Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173


Best Of The Web

SEARCH SECURITY
How To Prevent Memory Dump Attacks
Full protection means not only securing memory at rest, but also when data is in motion

WXVT NEWS
Louisiana Man Gets 309 Years In Prison For Identity Theft Scam
Sentence is the toughest ever handed down for white-collar crime in the region

INFOSECURITY
3,000 Small Dog Electronics Customers' Credit Card Details Compromised
Hackers got in through a Web app flaw, even though company passed a PCI audit and a pen test

TREND MALWARE BLOG
Keeping An Eye On The EYEBOT And A Possible Bot War
New botnet Eyebot's spyware behaviors indicate be readying for a bot war with Zeus

KREBS ON SECURITY
'Time Bomb' May Have Destroyed 800 Norfolk City PCs
The City of Norfolk, Va., is investigating how unidentified malware destroyed data on nearly 800 of its computers citywide

PRAGUE MONITOR
Czech Experts Uncover Global Virus Network
A global network of infected computers was discovered that steals bank account, email, and password data

VIRUSLIST
Kaspersky Security Bulletin 2009
The most dangerous applications of 2009 based on security incidents were Apple QuickTime, Microsoft Office, and Adobe Flash Player, according to a new Kaspersky Lab report

SEARCHSECURITY
MAAWG Documents Spam Statistics Stalemate
MAAWG executive director says spam volume is still at about 90 percent and holding, based on SP data gathered from 500 million mailboxes and 200 billion delivered email messages

H ONLINE
Symantec Says Rootkit Causes Windows XP Blue Screen Of Death
A rootkit is causing many of the "blue screen of death" incidents that are now occurring with Windows XP, according to Symantec

BANKINFOSECURITY
ATM Fraud: Six Steps To Improving Customer Awareness
What banking customers should look out for to prevent being a victim of ATM-skimming -- including wires, jammed ATM machines, and "no tampering" signs

INFOWORLD
Facebook Hit With Class Action Lawsuit Over Privacy Changes
A class-action lawsuit has been filed in California against Facebook over changes the social networking site made to its privacy settings last November and December

ADOBE
Adobe Issues Patch For New Critical Vulnerability
Flaw could subvert domain sandbox, crash application, or enable remote control

MONSTERS & CRITICS/strong>
Massive Security Breach Suspected At Latvian Tax Office
More than 7 million documents may have been leaked from database in tax agency

FINEXTRA
Iceman Gets 13 Years For Massive Card Data Theft
California-based hacker convicted of stealing more than 2 million credit card numbers

BBC
Internet Fraud Targeted By New Team
U.K. government to invest in new cybercrime-fighting unit

THE INDEPENDENT
Arrest Warrant Issued For American Cyclist Over Data Hacking
French police allege Landis hacked information in anti-doping case

TIPPINGPOINT DV LABS BLOG
Pwn2own Contest Set For Vancouver Mar. 24
Hacking contest will pay out $100,000 in prizes

BANK INFO SECURITY
ACH Fraud: Seven Tips For Secure Transactions
Banking security experts recommend using a separate machine for financial transactions

ZSCALER RESEARCH
Google Buzz For Spammers
Social networking site could pose privacy issues for users, researchers say

BBC
New Flaws In Chip And Pin System Revealed
Cambridge University computer scientists say entire system may need a rewrite

COMPUTERWORLD UK
Simulated Hacker Attack To Test U.S. Government Response
Cyber Shockwave to involve former government officials, experts

GOVERNMENT TECHNOLOGY
Smart Grid Cybersecurity Investment Will Grow To $21B By 2015, Report Claims
Federal government initiatives will help drive utilities to update their security efforts, study says

TECH REPUBLIC
Security Breakdowns Don't Follow Rules
When evaluating threats, keep your eyes open for those who color outside the lines

THAI PR
Trend Micro Warns Users To Beware Of Cybercriminals During Valentine's Day
Volume of phishing, malware has already increased, researchers say

SAN FRANCISCO CHRONICLE
AT&T, Verizon, Other Carriers Eyeing Federal Government Cybersecurity Deals
Managed security services will play key role in next generation of federal systems, observers say

TIMES ONLINE
Ex-Goldman Employee Indicted Over Software Theft
Programmer charged with stealing code to use at a rival trading house

THE NEW NEW INTERNET
Hacker To Help DARPA
"Mudge" will help federal government defend against cyberattacks

NETWORK WORLD
Virginia Firm Files Encryption Lawsuit Against Tech Giants
TecSec alleges that companies such as IBM, Oracle, and Cisco violated 11 of its patents

COMPUTERWORLD
Windows Patch Cripples XP With Blue Screen, Users Claim
Angry customers blame new patch for XP reboot hell

EWEEK
Google Buzz Privacy Concerns Similar To Facebook Issues
Here are some facts to keep in mind about Google's new social networking entry

PC TOOLS
'Flirt Bots' Lure Users In To Malicious Sites
This sort of flirting constitutes an unwelcome advance, researchers say

CLOUDMARK
New Spam Campaign Promises Government Grants
Spammers hope to turn users' heads with promises that the government is giving out money

SHANGHAI DAILY
Cyber Claims Just 'Nonsense,' Chinese Official Says
Cabinet member says Chinese government has never been involved in cyberattacks

BBC
Political Hacktivists Turn To Web Attacks
Groups increasingly using cyber exploits as a form of protest, report says

ZDNET UK
Early-Adopter Criminals Embrace Cloud Computing
Cloud technology's popularity among the bad guys bodes well for its future, expert says

B2B NEWZ
Hacker Owes Nintendo $1.3M
Nintendo says an Australian man will pay the company $1.3 million for illegally uploading a new Super Mario Bros game for the Wii to the Internet six days before its global release

WALL STREET JOURNAL
The Rise Of Caller ID Spoofing
Applications that let users change or spoof their caller IDs are gaining in popularity in mobile phone app stores -- meanwhile, Congress is considering legislation to outlaw particular uses of the technology

CNET
Hacker 'Mudge' Gets DARPA Job
Peiter Zatko -- best known as "Mudge" -- has has been named a program manager at DARPA, where he will be in charge of funding research designed to help give the U.S. government tools needed to protect against cyberattacks

THE REGISTER
USB Hack Connects Droid To Printers, Video Cams, And More
A security expert has revealed a way to make a Motorola Droid host USB-enabled devices, which lets the smartphone directly connect to printers, video cameras, TV tuners, and other peripherals

MCAFEE AVERT LABS
Valentine's Day Searches Lead To Malware
Several poisoned search teams have been identified, including Valentine's Day Screensavers, Valentine's Day eCards, Valentine's Day Greetings, and Valentine's Day Gift Ideas


Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)