Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173


Best Of The Web

ZDNET
Microsoft Partners With Good Technology For Encrypted Mobile Email
The Good for Enterprise app will be available for Windows Phones starting early in the second quarter of 2012

BANK INFOSECURITY
ATM Crime Boss Sentenced
An alleged Bulgarian crime boss who pleaded guilty to heading up several ATM-skimming attacks in the U.S. was sentenced to 41 months in prison

INTERNET SOCIETY
ICANN Publishes List Of Domain Registrars Supporting DNSSEC
ICANN has released a list of domain name registrars that support DNSSEC and says the list may be relatively short, but it's a 'good start'

SOURCEFIRE BLOG
Would You Like Some Malware With Your Recovery?
When AV fails, malware can inadvertently be spread to a company's data backup and cause reinfections when users restore their systems

THE WALL STREET JOURNAL
Tech Giants Agree To Deal On Privacy Policies For Apps
The state of California has reached an agreement with Apple, Google, Amazon, Microsoft, HP, and RIM over privacy issues in the mobile market

SOFTPEDIA
Security Holes Found In 25 'Verisign Trusted' Online Stores
A hacker has found multiple cross-site scripting (XSS) vulnerabilities in 25 online shops from the United Kingdom

SYMANTEC BLOG
Zeusbot/Spyeye P2P Updated, Fortifying The Botnet
The botnet was previously sending messages two and from the command and control servers, but is now doing so via the P2P network so any bot can serve as a C&C

NAKED SECURITY
Activists Creating Decentralized Mesh Networks That Can't Be Blocked, Filtered Or Silenced
Activists are building alternative mesh networks, often called an "internet in a suitcase," in order to keep online access

THE REGISTER
New Password-Snatching Mac Trojan Spreading In The Wild
A new variant of a Mac-specific password-snatching Trojan has been spreading in the wild that at first tries to install via Java vulnerabilities

CNN
U.S. Gears Up For Cyberwar Amid Conflicting Ideas On How To Fight It
Congress, former government officials and private sector experts often have conflicting ideas about how to address cyberwar

EWEEK
FCC: ISPs Need to Protect Users From Botnets, DNS Fraud, Cyber-Threats
ISPs, experts, academics, and others need to do more to protect users from botnets, IP hijacking, domain-name fraud, and other threats, FCC head says

THREAT POST
Video: Expert Proves Stuxnet's Link To Iran Nuclear Facilities
Ralph Langner shows how he isolated specific lines of code used in the Stuxnet attack that proves that it was written to attack the Iranian uranium enrichment facility in Natanz

SCHNEIER ON SECURITY
Computer Security When Traveling To China
A China expert with the Brookings Institution says that when he travels to China, he leaves his cellphone and laptop at home and instead brings loaner devices, which he erases before he leaves the United States and wipes clean when he returns

ZDNET BLOG
XSS Flaw Discovered In Skype's Shop, User Accounts Targeted
A researcher has discovered cross-site scripting flaws in shop.skype.com and api.skype.com, which if exploited could let an attacker hijack the user?s session and steal the account

INFOSEC ISLAND
DHS's Mark Weatherford On The Cybersecurity Act Of 2012
Deputy undersecretary for cybersecurity publicly endorses proposed legislation

EWEEK
FCC: ISPs Need To Protect Users From Botnets, DNS Fraud, Cyber Threats
Internet stakeholders should do more to protect end users, commission says

THE REGISTER
Brits Guard Facebook Passwords More Than Work Logins
A third of users have shared their work logins, but only 20 percent say they share Facebook credentials

REUTERS
WikiLeaks Suspect Manning Defers Plea, Court Martial Begins
Man accused of largest leak of classified documents in U.S. history faces life sentence

SECURITY NEWS DAILY
Hidden Security Worms May Loom In Apple?s Future
Rapid growth of platform could lead to increased targeting by hackers, experts say

CNET
Tech Firms Agree To Privacy Protections For Mobile Apps
Apple, Google, Microsoft and others agree to inform users of data usage policies before they download apps

WIRED
Ruling Stands: Defendant Must Decrypt Laptop
Woman who faces years in prison says decryption would violate her Fifth Amendment rights; appeals court says defendant must be acquitted or convicted before appeal can take place

INFO SECUIRITY
Firms Move Ahead With Mobility, Despite Security Concerns
More than 41 percent of IT professionals in Symantec study say they are worried about security risks posed by mobility programs

BANK INFOSECURITY
Tips To Fight Debit Fraud
New American Bankers Association report finds that POS signature suffer more losses than PIN-debit and ATM, which are a bit safer with their PINs, and debit card losses are now more than paper check fraud

GARTNER BLOG
Proposing An International Cyberweapons Control Protocol
Gartner analyst says protocols for cyberweapons weapons control and law enforcement are linked and lauds Eugene Kaspersky?s views on cyberwar

COMPUTERWORLD
Google, Microsoft Butt Heads Over IE Privacy Skirting
Google countered Microsoft's assertion that the search engine giant is skirting Internet Explorer's privacy protections

ZDNET
Microsoft Quietly Extends Consumer Support For Windows 7, Vista
Microsoft this month changed its support policy for consumer versions of Windows ? now Vista and Windows 7 will get a full 10 years of support

HELP NET SECURITY
Users Don't Bother Changing Default Passwords
Most people rarely change default, automatically generated and assigned passwords, and only about 25 percent change their passwords regularly

MOBILE COMMERCE PRESS
Visa Criticizes Lackluster Security Measures For PayPal?s New Mobile Payment Platform
Visa is warning anyone that chooses to use PayPal?s platform to guard their PINs so their financial information isn?t stolen

RAPID 7 COMMUNITY
Metasploit 4.2 Released: IPv6, VMware, And Tons Of Modules
New version of popular hacking tool supports opening command sessions and shells on IPv6 networks and existing payloads in Metasploit now also support IPv6

SECURELIST
DDoS Attacks In H2 2011
Kaspersky Lab says the longest DDoS attack in the second half of last year was against a travel website and lasted 80 days, 19 hours, 13 minutes, and five seconds

MARKETWATCH
New Survey Highlights Security Risks Facing Health IT And Security Professionals
Rapid adoption of mobile technologies brings new challenges to health care settings

IT NETWORKS
Hacker Jailed For Infiltrating Facebook Servers From His Parents? House Last Year
Hacker who ?tested? secure areas of Yahoo gets eight months for doing the same to Facebook

GOVERNMENT COMPUTER NEWS
The Riskiest Cities For Cybercrime: Where Does Yours Rank?
Nation?s capital takes top spot in Symantec report

CYBER NEWS
Anonymous Hackers Promise 'Something Big' Is Coming
Hacktivist group says a massive announcement will take place later this week

CNET
Scared Of Anonymous? NSA Chief Says You Should Be
Hacktivist group is growing more powerful, official says

FEDERAL NEWS RADIO
DHS Defends Social Media Monitoring Program
Congress takes closer look at privacy aspects in Homeland Security program

IT NETWORKS
Hackers Can Follow You Via Your Cell Phone
With cheap equipment, hackers can easily locate where you and your phone are, University of Minnesota study says

bit9
State-Sponsored Threats: Q&A With Richard Clarke
Former White House cybersecurity adviser offers insight on foreign governments? initiatives

THREAT POST
Google Password Generator In The Works
Google is building a tool to help users generate strong passwords for websites as an interim solution until the OpenID standard becomes widely deployed

THE WASHINGTON POST
Google Pulls Cookies That Tracked Users Through Safari
Google has removed special code it had reportedly attached to users' cookies when they ran Apple Safari browser that allows advertisers and Google to bypass Safari's ability to block third-party cookies


Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)