Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2


Around The Web

CIO INSIGHT
Cyber-Criminals Change Tactics As Network Security Improves
IBM in its X-Force security report for 2011 said security efforts have cut spam and improved vulnerability patching, but attackers are now targeting mobile devices and the cloud

THE EPOCH TIMES
US Military Gearing Up For Cyberwar
The U.S. military is working overtime to secure its networks against cyber-attacks, while also developing new systems to strike back

NATIONAL JOURNAL
OMB: Growth In Federal Cyberattacks Slows
Cyberattacks on the federal government continue to increase, but most were "phishing" attempts and reports of threats largely leveled out in the past year, according to the Office of Management and Budget

CSO AUSTRALIA
Addressing The Security Risks Of BYO Devices
Bring your own device (BYOD) is a trend that will gain visibility at an accelerating pace and is inherently tied to the cloud. As such, there are many parallels when considering the implications

THE GUARDIAN UL
China Suspected Of Facebook Attack On NATO's Supreme Allied Commander
Beijing cyberspies accused of using fake social networking accounts in bid to steal military secrets from the West

GOVERNMENT COMPUTER NEWS
FISMA Guide Updated To Reflect APT, Mobile Threats
The set of security controls that form a foundation for compliance with the Federal Information Security Management Act is being updated to reflect the latest cybersecurity threats

PC WORLD
Threat Of A Bullet In The Face Keeps Cybercrooks Cautious
Sure, more sophisticated threats are on the way, but those in cybersecurity also have new opportunities to defend threats and even enable economic growth

WALL STREET JOURNAL
Watching And Waiting
Most cyberattacks are random. But some attackers know exactly whom they want, and how to strike

THREAT POST
Ongoing Targeted Attack Campaign Going After Defense, Aerospace Industries
Researchers have identified a strain of malwarebeing used in a string of targeted attacks against defense contractors, government agencies, and other organizations by leveraging exploits against zero-day vulnerabilities

GOOGLE BLOG
Android And Security: The Bouncer Service
Google reveals a service,code-named Bouncer that provides automated scanning of the Android Market for potentially malicious software

INFOWORLD
VeriSign Hacked Several Times, Won't Reveal The Details
The company buried the fact of the 2010 incidents involving its Internet domain service in a financial filing the following year. It only came to light in February

IDG NEWS SERVICE
Kelihos Botnet, Once Crippled, Now Regaining Strength
A botnet that was crippled by Microsoft and Kaspersky Lab last September is spamming once again and experts have no recourse to stop it

WIRED
Railroad Association Says Hack Memo Was Inaccurate
A government memo saying a railway was hacked in a targeted attack was incorrect, but a spokesperson declined to elaborate, leaving the public in the dark about what exactly was right and wrong in the memo

THREAT POST
Why Stuxnet-Like Attacks Aren't Going Away
In 2010, the German researcher made headlines as one of the security experts who initially analyzed parts of the Stuxnet worm's code devoted to manipulating programmable logic controllers by Siemens-- why Stuxnet-like attacks are here to stay

WIRED
Anonymous Goes After World Governments In Wake Of Anti-SOPA Protests
Anonymous has launched unprecedented string of attacks on government and business sites around the world, as the anger of the hive that a year ago turned on Egypt?s Mubarak regime turned on governments around the world

IDG NEWS SERVICE
SpyEye Malware Borrows Zeus Trick To Mask Fraud
A powerful bank-fraud software program, SpyEye, has been seen with a feature designed to keep victims in the dark long after fraud has taken place

HOST EXPLOIT
Skimming Incidents "Slowing Slightly"
ATM attacks down a bit, according to European ATM Security Team

THE CHOSUNILBO
Chinese Hackers Access Korea's Global Hawk Purchase Plans
Top-secret plan to purchase U.S.-made reconnaissance drone compromised, report says

NEW ZEALAND HERALD
Cyber Alert After French Ministry Is Hacked
France's Finance Ministry forced to shut down systems as hackers target documents related to G20 summit

YAHOO! NEWS
European Agency Warns Of Botnet Dangers
Lack of international coordination leaves many botnets operational, ENISA report says


Best Of Web Archive:
Most Recent | 1| 2








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)