Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11


Around The Web

COMPUTERWORLD
CalOptima Says Data On 68,000 Members May Be Compromised
Personally identifiable information on about 68,000 members of Medicaid managed care plan in Orange County, Calif., may have been exposed in the wake of several CDs going missing this month

TECH REPUBLIC
10+ Reasons To Split An Access Database
Splitting your Access database provides moreflexibility, security, efficiency, and scalability

EWEEK
Database Security Takes Proper Planning
Forrester says only 20 percent of enterprises have a database security plan today even though they have a data security plan

SEARCHSECURITY
Visa Probes Tokens, Encryption For PCI Card Data Protection
Visa is considering protecting credit card data with end-to-end encryption and the use of tokens

INFORMATIONWEEK
Heartland, After The Hacking
The massive data breach cost the company $32 million in legal fees, fines, settlements, and forensics during just the first half of the year

NEWSDAY
E-Mail Error Sends Out Students' Social Security Numbers
Suffolk Community College is offering free credit monitoring for 300 students whose last names and Social Security numbers were mistakenly listed in an attachment to an e-mail

PETE FINNIGAN'S BLOG
Oracle Security Worst Practices
Don't use built-in sample accounts for business purposes, nor make your DBA's too powerful, nor allow users to share database accounts, for instance

NET-SECURITY.ORG
Companies Make Little Headway In Securing Data
Most organizations still do not have mechanisms in place to prevent database administrators and other privileged database users from reading or tampering with sensitive information in financial, HR, or other business applications

PITTSBURGH TRIBUNE REVIEW
Highmark: Stolen Laptop Contained Doctors' Information
Personal information, including Social Security numbers or tax identification numbers of around 50,000 doctors was exposed when a laptop from a Blue Cross-Blue Shield Association worker was stolen this summer

CIO
Online Banking Fraud in U.K. Hits a New High
Online banking fraud increased 55 percent in the first six months of the year compared to the same period last year

DATABREACHES.NET
Man Who Misused Commercial Database Sentenced To Prison
A New York man was sentenced to 141 months in federal prison today for supplying Social Security numbers to members of an identity fraud ring after using a phony database account

CHANNEL INSIDER
Eight Steps to Securing Unstructured Data
Identify and classify data, prioritize security control objectives, assign clear ownership and accountability, and measure and monitor

INTERNET NEWS
Security Audits Worthwhile But Infrequent: Survey
One-third of companies queried say their internal audits "don't go far enough" to protect sensitive data and 24 percent responded that they had never undergone a formal security audit by an outside organization

MACWORLD
Personal/SOHO Database App Adds IPhoto Integration, Database Sharing
Bento 3 includes multi-user capabilities, 128 bit AES encryption. and iPhoto integration for electronic data organization

SC MAGAZINE
Records Management And Privacy: Conflict Or Convergence?
Lax controls in business processes or errors in technology systems are the primary cause loss of privacy related data

SEARCHSECURITY
University Data Breach Exposes 163,000 Women To Identity Theft
A server was hacked at the UIniversity of North Carolina at Chapel Hill, resulting in the breach of ??identities of 163,000 women enrolled in a mammography study there

NEWS.COM.AU
One In Five Australians Victim Of Credit Card Fraud, Hackers
Over 1.5 million credit cards have been stolen and 1.2 million people's bank accounts have been compromised in Australia

IT STOCK ANALYST
Oracle Releases New Version of Secure Backup Platform
Oracle has released Oracle Secure Backup 10.3, a centralized tape backup management solution, which provides virtual tape library support through server-less tape duplication

WIRED
FBI's Data-Mining System Sifts Airline, Hotel, Car-Rental Records
A data-mining system built by the FBI ??for hunting terrorists is being used in hacker and domestic criminal investigations

EWEEK
Database Security Truths: Orgs Still Struggling to Herd Info
The volume of databases and access controls companies must track for compliance reasons makes it hard for them to effectively manage them


Best Of Web Archive:
Most Recent | 1| 2| 3| 4| 5| 6| 7| 8| 9| 10| 11








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)