Best Of Web
Best Of The Web
HELP-NET SECURITY
Skype Becomes A Malware Minefield
With the announcement of Skype in the Workspace, first-time Skype users and businesses should be careful when using Skype given the latest threats on the site
COMPUTERWORLD
Exposure Of Files On Unsecured Wireless No Excuse To Search, Judge Rules
Warrantless search of a file violated a child pornography defendant's Fourth Amendment right, federal judge says
COMPUTERWORLD
Twitter Flaw Gave Private Message Access To Third-Party Apps, Researcher Says
Apps that gained this permission without proper authorization still have it after Twitter fixes issue
THREAT POST
Twitter Bug Allowed Apps to Access Direct Messages Without Permission
Flaw enables access even though users have not given those rights to the app
TECHWORLD
John McAfee Biopic Will Dramatize Antivirus Entrepreneur's Eventful Life
Canadian company buys rights to make $28 million movie from unpublished memoirs of antivirus founder
DVLABS
Pwn2Own Competition Expanded
Hacking competition will now include vulnerabilities outside the Web browser
ARS TECHNICA
Cracking Tool Milks Weakness To Reveal Some Mega Passwords
Dotcom's Mega aids crackers by sending password hashes in plain text email
ZDNET
Sri Lanka Government Websites Hit In Spate Of Attacks
Hacker Davy Jones breaches government sites as well as those of two TV stations
CSO
iPhone Hackers Hint At Progress Towards iOS 6 Jailbreak
Two new vulnerabilities found in a day, according to one of the hackers
CYBER WARZONE
Red October Cyberattack Discovered Targeting Governments
Espionage malware targets diplomats, government employees, and scientific research
ARS TECHNICA
Two U.S. Power Plants Infected With Malware Spread Via USB Drive
Investigators find no up-to-date antivirus, system backups for control systems
ARS TECHNICA
Why Red October Malware Is The Swiss Army Knife Of Espionage
With more than 1,000 separate components, attack represents the age of super malware
BLOOMBERG
Naked-Image Scanners To Be Removed From U.S. Airports
The U.S. Transportation Security Administration will remove airport body scanners after the manufacturer was unable to update its software to make passenger images less revealing
QUARTZ
The Death Of Aaron Swartz Is The Failure Of Brinksmanship -- And Prosecution Of Real Computer Crimes
Swartz should have been given a restraining order to stay away from MIT or fined
USA TODAY
Feds: Infected USB Drive Idled Power Plant 3 Weeks
An infected USB spread to a turbine-control system at a U.S. power plant last fall and took three weeks for it to restart, the DHS says
DEFENSE NEWS
DoD Looking To 'Jump The Gap' Into Adversaries' Closed Networks
Army program will demonstrate, test systems that can insert and extract data from sealed, wired networks
COMPUTERWORLD
Malware Masquerades As Patch For Java
But it does not exploit Java vulnerabilities, Trend Micro says
NAKED SECURITY BLOG
War Of Words Continues Over Cisco Linksys Router Access Exploit
Remote attacker would need to authenticate to victim���s WiFi network first, so avoid WEP and choose a good password
SC MAGAZINE
Patient Data Revealed In Medical Device Hack
Unpatched flaws within the Philips Xper systems allowed researchers, within two hours, to develop an exploit capable of gaining remote root access
MASHABLE
Mystery Online Theft Operation 'Red October' Is Winding Down
Red October is disappearing quickly and its infrastructure dismantled or relocated after being exposed
SANS INTERNET STORM CENTER
86 Oracle Updates
Among the massive number of vulnerabilities in Oracle's security patch release was one with a risk of 9 out of 10
THE NEW YORK TIMES
Europe Weighs Requiring Firms To Disclose Data Breaches
The European Commission is considering a plan to require companies that store data online, such as Microsoft, Apple, and Google, to report the loss or theft of personal information in the 27-nation bloc or risk sanctions and fines
SECURELIST
Red October Java Exploit Delivery Vector Analysis
The attackers behind the 'Red October' targeted attacks used a Java exploit called 'Rhino' as one of their malware weapons
CHRISTIAN SCIENCE MONITOR
Should 'Good' Hackers Be Protected By Law?
Dutch member of parliament who exposed a security gap on a medical site is himself accused of hacking crimes
SOFTPEDIA
WBC Threatens To Picket Aaron Swartz Funerals; Anonymous Intervenes
Members of the controversial Westboro Baptist Church say they will protest, spurring hacktivist reaction
eSECURITY PLANET
Man Charged With Launching Cyberattacks On Vladimir Putin
The unidentified 30-year-old man faces up to four years in prison
eSECURITY PLANET
Michael Jackson Hackers Sentenced
James Marks and James McCormick received six-month suspended sentences, along with 100 hours of community service
SYDNEY MORNING HERALD
Lessons To Crack Down On Cyber Bullies
Some 600,000 Australian students to receive cybersafety training
CSO
Mobile Devices, Social Networks To Remain Security Targets In 2013: Sourcefire
Greatest challenge for today's security infrastructure is advanced malware attacks, report says
TECHWORLD
Iran Vs. USA -- The World's First Cyberwar Has Started
It sometimes hides behind hacktivism, but 75-Gbps peak DDoS on U.S. banks is no amateur protest
PC MAGAZINE
Hackers Who Tangled With The Feds And Lost
These hackers have taken on the U.S. government, only to land in jail or incur hefty fines
THREAT POST
Emergency Zero-Day Patch Does Not Quiet Calls To Disable Java
Experts say there are ways to bypass a security configuration in the update -- and others are concerned about fixes for vulnerabilities reported months ago that still have not been addressed
THE PALM BEACH POST
State Investigates Security Breach At Department Of Juvenile Justice
Florida law enforcement officials are investigating a breach at the Florida Dept. of Juvenile Justice that exposed information on 100,000 employees and youth offenders
SOFTPEDIA
Security Researcher Moxie Marlinspike Leaves Twitter
Marlinspike announced via Twitter that he’s leaving the company and has some ‘fun projects' under way
IMMUNITY PRODUCTS BLOG
Confirmed: Java Only Fixed One Of The Two Bugs
Immunity's analysis of the new Oracle Java 7 update 11 finds that only one of the two vulnerabilities were fixed, so Java remains vulnerable to one of the bugs used in the exploit spreading in the wild
SECURITY WEEK
Russian Faces 4 Years For Attack On Kremlin Website
A 30-year-old Russian man who allegedly organized an hour-long DDoS attack on the Kremlin website in support of the political opposition faces up to four years in prison
THE TELEGRAPH
Anonymous Hacktivists Target MIT Websites Over Aaron Swartz Suicide
Anonymous has defaced websites at the Massachusetts Institute of Technology in the wake of the suicide of free information-activist Aaron Swartz, who was due to face trial for allegedly stealing academic papers from the university
COMPUTERWORLD
New Congress Seen Shunning SOPA
Concerns on the Hill that a new bill like the Stop Online Piracy Act would result in massive online protests again
CTV NEWS
RCMP Investigating After Ottawa Loses Data On 583,000 Students
A portable hard drive containing personal information about more than half a million people who took out student loans went missing, exposing information on 583,000 Canada Student Loans Program borrowers from 2000 to 2006
REUTERS
Exclusive: JP Morgan Faces U.S. Order To Improve Compliance -- Sources
U.S. regulatory probe of JP Morgan Chase will result in order that the bank better police suspicious money-movement
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3496 (vipnet_client, vipnet_coordinator, vipnet_personal_firewall, vipnet_safedisk)
Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.
CVE-2013-2849 (chrome)
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.
CVE-2013-2848 (chrome)
The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.
CVE-2013-2847 (chrome)
Race condition in the workers implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via unknown vectors.
CVE-2013-2846 (chrome)
Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2840.


