Best Of Web
Best Of The Web
ZDNET
Korea Attacks Force DDOS Bunker Creation
South Korea has set up new IP addresses, sinkholes, and tarpits to prevent a repeat of the massive distributed-denial-of-service attacks that crippled parts of the country last year
THE GUARDIAN
Computer Expert Jailed After Hacking Victims' Webcams
Hacker who took over victims' webcams was member of an international gang that targeted businesses and individuals
THE WASHINGTON POST
AEA Report Confirms Iran Temporarily Shut Down Centrifuges
Amid speculation that Stuxnet was targeting Iranian centrifuges, the International Atomic Energy Agency is now reporting that on Nov. 16, Iran stopped feeding uranium gas into its centrifuges and the shutdown could have lasted for several days
EWEEK
Exploit Code For Windows Zero-Day Targeted By Stuxnet Goes Public
Exploit code for one of the zero-day vulnerabilities used in the Stuxnet worm has been released
THE WALL STREET JOURNAL
Insurers Test Data Profiles To Identify Risky Clients
Insurance companies are increasingly gathering information found online about consumers, who are only vaguely aware that bits of information about them are being collected and collated
SOPHOS
New Password From Facebook? Beware Widely-Spread Malware Attack
Attack appears as email that purports to be from Facebook admin
EWEEK
Facebook Bug Locks Out Female Users
System designed to root out fake accounts briefly causes logon trouble for some users
EWEEK
Stuxnet Requires Better Critical Infrastructure Security Approach
U.S. industrial plants will need to step up their IT security efforts, Senate subcommittee is told
RIANOVOSTI
Russian Banks Probed For Involvement In U.S. Hacker Attacks
Russia's financial watchdog will investigate to find out whether country's banks were involved in hacking and money-laundering ring
ZDNET
Korea Attacks Force DDoS Bunker Creation
South Korea installs digital "bunker" to help prevent a repeat of previous attacks
HELP NET SECURITY
LinkedIn Attack Comprised Over 31 Percent Of All Spam
Enterprise users encountered an average of 133 Web malware encounters per month, Cisco report says
TECHTREE
Twelve Scams Of Christmas To Watch Out For
Be on the lookout for these online exploits as the festive season approaches
RSA
The Limitations Of Phishing Attacks
Phishing is an effective an easy attack vector, but it does have flaws that may be useful in defense
WIRED
Clues Suggest Stuxnet Virus Was Built For Subtle Nuclear Sabotage
New evidence found in the Stuxnet malware hints that the code was designed to sabotage nuclear plants and involves briefly speeding up and slowing down physical machinery at a plant over a span of weeks
NEW SCIENTIST
Nuke Watchdog Could Help Prevent Future Stuxnets
The International Atomic Energy Agency could add computer security at nuclear plants now that evidence shows Stuxnet indeed targeted nuclear energy equipment
THE REGISTER
Hackers Hop Onto Royal Engagement Search Results
Links to malicious sites appeared prominently in Google searches for Kate Middleton, and malicious downloads were offered under the guise of a Firefox update
MIT TECHNOLOGY REVIEW
For Your Eyes Only
New biometric security system uses the unique pattern of a person's eye movements to provide an eye-tracking system that's easy to use and difficult to fool
KCAU-TV
Nebraska Students' Financial Privacy Breached
Effort to ensure transparency in state spending in Nebraska resulted in the posting of private financial aid and loan information about thousands of University of Nebraska students
DOW JONES NEWSWIRES
Credit Unions Ask Congress To Help With Security Breaches
The National Association of Federal Credit Unions has asked Congress to help address identity theft and fraudulent charges, saying the new financial overhaul makes it harder to offset the cost of breaches
ASSOCIATED PRESS
New Settlement Offered In TD Ameritrade Data Theft
Millions of current and former TD Ameritrade customers whose contact information may have been stolen more than three years ago will be eligible to receive as much as $2,500 under a new settlement agreement
YAHOO NEWS
U.S. Faces 'Huge' Cyber Threat In The Future: Gates
Defense Secretary Robert Gates said this week that potential cyberattacks posed a "huge" future threat that requires joint efforts by U.S. military and civilian agencies
THE REGISTER
World's Most Advanced Rootkit Penetrates 64-Bit Windows
Rootkit attaches itself to master boot record
REUTERS
U.S. Sees "Huge" Cyber Threat In Future
Defense will require coordination between civil and military resources, Defense Secretary Gates says
NEWSMAX.COM
Obama Wants Internet Security Czar
Internet privacy laws may also be in the works
NATIONAL DEFENSE
Cyber Experts Have Proof That China Has Hijacked U.S-Based Internet Traffic
Chinese could have eavesdropped on redirected traffic
ADOBE
Security Updates Released For Adobe Reader And Acrobat
Updates address critical security issues found in Adobe apps
WASHINGTON POST
New Research Confirms Iran's Nuclear Program Was Target Of Stuxnet Worm
Exploit might have crippled centrifuges used to enrich uranium gas, researchers say
IT BUSINESS EDGE
Another Internet Explorer Zero-Day Surfaces, Added To Exploit Kit
Eleonore toolkit has a new weapon in it, researchers say
NEW SCIENTIST
U.S. Internet Hosts Are Linchpin Of Criminal Botnets
When it comes to hosting command and control servers, U.S. hosts are at the head of the pack
THE REGISTER
Koobface Takedown Exposes Money Trail
Canadian security firm leads takedown of Koobface servers over the weekend -- the Koobface gang has made $2 million since 2008 with fake AV, click fraud, and other ruses
COMPUTER WEEKLY
Private Sector Vital To Fighting Cybercrime, Says SOCA
Partnership between business, law enforcement is critical, says U.K.'s Serious Organized Crime Agency
SILICON INDIA
Employees' Online Shopping To Hamper Business
Shopping at work could bring additional risk to corporate computing environment, ISACA study says
PC PRO
Malware Spam Soars As Crooks Club Together
Nearly 5 percent of all spam messages contain some sort of threat, Kaspersky researchers say
NETWORK WORLD
FTC Appoints Cool Hacker As First Chief Technologist
Ed Felton's appointment could signal that commission is about to dive deeper into digital privacy issues
WALL STREET JOURNAL
Cybercriminals Are People, Too
Government intelligence expert says cybercrime is not just a technology issue, but a human issue
SILICON REPUBLIC
Bruce Schneier On The Future Of IT Security
Security expert seeks to debunk some of the myths about cyberwar
PC MAGAZINE
FCC Investigating Google Street View Wi-Fi Data Collection
Privacy of users could be at risk, commission says
MERRITT GROUP
Making A Difference With The Launch Of The Identity Theft Council
New nonprofit benefits ID theft victims -- and brings a human element to IT security
NETWORK WORLD
When Sites Share Data About Zero-Day Attacks, False Positives Plummet
University study shows the value of sharing data about new exploits
TECHWORLD
Women More Likely To Fall For Internet Fraud
In six of seven research tests, women were less likely to detect a scam than men
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



