More on SecuBat

Looks like there is a alpha release of SecuBat available here .
if (like me) your Austrian's not so hot, there's some more information in english here
It'll be interesting to line this up with Oedipus and see what their vulnerability finding strengths and weaknesses are...

Security flaws in OSX

Security-Protocols :: The Bug Hunters Blog - Latest on OS X research..
Post about some serious security flaws in OSX, found by a security researcher.
I must say, I'm not surprised.
There's not been a lot of focus on security of Apple products in the past, but it seems that when it comes, with the increasing popularity of the platform, there will be a decent quantity of problems.
Whilst the UNIX-like underpinnings of OSX provide certain security advantages, there's nothing that I'm aware of which makes their security inherently better, at an application-level. And if they're typical of most tech companies, they won't be paying a huge amount of attention to secure development practices, until they start getting problems with published flaws/virii/worms...

TaoSecurity's take on the latest Jericho moves

TaoSecurity
Some interesting comment on BP's new deperimeterisation moves (more information here )
I'd agree with the sentiments expressed in TaoSecurity, I agree with the Jericho Forums position that every device should be able to stand on its own from a security perspective, however the idea of deliberately weakening the security afforded to laptops by connecting them directly to the Internet when they're on the Corporate LAN seems like a very bad plan, as it reduces the numbers of layers of protection afforded to them needlessly.
Also it renders the security of the laptops very brittle, so if for example there is a problem with a change deployed to these devices which leaves them vulnerable to an attack, they won't have the safety net of being behind a corporate firewall to allow the IT team time to fix the problem before it has an impact...
I've also been thinking, how is this going to work in practice? If the laptops are on the Internet, surely they'll need to connect to Corporate IT assets, so they'll need a VPN tunnel into the company. Also surely BP will still want to take advantage of centralised web site monitoring, Email Anti-Virus etc... So all the traffic from these laptops sitting in corporate offices will go through a VPN tunnel back into the corporate LAN then potentially back out onto the internet.... Surely that's not a great plan from a cost perspective..