Best Of Web
Best Of The Web
BBC NEWS
Facebook Suffers Brief Shutdown
Facebook took its site offline after a staff member accidentally leaked internal product prototypes, leaving the social network unaccessible for about 30 ninutes
EWEEK
Scotland Yard Has Been After Anonymous For Months
The Metropolitan police had been investigating Anonymous prior to the WikiLeaks-related DDoS attacks for waging similar attacks against other companies
HELP NET SECURITY
NSA Considers Its Networks Compromised
Head of NSA's Information Assurance Directorate said no computer network can be considered completely impenetrable, not even NSA�s and the agency works under the assumption that parts of its network have already been hacked
CSO ONLINE
Smartphone Botnets? New Report Predicts Mobile Devices Will Be Part Of DDOS Attacks
Smartphones could soon be used to launch distributed attacks, much like traditional PCs are now used as parts of larger botnet networks, according to a new report from ENISA
SCHNEIER ON SECURITY
Security In 2020
In the future, security will be less about protecting you from the bad guys and more about protecting the business from you
HELP NET SECURITY
Insiders Are Most Often Responsible For Data Loss
IT managers see insiders as greatest threat, Imperva study says
SYMANTEC
Holidays Bring Increase In Product Spam
Bad guys seek to take advantage of shopping season, report says
WALL STREET JOURNAL
U.S. Urges Web Privacy "Bill Of Rights"
Obama administration calls for creation of a Privacy Policy Office
NETWORK WORLD
Security Feature In Office 2010 Will Soon Be Added To Older Versions
File validation will be available in Q1 of 2011, software giant says
CNN
Five Data Breaches: From Embarrassing To Deadly
Major companies--including NetFlix, Google, and Facebook--have let private data loose
OPEN GROUP
The Trusted Technology Forum: Best Practices For Securing The Global Technology Supply Chain
TTF will focus on reducing vulnerabilities introduced through supplier-partner relationships
CSO ONLINE
Bank Of America: Ex-Employees Took Databases
In lawsuit, company alleges that four employees copied confidential databases of trade secrets
JPOST.COM
Stuxnet Virus Set Back Iran�s Nuclear Program By 2 Years
The German security expert who was one of the first to analyze the Stuxnet code said the worm has set back Iran�s nuclear program by two years and was almost as effective as a military strike, but without casualties
THE DENVER POST
FBI Memo Reveals Cost Of Fighting Computer Hacker
An attack on Google during 2004 and 2005 cost Google $500,000 to defend and recover from, according to internal FBI memos obtained through a Freedom of Information Act request
AVIATION WEEK
NASA IG Finds Shuttle IT Security Lapses
Equipment not properly sanitized upon disposal, report states
NAKED SECURITY BLOG
The Top 50 Passwords You Should Never Use
Among the most common passwords exposed in the Gawker hack were the easily guessed 123456, password, 123345678, lifehack, abc123, and qwerty
WALL STREET JOURNAL
Attacks Test Firms' Internet Defenses
WikiLeaks protests challenge companies' ability to withstand targeted exploits
SPAMHAUS
WikiLeaks Mirror Malware Warning
New host of controversial site is located in a dangerous neighborhood, researchers warn
THE REGISTER
Email Protected By Fourth Amendment, Says Appeals Court
ISPs not required to disclose messages without a warrant, regardless of time stored
STOREFRONT TALKBACK
Genesco Payment Database Breached, Full Payment Data Taken
Footwear retailer says its payment systems had been breached and it�s possible that credit or debit card numbers, expiration dates, and card verification codes were grabbed
CNET
Fortinet: Job Outlook Improving For Cybercrooks
Cybercriminals are more likely to find jobs next year, security firm predicts
THE WALL STREET JOURNAL
Air Force Blocks Media Sites
U.S. Air Force is blocking the use of work computers to view the websites of The New York Times and other major publications that have posted classified diplomatic cables
SECLISTS.ORG
Hidden Admin User On Hewlett-Packard Storage Area Networks
Bug could create problems for HP SANs, researcher says
SECURE COMPUTING
Freelancer.com Posts: Jobs For Botnets, Fake IDs
Cybercriminals began using Freelancer.com to recruit malware writers and for identity fraud, but the posts have now been removed
MICROSOFT
Microsoft Releases 17 Updates On Big Patch Tuesday
Two updates are considered critical, software giant says
ZDNET BLOG
Mozilla Expands Bug Bounty To Web Apps
Mozilla will pay between $500 to $3,000 for major vulnerabilities in its open-source code
HUFFINGTON POST
Why I'm Posting Bail Money For Julian Assange
Oscar-winning documentary filmmaker Michael Moore offers support for WikiLeaks leader
CSO ONLINE BLOG
An FBI Backdoor In OpenBSD?
Former government contractor told OpenBSD exec the FBI had placed several backdoors in the Open BSD IPsec protocol, but skeptics say it�s not true
SOFTPEDIA
Second Teenager Arrested In The Netherlands For Anonymous-Orchestrated DDoS
Dutch police have arrested a 19-year-old suspected of participating in pro-WikiLeaks DDoS attacks organized by members of the Anonymous hacktivist group
THE EXAMINER
Wisconsin Bungles Another Data Breach And ID Theft Threat To 60,000
The University of Wisconsin-Madison says a database containing Social Security numbers of 60,000 former students and staff had been repeatedly hacked since 2008, but that there is no evidence that anyone's information was retrieved
TREND MICRO BLOG
2010 In Review: The Hype And Reality Of Stuxnet
Stuxnet, indeed, is a sophisticated piece of malware, but the reality is most users were not significantly affected
INTERNET EVOLUTION
Arms Control In Cyberspace: A Proposal
National security planners may look beyond reactive cyber-defense tactics to proactive, cyber-defense strategies using cyber-arms control as one possibility
NETCRAFT
Mastercard Goes Down As Anonymous Launch 2nd Attack
The hacktivist movement knocked Mastercard.com offline for a second time via a distributed denial-of-service attack
REUTERS
Walgreen Warns Customers Email Addresses Accessed
Walgreen Co. has warned its customers they may have received unauthorized email seeking personal data after a breach of one of the company's customer lists
ECRM GUIDE
Companies Try To Avoid Data Privacy Regs With Voluntary Effort
Data collection companies have teamed in a project that will let consumers edit data about themselves or opt out of online data collection entirely
OC REGISTER
McDonald's Hacked, Customer Data Stolen, Chain Says
McDonald's is warning customers to be on the alert for an email claiming to be from the fast-food giant asking for personal or financial information
UK REUTERS
Shamed Chinese Hacker Turns Panda Protector
Former Chinese hacker who just finished a four-year jail term has donated 50,000 yuan ($7,520) to protect endangered pandas -- he had used an image of an incense-waving panda for a computer virus he spread to millions of computers
THREAT POST
New Remotely Exploitable Bug Found In Internet Explorer
Browser vulnerability has to do with how IE 6, 7, and 8 handle a certain DLL library on pages that reference CSS files, and exploit code is out
NAKED SECURITY BLOG
Firefox Receives Critical Security Fixes--Update Now
Mozilla has issued version 3.6.13 of its Firefox browser with fixes for 11 security holes, nine of which are critical
WIRED
Military Bans Disks, Threatens Courts-Martial To Stop New Leaks
U.S. military says troops must halt in their use of CDs, DVDs, thumb drives, and all other removable media or risk a court martial
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3270 (vnx_control_station, celerra_control_station)
EMC VNX Control Station before 7.1.70.2 and Celerra Control Station before 6.0.70.1 have an incorrect group ownership for unspecified script files, which allows local users to gain privileges by leveraging nasadmin group membership.
CVE-2013-1014 (itunes)
Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
CVE-2013-1011 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
CVE-2013-1010 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
CVE-2013-1008 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.


