Vendor
VMware Presentation to AZSPF posted!
Submitted by tintagel on Tue, 2008-09-02 12:19. Meetings | SPF | VendorA copy of the August 25th presentation from VMware has been posted to the Meeting Event Announcement at http://www.azspf.org/node/170.
Security Practitioners' Forum (August 25, 2008) [VMware]
Submitted by tintagel on Mon, 2008-08-25 18:30. Events | Meetings | Software | SPF | VendorThe monthly meeting of the Security Practitioners' Forum (Security Users' Group)
- **Special Note**
- Be sure to check out the special event ISSA Security Forum that preceeds our regularly scheduled meeting. The event is free to attend for AZSPF mambers and guests, just be sure to pre-register.
- Topic: VMware
- VMware & Security
- Presenter: Rob Randell
Virtualization is becoming a very hot topic in IT industry and in datacenters around the world. Along with the popularity comes the inevitable security concerns associated with any new technology. Virtualization is no exception to that rule. In this presentation, Rob Randell, Senior Security Specialist at VMware will talk about the security implications of virtualization. Included in this talk will be a general virtualization overview covering the different types of virtualization in the market today focusing mostly on the most recognized form, being hardware virtualization. Also covered will be the security concepts introduced by virtualization, security advantages of virtualization, and common concerns and misconceptions will also be covered.
About the Speaker:
Rob Randell. CISSP is a Senior Security Specialist at VMware where he is responsible for working with customers to help them understand the security stance of VMware and its platforms . Rob has over 14 years of experience in the IT world and over 10 years in the Security industry. Rob came to VMware as part of the acquisition of Determina, which provided software to provide true zero day protection of the most critical memory based vulnerabilities. Prior to Determina Rob was a Senior SE at Webroot software and Vericept Corporation in which he was responsible for building the SE team. Rob spent over six years prior to these positions on the operations side of the house managing and securing datacenters in the telecom industry.
ISSA Security Forum - Future of Web App Hacking (August 25, 2008)
Submitted by tintagel on Mon, 2008-08-25 16:30. Events | Meetings | Other Users' Group | VendorISSA Phoenix Special Security Forum
The Future of Mass Hacking Campaigns Against Web Applications & Databases
- What:
- This is a special ISSA Security Forum event and is *FREE* to members and guests, but you MUST register (see below).
QuietMove Web Application Security Training (December 3 - 7, 2007)
Submitted by tintagel on Wed, 2007-11-14 00:39. Risk Analysis | Software | Training | Vendor | VulnerabilitiesDec. 3-7 in San Diego
3 Tracks of Web Application Security Training
QuietMove in cooperation with Business Partners Solutions will be conducting web application security training the week of Dec 3-7.
Learning about the threats, countermeasures, and immediately applicable development strategies which can be used to integrate security into your Software Development Life Cycle (SDLC) is a proven risk reduction strategy.
All classes qualify as OWASP Top Ten Training, per v1.0 and v1.1 of the PCI Data Security Standard (PCI DSS).
Microsoft Acquires Winternals and Sysinternals
Submitted by tintagel on Wed, 2006-07-19 16:01. Research | Software | VendorMicrosoft have acquired the famed Winternals and Sysinternal started by Mark Russinovich and Bryce Cogswell.
Now might be a good time to ensure that you have the latest edition of their invaluable tools.
First seen on Slashdot
WMF Redux: New IE 0-Day actively exploited, 3rd party patches issued.
Submitted by tintagel on Tue, 2006-03-28 12:26. Exploits | Patch Management | Software | Vendor | VulnerabilitiesSecurityFocus have an article discussing the latest round of unpatched vulnerabilities. The difference between this and WMF? Hundreds of malicious websites are actively exploiting this one.
Rise in PIN based debit transaction fraud
Submitted by tintagel on Sun, 2006-03-12 01:33. Exploits | Financial Services | Hardware | Retail | Software | Vendor | VulnerabilitiesWhat started out as a small story on a blog is unraveling rapidly and may be a leading indicator of an overhaul of the PIN based ATM/POS network. The term Class Break has been kicked around, but it looks like it is 'just' a severe data breach at a dumb merchant. The NY Times and MSNBC coverage is strongest. Bruce Schneier's blog is always an interesting read.


