enforces certain restrictions on how an application interacts with the underlying operating system. Microsoft admits Security Essentials offers bare-bones protection by design

A Microsoft official has gone on record stating that the company's free Security Essentials software, by design, offers mere "baseline" protection for Windows PCs and users should turn to third-party offerings for IE zero-day vulnerability exploited more widely than previously thought

A recently announced and yet-to-be-patched vulnerability that affects all versions of Microsoft Internet Explorer (IE) has been exploited in targeted attacks against organizations in Taiwan since the beginning of July, according to security researchers. How to secure your company against NSA-inspired hacking

Credit: Reuters/Jason Lee