Best Of Web
Best Of The Web
HELP-NET SECURITY
Skype Becomes A Malware Minefield
With the announcement of Skype in the Workspace, first-time Skype users and businesses should be careful when using Skype given the latest threats on the site
COMPUTERWORLD
Exposure Of Files On Unsecured Wireless No Excuse To Search, Judge Rules
Warrantless search of a file violated a child pornography defendant's Fourth Amendment right, federal judge says
COMPUTERWORLD
Twitter Flaw Gave Private Message Access To Third-Party Apps, Researcher Says
Apps that gained this permission without proper authorization still have it after Twitter fixes issue
THREAT POST
Twitter Bug Allowed Apps to Access Direct Messages Without Permission
Flaw enables access even though users have not given those rights to the app
TECHWORLD
John McAfee Biopic Will Dramatize Antivirus Entrepreneur's Eventful Life
Canadian company buys rights to make $28 million movie from unpublished memoirs of antivirus founder
DVLABS
Pwn2Own Competition Expanded
Hacking competition will now include vulnerabilities outside the Web browser
ARS TECHNICA
Cracking Tool Milks Weakness To Reveal Some Mega Passwords
Dotcom's Mega aids crackers by sending password hashes in plain text email
ZDNET
Sri Lanka Government Websites Hit In Spate Of Attacks
Hacker Davy Jones breaches government sites as well as those of two TV stations
CSO
iPhone Hackers Hint At Progress Towards iOS 6 Jailbreak
Two new vulnerabilities found in a day, according to one of the hackers
CYBER WARZONE
Red October Cyberattack Discovered Targeting Governments
Espionage malware targets diplomats, government employees, and scientific research
ARS TECHNICA
Two U.S. Power Plants Infected With Malware Spread Via USB Drive
Investigators find no up-to-date antivirus, system backups for control systems
ARS TECHNICA
Why Red October Malware Is The Swiss Army Knife Of Espionage
With more than 1,000 separate components, attack represents the age of super malware
BLOOMBERG
Naked-Image Scanners To Be Removed From U.S. Airports
The U.S. Transportation Security Administration will remove airport body scanners after the manufacturer was unable to update its software to make passenger images less revealing
QUARTZ
The Death Of Aaron Swartz Is The Failure Of Brinksmanship -- And Prosecution Of Real Computer Crimes
Swartz should have been given a restraining order to stay away from MIT or fined
USA TODAY
Feds: Infected USB Drive Idled Power Plant 3 Weeks
An infected USB spread to a turbine-control system at a U.S. power plant last fall and took three weeks for it to restart, the DHS says
DEFENSE NEWS
DoD Looking To 'Jump The Gap' Into Adversaries' Closed Networks
Army program will demonstrate, test systems that can insert and extract data from sealed, wired networks
COMPUTERWORLD
Malware Masquerades As Patch For Java
But it does not exploit Java vulnerabilities, Trend Micro says
NAKED SECURITY BLOG
War Of Words Continues Over Cisco Linksys Router Access Exploit
Remote attacker would need to authenticate to victim���s WiFi network first, so avoid WEP and choose a good password
SC MAGAZINE
Patient Data Revealed In Medical Device Hack
Unpatched flaws within the Philips Xper systems allowed researchers, within two hours, to develop an exploit capable of gaining remote root access
MASHABLE
Mystery Online Theft Operation 'Red October' Is Winding Down
Red October is disappearing quickly and its infrastructure dismantled or relocated after being exposed
SANS INTERNET STORM CENTER
86 Oracle Updates
Among the massive number of vulnerabilities in Oracle's security patch release was one with a risk of 9 out of 10
THE NEW YORK TIMES
Europe Weighs Requiring Firms To Disclose Data Breaches
The European Commission is considering a plan to require companies that store data online, such as Microsoft, Apple, and Google, to report the loss or theft of personal information in the 27-nation bloc or risk sanctions and fines
SECURELIST
Red October Java Exploit Delivery Vector Analysis
The attackers behind the 'Red October' targeted attacks used a Java exploit called 'Rhino' as one of their malware weapons
CHRISTIAN SCIENCE MONITOR
Should 'Good' Hackers Be Protected By Law?
Dutch member of parliament who exposed a security gap on a medical site is himself accused of hacking crimes
SOFTPEDIA
WBC Threatens To Picket Aaron Swartz Funerals; Anonymous Intervenes
Members of the controversial Westboro Baptist Church say they will protest, spurring hacktivist reaction
eSECURITY PLANET
Man Charged With Launching Cyberattacks On Vladimir Putin
The unidentified 30-year-old man faces up to four years in prison
eSECURITY PLANET
Michael Jackson Hackers Sentenced
James Marks and James McCormick received six-month suspended sentences, along with 100 hours of community service
SYDNEY MORNING HERALD
Lessons To Crack Down On Cyber Bullies
Some 600,000 Australian students to receive cybersafety training
CSO
Mobile Devices, Social Networks To Remain Security Targets In 2013: Sourcefire
Greatest challenge for today's security infrastructure is advanced malware attacks, report says
TECHWORLD
Iran Vs. USA -- The World's First Cyberwar Has Started
It sometimes hides behind hacktivism, but 75-Gbps peak DDoS on U.S. banks is no amateur protest
PC MAGAZINE
Hackers Who Tangled With The Feds And Lost
These hackers have taken on the U.S. government, only to land in jail or incur hefty fines
THREAT POST
Emergency Zero-Day Patch Does Not Quiet Calls To Disable Java
Experts say there are ways to bypass a security configuration in the update -- and others are concerned about fixes for vulnerabilities reported months ago that still have not been addressed
THE PALM BEACH POST
State Investigates Security Breach At Department Of Juvenile Justice
Florida law enforcement officials are investigating a breach at the Florida Dept. of Juvenile Justice that exposed information on 100,000 employees and youth offenders
SOFTPEDIA
Security Researcher Moxie Marlinspike Leaves Twitter
Marlinspike announced via Twitter that he’s leaving the company and has some ‘fun projects' under way
IMMUNITY PRODUCTS BLOG
Confirmed: Java Only Fixed One Of The Two Bugs
Immunity's analysis of the new Oracle Java 7 update 11 finds that only one of the two vulnerabilities were fixed, so Java remains vulnerable to one of the bugs used in the exploit spreading in the wild
SECURITY WEEK
Russian Faces 4 Years For Attack On Kremlin Website
A 30-year-old Russian man who allegedly organized an hour-long DDoS attack on the Kremlin website in support of the political opposition faces up to four years in prison
THE TELEGRAPH
Anonymous Hacktivists Target MIT Websites Over Aaron Swartz Suicide
Anonymous has defaced websites at the Massachusetts Institute of Technology in the wake of the suicide of free information-activist Aaron Swartz, who was due to face trial for allegedly stealing academic papers from the university
COMPUTERWORLD
New Congress Seen Shunning SOPA
Concerns on the Hill that a new bill like the Stop Online Piracy Act would result in massive online protests again
CTV NEWS
RCMP Investigating After Ottawa Loses Data On 583,000 Students
A portable hard drive containing personal information about more than half a million people who took out student loans went missing, exposing information on 583,000 Canada Student Loans Program borrowers from 2000 to 2006
REUTERS
Exclusive: JP Morgan Faces U.S. Order To Improve Compliance -- Sources
U.S. regulatory probe of JP Morgan Chase will result in order that the bank better police suspicious money-movement
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3927
Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 before 10.0.3.0.4 allows local users to obtain unintended write access to the database by leveraging read access.
CVE-2013-3647
The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL. NOTE: this vulnerability exists because of a CVE-2012-4009 regression.
CVE-2013-3646
The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site. NOTE: this vulnerability exists because of a CVE-2012-4008 regression.
CVE-2013-3644
Unspecified vulnerability in JustSystems Ichitaro 2006 through 2013; Ichitaro Pro through 2; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro Portable with oreplug; Ichitaro Viewer; and Ichitaro JUST School through 2010 allows remote attackers to execute arbitrary code via a crafted document.
CVE-2013-4616 (iphone_os)
The WifiPasswordController generateDefaultPassword method in Preferences in Apple iOS 6 and earlier relies on the UITextChecker suggestWordInLanguage method for selection of Wi-Fi hotspot WPA2 PSK passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack that leverages the insufficient number of possible passphrases.



