Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173


Best Of The Web

THE NEXT WEB
Google Chrome Overtakes Internet Explorer As The Web's Most Used Browser
Chrome has now surpassed Microsoft?s Internet Explorer (IE) as the most-used browser, new data from StatCounter has found

THE REGISTER
Anonymous Takes Out Indian CERT As Attacks Continue
The hacktivist collective went after the Indian government again by knocking offline its national CERT and the Indian president's website

SECURITY WEEK
Chicago Police And NATO Websites Hit By DDoS Attacks
AntiS3curityOPS targeted the Chicago Police Department for its actions against protestors, and NATO suffered a DDoS on Sunday by another Anon-related group

GOV INFOSECURITY
Who Is Michael Daniel?
The new White House cybersecurity coordinator, a former intelligence branch chief, is expected to reshape the cyberczar role with his policy, budget experience

THREAT POST
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
Northrop Grumman is hiring software engineers to help it carry out "offensive cyberspace operations," according to a recent job posting, but a company spokesperson would not elaborate on just what that job would entail

PC WORLD
Wikipedia Warns Users About Malware Injecting Ads Into Its Pages
Wikipedia says if you see advertisements on its site for for-profit organizations, you've likely been hit with a browser malware infection

NAKED SECURITY BLOG
Selena Gomez's Facebook Account Hacker Jailed For One Year
A 21-year-old British man has been sentenced to one year in prison after saying he hacked into the Facebook account of Justin Bieber's girlfriend, Selena Gomez, and accessed private messages

CSO ONLINE
IT Students Aim For The Security Services
IT students in the UKK say they would like to work for The Secret Intelligence Service (MI6), Security Service (MI5), and GCHQ (Government Communications Headquarters), as well as Apple, Google, Microsoft, IBM, and Intel

ZDNET
The Pirate Bay Returns, Anonymous Hater Takes Credit For DDoS
Anonymous traitor who goes by name of AnonNyre claims responsibility for attack

CIFAS
Staff Fraud Report Reveals Complex Set Of Dangers
U.K.'s Fraud Prevention Service reports that insider frauds are up nearly 15 percent

THREAT POST
Trojan Mimics Chrome Installer To Steal Banking Information
Malware impersonating a Google Chrome installer is actually stealing data

CYBER WAR ZONE
Saudi Arabian Hackers Attack Iranian Oil Companies
Several state-backed Iranian oil firms targeted by group from Saudi Arabia

KREBS ON SECURITY
Facebook Takes Aim At Cross-Browser 'LilyJade' Worm
Social networking worm spreads via an app built to run as a plug-in across multiple browsers and operating systems

SOPHOS
Call Of Duty Trojan Horse Creator Ends Up In Jail After Drunken College Raid
British man who spread spyware Trojan disguised as video game update gets 18 months in jail

DEFENSE NEWS
China Continues Its Focus On Cyber: Report
China continues to develop offensive cyberwarfare capabilities that could disrupt global computer network, Defense Department says

CNET
FBI 'Looking At' Law That Makes Websites Wiretap Ready, Director Says
Agency needs to be able to 'capture communications' of people under surveillance, Mueller says

THREAT POST
DHS Warns About Threat Of Mobile Devices In Healthcare
The Department of Homeland Security (DHS) issued a warning to healthcare organizations on the danger of insecure, network-attached medical devices and the use of smartphones, tablet PCs, and other mobile devices in healthcare settings

MICROSOFT TECHNET BLOG
Introducing EMET v3
Microsoft has released a new version of its freebie Enhanced Mitigation Experience Toolkit, EMET 3.0, that comes with more enterprise configuration, deployment, and reporting options

NAKED SECURITY BLOG
Global Payments Breach Continues To Bewilder, Accusations Abound
Global Payments insists the affected cards total 1.5 million, but it may be closer to 7 million as Vons supermarket have reported a large volume of prepaid credit card fraud and Union Savings Bank has seen similar scams of late

SCHNEIER ON SECURITY
Security Vulnerabilities In Airport Full-Body Scanners
The DHS Office of Inspector General has found "vulnerabilities in the screening process" at U.S. airports using full body scanners, a classified internal Department of Homeland Security report says

FORBES
Antivirus Firm: 75% Of Phone-Based Malware Now Targets Android
F-Secure found that 37 of the 49 variants of smartphone malware in the last quarter targeted the Android, up from 10 out of the 16 malware found in the same quarter last year

SECURITY WEEK
Utah's IT Boss Resigns After Massive Data Breach And Policy Failure
The executive director of the state of Utah Department of Technology Services has now resigned in the wake of the recent widespread data breach that exposed information on close to 1 million people, including children

BANK INFOSECURITY
Key Phish Phry Player Sentenced
A U.S. District Court has sentenced Nichole Michelle Merzi, a key member of an international cybercrime ring that between 2008-2009 stole thousands of dollars from U.S. bank accounts, to more than five years in prison

COMPUTERWORLD
Google Releases Chrome 19, Adds Tab Sync And Patches 20 Bugs
New Chrome 19 update fixes 20 vulnerabilities in the browser, and Google awarded $16,500 in bug bounties and rewards to independent researchers who discovered flaws in the browser

WIRED
OnStar Files Patents For Minority-Report-Style Billboards
Public advertisements could be tailored to individual drivers

THREAT POST
Stolen Certificates Found In Malware Possibly Targeting Tibetan Groups
Trend of attackers using stolen digital certificates to mask their malware continues

F-SECURE
Mobile Threat Report Q1 2012
Android Trojans continue to rule the mobile threat roost, study says

ARS TECHNICA
LulzSec Member Pleads Not Guilty To Charges He Hacked Stratfor Website
Former hacktivist group member denies hacking global intelligence company and stealing credit card details of 860,000 clients

BANK INFO SECURITY
Is Global Payment Inc.'s Breach Growing?
Sources say 7 million cards may have been exposed

WIRED
Popular Surveillance Cameras Open To Hackers, Researcher Says
Closed-circuit security cameras are often configured insecurely, leaving them open to hackers, researcher says

NETWORK WORLD
Public Vs. Private Cyberattack Responsibility Debate Heats Up
What role should government play in requiring private companies to pony up cyberwar defenses? Arguments fly on both sides

PC ADVISOR
Kaspersky Denies It's Working With Apple On Mac Security
Security firm denies report it is working on Mac OS X security

SEARCH SECURITY
May 2012 Patch Tuesday: Microsoft Fixes Duqu Trojan Ghost Code
Amid Microsoft's security updates last week was an update to repair the font-parsing code related to the Duqu Trojan

NATIONAL POST
Insider Tells Why Anonymous 'Might Well Be The Most Powerful Organization On Earth'
Christopher Doyon, a.k.a. Commander X, in Canada on the run from U.S. law enforcement, told a reporter that groups are leaking passwords and usernames of secure databases to Anonymous

INFOSEC ISLAND
Federal Charges Filed In Case Involving Theft Of Trade Secrets
Two Chinese citizens, one Chinese company, and one U.S. company are charged with theft of trade secrets, wire fraud, and conspiracy to commit wire fraud in connection with the alleged theft of intellectual property from Orbit Irrigation Products Inc., a sprinkler and irrigation company headquartered in Utah

KREBS ON SECURITY
Global Payments Breach Fueled Prepaid Card Fraud
Debit card accounts stolen in a recent breach of card processor Global Payments have been appearing in fraud incidents at retailers in Las Vegas and other cities, officials from one bank say

ZDNET BLOG
Adobe About-Face: Photoshop, Illustrator Patches Will Be Free
Adobe says it will provide free updates to paid upgrades for Photoshop and Illustrator

POLITICO
Cybersecurity Bill Hits Snag
Sen. Joe Lieberman's cybersecurity bill is under fire now from Democrats as well, who say it doesn't do enough to protect consumer privacy; many Republicans already oppose it

ARS TECHNICA
Hands-On With Five Antivirus Apps For The Mac
Even visiting favorite websites can result in infections for Macintosh users today, so there are options for antivirus -- a look at some offerings

BURLINGTON FREE PRESS
Vermont Utilities See Growing 'Smart Meter' Opposition
State of Vermont offers a free, no-penalty opt-out option to its consumers amid growing concerns about health effects, privacy, and cost of smart grid systems


Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)