<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
					xmlns:content="http://purl.org/rss/1.0/modules/content/"
					xmlns:wfw="http://wellformedweb.org/CommentAPI/"
				  >
<channel>
<title>Security Clearance Jobs | Security Tips</title>
<link>http://www.clearancejobs.com/</link>
<item>
<title>New Malware Targets U.S. Military Personnel</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Thu, 26 Aug 2010 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[The TrendLabs Malware Blog reported that a malware variant created with the well-known ZeuS toolkit seems to be targeting members of the U.S. military serving overseas. Targets of this scam will receive an email regarding their Bank of America Military Bank Account.  If the recipient clicks the link, they will be brought to a fake login page that is almost identical to the real login page of the bank. 
<Br><Br>
This is not the first time that the users of the Military Bank have been targete...]]></description>
</item>
<item>
<title>Cybersecurity Worries</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 23 Aug 2010 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[An <a href="http://fcw.com/articles/2010/08/17/top-cybersecurity-threats.aspx">article</a> in FCW examined six reasons to worry about cybersecurity.  Professional criminals and spies are more frequently using low-profile, selective attacks that rely heavily on social engineering. In June, an average of one in 276 e-mails, less than half a percent, was found to contain malicious code. But for government, the figure was one in 124 e-mails. That still is less than 1 percent, but the danger is in...]]></description>
</item>
<item>
<title>Dealing with identity theft in official duties</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Thu, 29 Jul 2010 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[An <a href="http://www.edwards.af.mil/news/story.asp?id=123198886">article</a> posted on <a href="http://www.edwards.af.mil/">Edwards Air Force Base</a> site appeared back in April highlighting the threat of identity theft, addressing those in uniform performing official duties. The article provides ways you can better protect not only your own vital information, but your colleagues as well:
<Br><Br>
When posting other information to a share drive or information sharing network ensure:
<ul...]]></description>
</item>
<item>
<title>Phishing Alert (military-targeted)</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Wed, 16 Jun 2010 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
An email floating around the web.  Looks legit (the phishers pulled most of the text off a legitimate site), until you see the zip files they want you to download.  Be aware.  <b>Do NOT enter any (url) addresses below!  This is a phishing scam!</b>

<Br><br><Br><i>
"From: rss@stratcom.mil <rss@stratcom.mil><Br>
To: <Br>
Sent: Wed Jun 16 13:10:08 2010<Br>
Subject: From STRATCOM to 
<br><Br>
, 
<br><Br>
United States Strategic Command
<br><Br>
Commanders Reading List
<br><Br>...]]></description>
</item>
<item>
<title>Spear Phishing Scam at AFB (no worries, it was just a test)</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Wed, 05 May 2010 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
An article in <a href="http://www.strategypage.com/htmw/htmurph/articles/20100504.aspx">Strategy Page</a> highlights the continued struggle to defend against phishing scams by holding exercises as part of routine readiness training. 
<br><br>
An offer to American airmen stationed at Anderson Air Force Base in Guam to be an extra in the Transformers 3 movie, turned out to be part of the Operational Readiness Exercise, a planned phishing scam used to bait airmen into releasing their con...]]></description>
</item>
<item>
<title>OPSEC and Social Networking Sites</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Fri, 23 Apr 2010 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>The Interagency OPSEC Support Staff (IOSS) acts as a consultant to other U.S government departments or agencies by providing technical guidance and assistance that will result in self-sufficient OPSEC programs for the protection of the U.S. operations.  IOSS is part of The National Operations Security Program, which was established to identify, control, and protect unclassified information and evidence associated with U.S. national security programs and activities. 
<br><br>
OPSEC relea...]]></description>
</item>
<item>
<title>Employment Scams Index</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 05 Apr 2010 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
A great website to help identify and report email scam is Scamdex.  It is a huge archive of email scams.  The site also has a range of resources, links and information aimed at informing and educating the Internet-using public about the dangers of and avoidance of scammers. 
<br><Br>
More importantly, it has an Employment Scams section devoted to job scams.
<br><Br>
Go to <a href="http://www.scamdex.com/employment-index.php">Employment Scams Index</a> or <a href="http://www.scamdex....]]></description>
</item>
<item>
<title>Most Commonly Used Passwords</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 22 Mar 2010 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
Back in January, <a href="http://www.imperva.com/news/press/2010/01_21_Imperva_Releases_Detailed_Analysis_of_32_Million_Passwords.html">Imperva</a>, a data security firm, analyzed 32 million passwords that were exposed from a data breach.  Unfortunately, these were the most commonly used passwords: 
<br><br>
1.	123456 <br>
2.	12345 <br>
3.	123456789 <br>
4.	Password <br>
5.	iloveyou <br>
<br>
Nearly 50% of users used names, slang words, dictionary words or trivial passwords (con...]]></description>
</item>
<item>
<title>The Phishing Flow Chart</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 01 Mar 2010 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>
Here is a handy <a href="http://loginhelper.com/wp-content/uploads/phishing_flow_chart1.jpg">phishing flow chart</a> that basically walks a user through the analysis of an email. It begins by identifying the sender and then checking consecutively if the email contains links or attachments and if it requests personal information.
<br><Br>
Flowcharts are great because they illustrate step-by-step decision paths easy to understand and follow. It's also very handy to show family or friend...]]></description>
</item>
<item>
<title>Spear Phishers Target Military Members at Home and Work</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Thu, 18 Feb 2010 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>
<em><strong>Phishing</strong></em> attempts to fraudulently acquire sensitive information, such as  passwords, personal information, military operations and financial  details by masquerading in an e-mail as a trustworthy person or  business.  Phishing is normally used for the purpose of identity theft. 
<br><Br>
<em><strong>Spear phishing</strong></em> will often use the victim's name, organization, spoof who the e-mail is  from, and  even relevant jargon to further make them think t...]]></description>
</item>
<item>
<title>Need to Improve your Employees Cybersecurity Training?</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Tue, 02 Feb 2010 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<Br>A recent survey by CDW Government reported that four out of five federal IT managers said they provide ongoing classes on security policies and procedures, however almost half had seen employees post passwords in public places.
<br><Br>
<b>Tips for cybersecurity-training your employees</b>
<ul>
<li>Make employee testing simple and routine<br><i> (part of their orientation, and the security tip of the day)</i>
<br>
<li>Check what they do, not just what they know <br><i>(use internal...]]></description>
</item>
<item>
<title>Chinese Attacks Target U.S. Military Contractors via Malicious PDF Attachments</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Wed, 20 Jan 2010 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<Br>
Security vendor F-Secure says targeted cyberattacks apparently originating in China are now targeting some U.S. defense contractors using malicious PDF files e-mailed to U.S. defense contractors last. The PDF file was designed to look like an official Department of Defense document. (<a href="http://www.f-secure.com/weblog/archives/airforce.png">See screenshot of malicious PDF</a>).
<Br><Br>
Opening the PDF document using Adobe Reader allows hackers to exploit a previously disclosed v...]]></description>
</item>
<item>
<title>Security Awareness Tips</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 14 Dec 2009 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>SANS Institute has a great section called "<a href="http://www.sans.org/tip_of_the_day.php?utm_source=offsite&utm_medium=misc&utm_content=Offsite_Link_twitter&utm_campaign=Tip_of_the_Day&ref=39148">Security Awareness Tip of the Day</a>". Some of the cybersecurity tips include:
<Br><br>
<b>Beware of USB Flash Drive</b>
A white hat hacker broke into a bank and left 20 USB tokens lying around the parking lot of the bank for employees to find. When they plugged in the USB token, the Trojan...]]></description>
</item>
<item>
<title>IRS Took Down 3,030 Fraudulent Websites in 2008</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 26 Oct 2009 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
A sharp (270%) increase by criminals to draw unassuming taxpayers to fake tax agency websites to steal identities and money was reported in a Government Accountability Office (GAO) audit <a href="http://www.gao.gov/new.items/d09882.pdf">released</a> this month. 
<br><Br>
To address online threats to its sites and taxpayers, the IRS in 2007 created the <a href="http://www.irs.gov/privacy/article/0,,id=186436,00.html">Online Fraud Detection and Prevention (OFDP) Office</a> to reduce onl...]]></description>
</item>
<item>
<title>Guard Your Job Search</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 24 Aug 2009 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
With unemployment rising, more people are looking for jobs. Criminals are setting increasingly sophisticated traps to prey on the desperation of the jobless, whose guards are down amid eroding savings, swelling debts and possibly foreclosure and bankruptcy.
<br><br>
Even the Federal Trade Commission has been cracking down on job scams.  Last July, the FTC announced that it brought eight new cases against companies that have conned consumers who are struggling to make a living and pay...]]></description>
</item>
<item>
<title>Government IT Security </title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Fri, 24 Jul 2009 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>A group of U.S. government security organizations has listed the <a href="http://www.sans.org/cag/">top  20 security actions</a> that they recommend organizations should take to  improve computer security. The list was published by a group of U.S. government agencies, including the NSA,  US-CERT, and other U.S. DoD computer security groups.  In addition, U.S. security organizations in conjunction with Sans Institute published a list of <a href="http://www.sans.org/top25errors//?cat=top25"...]]></description>
</item>
<item>
<title>Targeting U.S. Technologies: Reports from Defense Industry</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 29 Jun 2009 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
Back in January the Defense Security Service (DSS) released their 2008 "Targeting U.S. Technologies: A Trend Analysis of Reporting from Defense Industry" report.
This report is based on an analysis of Suspicious Contact Reports received from defense industry and identifies the most frequently targeted U.S. technologies, reflects the most common collection methods utilized, identifies entities attempting the collection, and identifies the regions where these collection efforts originate...]]></description>
</item>
<item>
<title>Strong Password vs. Weak Password</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Tue, 16 Jun 2009 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
A <b>strong password</b> consists of random letters and numbers set out in a way that no one can run a program using your personal information to figure it out. 
<br><Br>
A <B>weak password</b> consists of dictionary words, places, or names - frontwards or backwards, in ANY LANGUAGE (includes the names of spouses, friends, children, pets, etc.), the same as above using the first letter capitalized or with a digit at the beginning and/or end, a pure number less than a million, your log...]]></description>
</item>
<item>
<title>Identity Thief: Trends and Issues</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 08 Jun 2009 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>A recent report, <a href="http://www.fas.org/sgp/crs/misc/R40599.pdf">Identity Thief: Trends and Issues</a>, by the Congressional Research Service, examines the fastest growing type of fraud in the US - identity fraud; in 2008 about 9.9 million Americans were reportedly victims of identity theft, an increase of 22% from the number of cases in 2007. Since the FTC began recording consumer complaint data in 2000, identity theft has remained the most common consumer fraud complaint.
<br><Br>...]]></description>
</item>
<item>
<title>Credit Repair or Scam?</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 11 May 2009 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>Worried about being denied a security clearance because of bad credit?  Considering a credit repair company to fix your credit report? 
<br><br>
In an <i>AARP Bulletin Today</i> Scam Alert article, "<a href="http://bulletin.aarp.org/yourmoney/scamalert/articles/credit_repair_s_dirty_business_.html">Credit Repair's Dirty Business</a>," Steven Baker of the Federal Trade Commission (FTC) was quoted as saying, "In the last year, we've seen an increase of 50 percent in reports of credit repa...]]></description>
</item>
<item>
<title>Spoofing Alert - ClearanceJobs.com</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 30 Mar 2009 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
It appears spammers are falsely using the ClearanceJobs.com name and text from our homepage in spam emails going around the internet. These emails are made to appear as if they are coming from us, when in fact they are not. This is a common spam practice called spoofing, which is unfortunately common on the internet.
<br><br>
If you receive an email asking you to download a file, do not do so. Legitimate emails from ClearanceJobs.com follow a standard format, contain standard informat...]]></description>
</item>
<item>
<title>Who's on the other end?</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Thu, 26 Mar 2009 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
What's in a name, or an accent for that matter? As a job seeker, you are naturally likely to get calls from recruiting, staffing, and human resource professionals inquiring about your availability for certain careers. In today's global melting pot, some of the people you talk to may have accents and/or non-Western names. What to do? 
<Br><Br>
Don't forget, on ClearanceJobs.com we manually pre-screen companies requesting access to our resume database. Companies must be US-based, and al...]]></description>
</item>
<item>
<title>iPods and Data Breaches</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Sun, 22 Feb 2009 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<Br>
Last month, it was <a href=http://www.nextgov.com/nextgov/ng_20090127_1412.php>reported</a> that a New Zealand man purchased a used iPod containing personal information of U.S. soldiers, which included names, addresses, phone, and Social Security numbers as well as what appeared to be a mission briefing and lists of equipment deployed in Iraq and Afghanistan.
<br><Br>
This isn't the first time the DoD has had difficulty in protecting private information on removable storage devices (S...]]></description>
</item>
<item>
<title>FAA says Info on Workers Stolen in Data Breach</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Sun, 15 Feb 2009 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>
FAA is working to stem concerns regarding the agency's disclosure that a hacker was able to access Social Security numbers and other personal information of 45,000 agency employees and retirees that were stolen from a server at the agency.
<br><Br>
The compromise resulted from an intrusion into the system that was storing the data, the FAA said in a brief statement. There are no indications that any of the servers used for air traffic control or other operation systems were similarly...]]></description>
</item>
<item>
<title>Cybersecurity Contractor Warns of Virus on Own Network</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Wed, 04 Feb 2009 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>
SRA International, a government contractor that provides cybersecurity and privacy services, has warned its employees their <a href="http://fcw.com/articles/2009/02/04/sra-faces-possible-data-breach.aspx">personal information may have been stolen</a> after hackers planted a virus on its computer network.
<br><br>
The malware was installed on the same network that stored employees' personal data including names, addresses, dates of birth, health information and social security numbers....]]></description>
</item>
<item>
<title>Security Trends to Watch in 2009</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 26 Jan 2009 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>
<b>Economic Crisis:</b> The global economic crisis will be the basis of many new attacks. This will include phishing attacks (e.g. whose fictitious premise might surround the closing of a given bank). Similarly, attacks may also exploit other types of fraudulent activity such as around economic issues including e-mails that promise the ability to easily get a mortgage or refinance. Expect to see an increase in scams that prey on people who have had homes foreclosed, an increase in work...]]></description>
</item>
<item>
<title>Monster.com and USAJOBS Data Breach</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 26 Jan 2009 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<p>Monster.com and Monster-powered government job site USAJOBS are the victims of a large-scale data breach of job seeker information. See <a target="_blank" href="http://blogs.computerworld.com/thats_a_monster_of_a_data_breach">this article</a> for details. If you have accounts on these sites, read the article for advice on how to take precautions.</p>
<p>Best suggestion?&nbsp;Remove your resume and profile from Monster completely. Being the largest career site on the internet, Monster is&n...]]></description>
</item>
<item>
<title>Avoiding E-greeting Card Scams</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Sat, 27 Dec 2008 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>
The goal of phishing is theft of money and personal information. E-greeting cards have become a popular way to reach out to friends and family at holiday time and on special occasions. Cyber-scammers also take advantage of the growing popularity of e-cards by duping consumers into downloading malware. 
<br><br>
You can safeguard yourself, your friends, and your family against e-card scams by following the tips below. 
<br><br>
1.	<b>Don't open attachments:</b> Most legitimate e-card...]]></description>
</item>
<item>
<title>A Good Reminder Regarding Online Job Search Scams </title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 22 Dec 2008 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>
As the number of people conducting online job searches, the Consumer Protection Board warned consumers to be very suspicious of e-mail job offers looking legitimate but containing multiple grammatical and spelling errors, asking for personal information such as Social Security numbers or bank account information and requiring upfront processing fees for things like background checks as these can lead to identity theft. 
<br><br>
Particularly troubling for job hunters is a "Phishing sc...]]></description>
</item>
<item>
<title>Virus Prompts Pentagon to Ban External Flash Drives</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 24 Nov 2008 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>
A new malware outbreak is being spread via USB keys. The US Computer Emergency Response Team (<a href="http://www.us-cert.gov/">US-Cert</a>) is warning users and administrators to be on the lookout following a rise in incidents. USB drive attacks are on the rise again...
<br><br>
The Defense Department has banned the use of removable flash media and storage devices from all government computers, at least temporarily, according to messages that were sent to department employees informi...]]></description>
</item>
<item>
<title>Thick Accent Got You Wondering?</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Tue, 18 Nov 2008 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>
In the great melting pot that is our America, there are many people whose speech is accented and don't sound like "typical" Americans. As a security clearance holder, you have every right to be cautious about who you talk to regarding your credentials. If you get a phone call from a recruiter or HR representative and they have a non-U.S. accent, you should openly ask them if they are a U.S. citizen and not feel apprehensive about the line of questioning. As you will find, many people yo...]]></description>
</item>
<item>
<title>New CareerBuilder Email Going Around</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Thu, 13 Nov 2008 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<Br>
A new phishing scam email is going around, this time targeted to look like it came from CareerBuilder.com. Using the CareerBuilder logo and colors, this is a phishing email that is more dangerous than others as it looks fairly authentic. Text is as follows:
<br><br>
Dear job seekers! <br>
Apply for the job. We recommend this position.<br><br>

JobDescription<br><br>

We are looking for people who can control the payment of our customers from your state / region. The responsibilit...]]></description>
</item>
<item>
<title>Job Commander Phishing Email</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Fri, 31 Oct 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
Similar to recent phishing emails purported to be from CareerBuilder.com, eBay.com, and Monster.com, there are emails floating around the internet claiming to be from ClearanceJobs.com. The emails have the words "job commander" in them, along with a URL weblink to an .exe file.<br><br>
Phishing is the practice of luring unsuspecting Internet users to a fake Web site by using an authentic-looking e-mail in an attempt to steal passwords, account information or other sensitive data.
<br>...]]></description>
</item>
<item>
<title>Debunking Some Common Myths</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 27 Oct 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
The United States Computer Emergency Readiness Team (US-CERT) presents some common myths that may influence your online security practices. Knowing the truth will allow you to make better decisions about how to protect yourself.
<br><br>
<b>What are some common myths, and what is the truth behind them?</b>
<br><br>
   * <i> Myth: Anti-virus software and firewalls are 100% effective.</i><br>
      <b>Truth</b>: Anti-virus software and firewalls are important elements to protecting y...]]></description>
</item>
<item>
<title>Tip to Spot Email Scams</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 06 Oct 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
Like everything else in this world...Google it!  For example, I got this job offer (copy below) in my inbox.  Try Googling a sentence from the letter.
<br><Br>
I tried Googling the first sentence <a href=http://www.google.com/search?hl=en&client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&hs=9AD&q=Our+company+is+looking+for+permanent+representatives+within+the+territory+of+the+Canada%2FAmerica+and+Europe.&btnG=Search>Our company is looking for permanent representatives within the ter...]]></description>
</item>
<item>
<title>What is a Good Password/Reminder?</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 29 Sep 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
Should a password be long and complicated, requiring it to be written down to remember it….or should a password be easy to remember, easy enough that you don't have to write it down.  
<br><br>
Complex passwords - ones with lots of random numbers, punctuation, and letters are the best. And if you have to write it down, that's OK…because the biggest threat in defense contracting comes from the outside, especially hackers sponsored by a nation state or organized crime. The inside threat...]]></description>
</item>
<item>
<title>Data Mobility is...</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Fri, 05 Sep 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
Recent articles highlighting the danger thumb drives (i.e. flash drives, key drives, usb drives) can cause in <a href=http://techinsider.nextgov.com/2008/08/malicious_thumb_drives_in_just.php>high-secure government facilities</a> and in the <a href=http://computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=cybercrime_and_hacking&articleId=324009&taxonomyId=82&intsrc=kc_top>corporate world</a>.  The greatest benefit and threat of a thumb drive is their portability....]]></description>
</item>
<item>
<title>Spear (a.k.a. 'Smart') Phishing</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 25 Aug 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
The practice of 'spear phishing' has been known for quite some time.  However, it doesn't seem to get it's far share of attention.  We have all heard (or gotten) phishing scams using random services as bait (i.e. Paypal).  Most daily internet users can identify those pretty easily as phishing scams.  These new targeted phishing scams are far more sophisticated (i.e. relevent subject matter or offer).  Keep a look out.
<br><br>
At West Point in 2004, teacher and National Security Agenc...]]></description>
</item>
<item>
<title>Using a Soldier Story as Bait to Phish</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Fri, 22 Aug 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
As with previous email phishing scams shared on Security Tips, this one exhibits poor grammar and spelling, a free email account for contact, and to good to be true promises.  Never click any links in an emails you think are suspicious.<br>
---------------------------------------------------------------------------------------------------------------------------------------
<br>
HOW ARE YOU AND YOUR FAMILY? HOPE ALL IS WELL. MY NAME IS (SGT 1ST CLASS) GEOGE BROWN ; I AM AN AMERICAN S...]]></description>
</item>
<item>
<title>Hackers Spoof CNN &amp; MSNBC Alerts in New Malware Attack</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Fri, 15 Aug 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
A flood of e-mails pretending to be from CNN & MSNBC contain links to malicious software, security companies warned.  Emails with subject lines always start with "msnbc.com - BREAKING NEWS" then are followed with a variety of possible headlines, including: "Google launches free music downloads in China"; "Plane crashes into school, hundreds of kids killed"; "CNN.com Daily Top 10"; "Tropical Storm Edouard moving toward Texas coast"; and "Tehran says it launched nuke missile."
<br><br>...]]></description>
</item>
<item>
<title>Classic Fake Job Offer</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Tue, 12 Aug 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
Got an email today with one of the worst fake job offers we've ever seen. Don't fall for phishing scams like this. Key signs are "work from home", "a fixed salary", poor grammar and spelling, a free email account for contact, and essentially no skills required.<br><br>
Hello!
<br><br>
We offer a part time job on your computer.
<br><br>
Job Description:<br>
We will provide you with the texts for our employees with the important information and you will correct the texts as an engli...]]></description>
</item>
<item>
<title>The Top 10 Most Spammed US States</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Thu, 07 Aug 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
Interesting stuff from MessageLabs.  They recently released year-to-date spam rates for each US state. The top 10 most spammed US states are as follows:
<br><br>
1. Illinois<br>
2. South Dakota<br>
3. Oregon<br>
4. New Hampshire<br>
5. Wisconsin<br>
6. North Carolina<br>
7. Indiana<br>
8. Texas<br>
9. Pennsylvania<br>
10. Alabama<br>
<br>
MessageLabs scans three billion email connections per day and in June 2008, the global ratio of spam in email traffic from new and previo...]]></description>
</item>
<item>
<title>Defense Security Service Faulted for Jeopardizing ID Data</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Fri, 25 Jul 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
From reuters news wire...<br><br>
Personal data collected on military, civilian and contractor employees seeking federal security clearances between 1997 and 2005 could be at risk due to inaccurate record-keeping by the Pentagon agency that did the investigations, an audit showed on Thursday.
<br><br>
The Defense Security Service (DSS) was initially unable to account for 501 laptops used by its investigators and loaded with personal identity data, posing an undue risk to those people...]]></description>
</item>
<item>
<title>Tax-Related Identity Theft Skyrockets</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 14 Jul 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
A few days ago the IRS released a report by the <a href="http://www.irs.gov/advocate/index.html">National Taxpayer Advocate</a>, which concluded that <b>tax-related identity theft rose 644% from 2004 to 2007</b>.  
<br><br>
The IRS is attempting to educate taxpayers, warning them of a new wave of scam using the IRS name in identity theft (aka phishing) faxes, e-mails.  These letters will often threaten taxpayers that they will lose money or a refund if they do not respond. These types...]]></description>
</item>
<item>
<title>Red Flags To Look For When Searching For Jobs Online</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Thu, 19 Jun 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
It seems more and more are turning to the Internet as a key tool, noting that in 2007, 73% of job seekers reported using the online sources compared to 66% in 2005. While the Internet has made searching for jobs easier, it also provides an opportunity for ID thieves and scammers to take advantage of eager - and unsuspecting - job seekers.
<br><br>
Unfortunately, the search for a dream job can lead to becoming a victim of identity theft or other types of fraud. In 2007 alone, the FTC r...]]></description>
</item>
<item>
<title>Are State Laws Working Against ID Thefts?</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 09 Jun 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
Over the past five years, 43 US states have adopted data breach notification laws, but has all of this legislation actually cut down on identity theft? Not according to researchers at Carnegie Mellon University who have published a state-by-state analysis of data supplied by the US Federal Trade Commission (FTC). <br><br>
"There doesn't seem to be any evidence that the laws actually reduce identity theft," said Sasha Romanosky, a Ph.D student at Carnegie Mellon who is one of the paper'...]]></description>
</item>
<item>
<title>An Army &quot;Phishing&quot; Test Backfires</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Tue, 06 May 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<Br>
An e-mail, which had  the Army's official MWR logo, appeared to be an attempt to obtain personal information from soldiers by offering promises of free or discounted tickets to theme parks and attractions.
<br><br>
The MWR Command eventually found out that the phishers were the Army's own Network Enterprise Technology Command.
<br><br>
The phishing scam e-mail listed a Web link with an online registration form asking for a name, e-mail address, phone, city, state and ZIP code. The e...]]></description>
</item>
<item>
<title>Internet Security Threat Report - April 2008</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 28 Apr 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>
The latest <a href="http://www.symantec.com/threatreport">Internet Security Threat Report</a> was released in April 2008 by Symantec Corp. The report concludes that the Web is now the primary conduit of attack activity, as opposed to network attacks, and that online users can increasingly be infected simply by visiting everyday Web sites. 
<br><br>
In addition, attackers are leveraging a maturing underground economy to buy, sell and trade stolen information. This economy is now charac...]]></description>
</item>
<item>
<title>Don't Fall for Work at Home Scams</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 21 Apr 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>A good <a href="http://www.msnbc.msn.com/id/24132244/">article on MSNBC</a> reviews why just about all work from home jobs are actually scams. These jobs include at-home sales, packaging, mystery shopping, and other classic scams. Definitely not real jobs, these crooks are hoping to lure you into providing them with your information for identity theft and/or bank information. If it sounds too good to be true, it probably is.
<br><br>
<b>Related Resources</b>
<br>
The Better Business B...]]></description>
</item>
<item>
<title>Old Phishing Scam</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Wed, 09 Apr 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>See the email below for a new take on an old phishing scam. Again, read the content. The job is too good to be true. 100% flexible hours and a free iPhone! Don't fall for junk like this.<br><br>
Dear Sir/Madam,
<br><br>
We are happy to have your little time and paying our attention to this letter.Precious Metals incorporated company is looking forward to co-operate with you and provide you the vacancy of financial department employee in our company. We can definately say that after we...]]></description>
</item>
<item>
<title>Overseas Job Scams</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Wed, 12 Mar 2008 00:00:00 CDT</pubDate>
<guid></guid>
<description><![CDATA[<br>Finding a new job can be difficult and frustrating.  Having skills in high demand and a security clearance can make you a very attractive candidate.  Those same attributes can also make you a target for overseas job scams.  
<br><br>
When surfing the internet looking for your dream job overseas, beware of job firms listing sky-high salaries and a toll free number for you to call for more information.  
<br><br>
Conduct research on the company at the <a href="http://www.bbb.org/reports...]]></description>
</item>
<item>
<title>Are You A Human? CAPTCHA Will Know…</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 25 Feb 2008 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>The internet has developed to the point where software can automatically fill/submit web forms, create email accounts, and apply for jobs online.  Many sites, including ClearanceJobs.com, are now using a method called CAPTCHA to block these automated submissions.  If you are not logged into ClearanceJobs.com, you will see a CAPTCHA (see image below) that needs to be completed before you can submit a job application.  
<br><br>
<b>Remember:</b>  To avoid this CAPTCHA, either <a href="htt...]]></description>
</item>
<item>
<title>Spoofing Alert - ClearanceJobs.com</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Tue, 12 Feb 2008 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>It appears that someone is spoofing ClearanceJobs.com in a spam email. The email has a link to a file on the LatPro.com job board, which is a real job board. DO NOT click, run, or download the file. We are contacting LatPro.com to tell them that someone has managed to add a malicious file to their service. <br><b>ClearanceJobs.com is in no way affiliated or related to LatPro.com.</b> <br>Thanks]]></description>
</item>
<item>
<title>CareerBuilder Phishing Scam Making Rounds on Internet</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Thu, 31 Jan 2008 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>Emails are circulating around the internet claiming to be from CareerBuilder.com. While CareerBuilder isn't affiliated with our site in any way, we thought we'd warn people to not fall for this email.
<br><br>
The scam email is as follows:
<br><br>
<i>Dear employer
<br><br>
Due to a recent security breach in the Careerbuilder computer system, a new set of terms and conditions has been issued. In order to guarantee the security of your Careerbuilder account , we need you to login ove...]]></description>
</item>
<item>
<title>Laughable Spam Email</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Fri, 25 Jan 2008 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>Here's another piece of spam, this time poorly disguised as a job offer:<br>
<blockquote><i>
Hello, I am Tanya
I am manager of Russian reseller company: "Nix inc".
htt://nix.ru/
Our company need US and Ca partners for dropshipping.<br>
We buy staff in the USA and resell it to our clients in Eastern Europe (including Russia).<br>
If you are interested in cooperation we offer the following conditions:<br>
You recieve a package<br>
Then we send you pre-paid shipping label (we have o...]]></description>
</item>
<item>
<title>Should I Provide Clearance Details?</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Wed, 23 Jan 2008 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>There's some debate as to whether a job seeker should provide clearance details on their resume. As a rule, the government suggests that you NOT make your clearance details known in a public forum. ClearanceJobs.com is not a public forum. <br><br>

Our service has restricted access - only authorized government contractors and legitimate search firms are allowed access to your resume. We manually pre-screen each employer requesting access. All employers gaining access to ClearanceJobs.co...]]></description>
</item>
<item>
<title>More Junk Email</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Wed, 19 Dec 2007 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>Here is an example of a phishing scam spam seen recently. The goal of the email is to entice potential job applicants to contact the fake company. During a fake interview, the candidate would be asked for various personal items like Social Security Number, bank account information for "direct payment of salary", etc.<br><br>
<blockquote><i>
TRX Group International Ltd.<br>
95 Wilton Road, London, SW1V 1BZ, United Kingdom<br>
International head office phone: +4407092897500<br>
US and...]]></description>
</item>
<item>
<title>Example of Fake Job Offer</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Fri, 30 Nov 2007 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>We wanted to post an example of a fake job offer here to give you ideas on what to look for. This is an actual email we received.

<blockquote><i>

Unique career opportunity to reward your skills and talents

Good afternoon,
<p>
My name is Jane Eshkova, and I'm a senior HR manager for Compass Group Corp. At the moment, our company has an open position for Remote Manager in the Department of Small Investment Projects. We have considered your application, and we believe that you are...]]></description>
</item>
<item>
<title>Validating Email Job Inquiries</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Tue, 27 Nov 2007 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>With all of the spam on the net, it can be difficult to weed though fake job offers and scams to find the legitimate inquiries. Here are some tips:

<UL>

<li>Fake job offers often originate from overseas. These emails contain broken English, unrealistic salaries, and almost always ask you to respond to a free, public email account like Yahoo, Gmail, AOL, or Hotmail.

<li>Fake job offers often ask for unnecessary personal data like contact information, social security number, phone...]]></description>
</item>
<item>
<title>Online Security Tips</title>
<link>http://www.clearancejobs.com/security_tips.php</link>
<pubDate>Mon, 19 Nov 2007 00:00:00 CST</pubDate>
<guid></guid>
<description><![CDATA[<br>Online data security is always important to ClearanceJobs. We would like to take a minute to remind you of some important tips:
<br />
<ul>
<li>Keep your machine up to date with the latest security patches.
<li>Create a separate email specifically for job hunting, separate from your personal email account.
<li>Make sure you have an up-to-date anti-virus product installed and running on your machine.
<li>Avoid using a Social Security number on your resume.
<li>Don't provide any non-...]]></description>
</item>
</channel>
</rss>