Best Of Web
Best Of The Web
INFORMATION MANAGEMENT
White House Proposes Cloud Security Standards
Requirements would apply to all federal agencies and contractors
TECHDIRT
Security Consultants Claim New Terrorist Bombs May Mean No More In-Flight Wi-Fi
Wi-Fi networks give bombers a number of options for remotely detonating an explosive, experts say
WORLD.EDU
Software To Combat Hacking Technique Wins Award
University researcher focuses on human behavior as the means for detecting malware
THE ETHICAL HACKER NETWORK
Organized Cyber Crime And Corporate Bank Account Takeovers
A look at how bank account fraud can happen, and what your organization can do about it
CIFAS
Digital Thieves: CIFAS Releases Special Report Into Online Identity Fraud
Instances of identity fraud are up nearly 10 percent over 2009, study says
FINEXTRA
American Express Spends $150 Million On Card-Not-Present Fraud Prevention Firm Accertify
Hosted software application offers an extra layer of security for transactions over the major payment networks
THE REGISTER
Google's $8.5 Million Buzz Settlement A Go
Google has been granted preliminary approval for a settlement in a class-action suit brought against Google Buzz, the Gmail add-on that attempted to convert Gmail into a social networking tool
MICROSOFT TECHNET BLOG
Zero-Day IE Attack Discovered, Microsoft Releases Security Advisory
New vulnerability found exploiting a single website, so Microsoft issues an advisory, workaround and plans for a fix
COMPUTERWORLD
Firesheep Not Evil, Says Snooping Tool's Maker
The creator behind the Firesheep snooping tool criticized Microsoft for adding detection of Firesheep to its antivirus software and argues the tool is neither unethical nor illegal
HEALTHCARE INFOSECURITY
EHR Adopters Need 'Culture Of Privacy'
An electronic health records expert says physicians adding their first EHR systems must adopt risk assessment, encryption, access control, and authentication, among other things
SECURITY INFO WATCH
Napolitano: Military To Aid Civilian Cybersecurity
DHS Secretary Janet Napolitano said the NSA can be used "appropriately" on civilian cybersecurity matters and that the recently announced agreement between the military and DHS takes privacy and civil liberties into account
THREAT POST
Adobe Accelerates Patch Schedule For Critical Flash Bug
Adobe will patch for the critical bug in Adobe Flash Player announced last week sooner than planned--tomorrow
SOPHOS NAKED SECURITY BLOG
Pharmaceutical Spammers Pose As Twitter Warnings
Messages redirect victims to an online website selling Cialis and Viagra
THE TELEGRAPH
16 Billion Devices Online By 2020, Says Report
The "Internet of things" will include more Internet-enabled devices, home gadgets and smart grid equipment, experts at consultancy firm Analysys Mason say
FORBES BLOG
British Nuclear Power Plant Goes Dark. Stuxnet Worm To Blame?
British Energy reported an outage at its nuclear power plant yesterday and speculation is swirling that it may also run the Stuxnet-targeted Siemens S7
ZDNET BLOG
SHODAN Search Exposes Insecure SCADA Systems
Hackers are using the Shodan search engine to find Internet-facing SCADA systems that insecurely authenticate and authorize systems, according to an alert from The Industrial Control Systems Cyber Emergency Response Team
GET ANDROID STUFF
Download SMS Replicator Android Secret Spy App
Free SMS tool can be installed on your significant other's phone, sending all of his or her text messages to your phone
THE TORONTO SUN
Youth Charged After Cracking School Board Database
London, Ontario, police have charged a 15-year-old with breaking into the Thames Valley District school board's website and exposing the passwords of 27,000 high school students on Oct. 23
EWEEK
Facebook App Developers Selling User IDs Suspended
Facebook is cracking down on application developers caught selling Facebook user IDs to data brokers
GARY WARNER BLOGSPOT
SAA Phish: Avalanche Uses Many "Redirectors"
New phishing campaign attempts to steal login credentials from USAA bank customers and appears to slip past many spam filters
DIGITAL SOCIETY
Online Services Security Report Card
Tests show that sidejacking is still possible even when a website runs SSL
TREND MICRO BLOG
Compromised Websites Use Java Flaws, Hit Japanese Users
More than 100 corporate clients in Japan have been hit with a Java-based attack that uses malicious Java scripting code on legitimate websites
NETWORK WORLD
Microsoft Considering Encryption For Bing
In the wake of the Firesheep WiFi hacking tool, Microsoft is looking into SSL and other security and privacy solutions for future releases of Bing
HELP NET SECURITY
Americans Feel Safer On A Computer Than A Mobile Device
Nearly 90 percent of Americans say they feel safer going online via their home computers than with their phones, according to a Symantec study
ZSCALER BLOG
Few Twitter Links Are Malicious
Zscaler looked at 1.5 million links in public Twitter tweets and found that less than 1 percent are dangerous links
CSO ONLINE
Is It Legal To Use Firesheep At Starbucks?
People using the Firesheep Firefox add-on could be breaking federal wiretapping laws, legal experts say, though the tool itself is not illegal
HELP NET SECURITY
One In Five Card Holders Use Birth Date As PIN
U.K. study found that 18 percent of people admit to using their birth date as a PIN code for a credit or debit card because it helps them remember the code
KCRA-TV
E-Mail Hacker Victimized Women
A man has been arrested for allegedly hacking into thousands of email accounts and posting nude or semi-nude photos of the victims on Facebook
THREAT POST
Expert Advises Caution On SCADA Security Hysteria
Worries about a breakdown or major disruption in the power grid or other SCADA-based systems are mostly unfounded in the wake of Stuxnet
SOFTPEDIA
Free Smartphone Spyware Tool Is Actively Developed
A software developer has released a new variant of a free Windows Mobile spyware application that steals call logs, SMS messages, contacts, appointments, and tracks people via GPS
THE STAR
Viagra Spammer Taken Down
Russia opens case against man accused of flooding the Internet with Viagra spam
BBC NEWS
Dutch Police Use Unusual Tactics In Botnet Battle
Law enforcement staff tap into hijacked computers to tell users they have been infected
DW-WORLD
Russian Hackers Rake In Millions With Little Fear Of The Law
Cybercrime in Russia is booming, and so far, police are no match for the hackers
TG DAILY
Iran Attempts To Bolster Cyber Defenses After Stuxnet
Government officials say country is working to shore up its defenses
YAHOO! NEWS
IT Governance Highlights Cyberattack As U.K.'s Greatest Threat
Security experts urge public and private sectors to shore up their defenses
BITPIPE.COM
Mobile Phones Emerge As Security Threat Targets
While sales of mobile smartphones skyrocket, potential for security problems increases
MY FOX ATLANTA
Palin Email Hacker Asks For Lighter Sentence
Tennessee man says his actions were an "aberration" from his normal behavior
SC MAGAZINE
Epidemiologist Fights Data Breach Pay Cut
Hack on server almost cost researcher her job, report says
ADOBE
Security Update Available For Shockwave Player
Adobe patches security critical flaw in popular app
H SECURITY
Spy Swallows Spy: ZBot And SpyEye Connected
Zeus developer Slavik has handed over his code to SpyEye developer Harderman, report says
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3562
Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-3561
Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.
CVE-2013-3560
The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-3559
epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (integer overflow, and heap memory corruption or NULL pointer dereference, and application crash) via a malformed packet.
CVE-2013-3558
The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not terminate a bit-field list, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.


