Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173


Best Of The Web

ARS TECHNICA
Is Megaupload "A Lot Less Guilty Than You Think?"
Legal experts say Megaupload is likely in serious legal trouble, but Jennifer Granick, a Bay Area attorney blogging for Stanford's Center for Internet and Society, raises the distinction between civil and criminal law in the case

THE GASTON GAZETTE
IRS: Beware Of Dirty Dozen Tax Scams
The Internal Revenue Service has issued its annual "Dirty Dozen" tax scams list to warn taxpayers about scams and threats including identity theft and return preparer fraud

TRUSTEER
Merchant Of Fraud Returns -- Shylock Polymorphic Financial Malware Infections On The Rise
Each new build of this polymorphic malware contains excerpts from Shakespeare's The Merchant of Venice

HELP NET SECURITY
Thwarting Attacks With Genetically-Inspired Computer Configuration Systems
Automated security technology would be capable of learning from experience

THREAT POST
What You Need To Know About The RSA Key Research
RSA algorithm is not broken, analysis says

ALERTSEC XPRESS
University Of North Carolina At Charlotte Is Latest Victim Of Data Breach
Authorities scrambling to figure out how much data has been compromised

SANS INSTITUTE
SANS Launches Eighth Annual Log And Event Management Survey
Study aims to collect data on how enterprises collect and use log and event data

SOFTPEDIA
Stratfor Faces Lawsuit For Failing To Secure Customer Data
Lawsuit demands more than $50 million

ARBOR NETWORKS
DDoS Attacks In Russia Added To Protests
Political protests include cybersecurity exploits

FORBES
Anonymous Plans To Take Down The Internet? We're Being Trolled
Hacktivists' plan to take down the Web?s core address book could be a hoax, expert says

THREAT POST
Bloody Valentine For Critical Infrastructure: EtherNet Exploit Could Crash Devices
A new batch of PLC exploits was released by researchers that includes one exploiting a bug in the implementation of the EtherNet/IP (Internet Protocol) used in many IP-enabled PLCs

THE HACKER NEWS
Anonymous Hackers Target Nasdaq Website
A DDoS attack against websites for Nasdaq and BATS temporarily caused disruptions to the those sites -- Nasdaq says no information was stolen and trading was not affected

REUTERS
Philips Investigates Possible Cyber Security Breach
Philips Electronics shut down one of its servers yesterday due to a possible attack under investigation there

ZDNET BLOG
Have You Uninstalled Java Yet? Here Are 14 New Reasons...
Oracle's new patch release included 14 new vulnerabilities in Java SE, some that let hackers remotely install malware on machines without authenticating to them

INFOWORLD
Mozilla Will Ask All Certificate Authorities To Revoke SSL-Spying Certificates
Mozilla will request that certificate authorities revoke certs that could be used by companies to inspect SSL traffic for domain names they don't control in response to Trustwave revealing that it had done so

REUTERS
Experts Say Iran Has 'Neutralized' Stuxnet Virus
Iranian engineers have cleaned up and neutralized Stuxnet from their countrys nuclear systems, European and U.S. officials and private experts say

THE GLOBE AND MAIL
Reported Hacking Of Nortel Fuels Concerns, Skepticism
Cyber security experts says it?s no surprise Nortel was hit by cyberspies, but the question is whether stolen intellectual property might have led to the company's downfall

NEW YORK TIMES BLOG
Senators Introduce Security Bill And Warn Of Hacker Threat
Senate Bill 2105 lets the feds regulate the security of privately owned critical infrastructure, including power grids, telecommunications networks, and nuclear power plants, and task DHS with creating security regulations for critical infrastructure companies and penalize companies that don't comply

WASHINGTON POST
Hackers Loyal To Anonymous Claim Attack On US Tear Gas Company, Website Taken Down
Hacktivists say they broke into Combined Systems' website and stole personal information belonging to clients and employees

REUTERS
Philips Investigates Possible Cybersecurity Breach
Electronics firm says it shut down one of its servers Monday due to possible cyberattack

V3.CO.UK
Hackers Target TicketWeb Customers In Email Database Hack
Ticketmaster subsidiary admits it was the victim of a security breach last week

TWITTER
Securing Your Twitter Experience With HTTPS
HTTPS security will now be on by default for all users, social networking site says

SECURITY NEWS DAILY
Love And Theft: Online Dating Sites Put Daters' Privacy At Risk
Electronic Frontier Foundation report says participants may be exposing more data than they know

INFOSEC ISLAND
Security Flaw In eBanking Affects Over 100 Million Users
CAPTCHA vulnerabilities could expose customers, researcher says

SOFTPEDIA
6 GB NASA Database Leaked, Hackers Notify Agency
Two hacker groups say they exploited SQL injection vulnerability to steal data

FEDERAL NEWS RADIO
Budget Request Sees DHS Increasing Cybersecurity Spending
Homeland Security would sharply raise cybersecurity spending under White House 2013 budget request

THREAT POST
Mozilla Fixes Critical Flaw In Firefox
New version of Mozilla Firefox -- 10.0.1 -- includes a fix for a critical use-after-free bug in the browser

CANADA.COM
Evil Shadow Team Hacks Microsoft India
Microsoft is investigating an attack by hackers on its Indian retail website, reportedly carried out by a Chinese group called the "Evil Shadow Team"

THE HUFFINGTON POST
Tunes Hack: Users Report Unauthorized Charges On Accounts
Global Mail investigation concludes iTunes may have been hacked as far back as 2010, but Apple is neither confirming nor denying this

THE HACKER NEWS
Al Jazeera News Network Hacked By Syrian Hackers
Syrian hacktivist group targeted Al Jazeera's website in support of the government's actions in the country

THREAT POST
Hackers Hit Alabama, Mexican Government Websites
Hackers associated with Anonymous claim to be behind hacks of government websites in Alabama and Mexico, including the theft of personal information on more than 46,000 people

FSECURE BLOG
Cryptome Hacked
Cryptome.org, a site that posts items on freedom of speech, cryptography, spying, and surveillance, has been hacked and infused with malicious code based on the Blackhole crimeware kit

H ONLINE
Valve: Hackers May Have Gained Access To Steam Transactions
Valve Software says hackers accessed the database for its Steam game distribution platform in an attack late last year and may have stolen a copy of a backup file of customer transactions

GOOGLE BLOG
Protecting Your Payments With Google Wallet
Google warns Google Wallet users not to disable security functions to gain system-level "root" access to their phones, which would render Wallet's security features useless

CSO ONLINE
FBI Call Participants 'Made It Easy' For Anonymous To Break In
Investigators say it's likely that someone e-mailed to his or her private e-mail account the location number and password of the FBI-Scotland Yard conference call, and that private e-mail account was hacked by Anonymous, which was able to snoop on the call

NAKED SECURITY
Apple Supplier Foxconn Hacked Not For Bad Factory Conditions But For Kicks
Taiwanese manufacturer of iPhones and iPads for Apple Foxconn has been cited for alleged inhumane working conditions, and now the group was hacked by a group that goes by Swagg Security -- not for the working conditions there, but for the fun of the hack

BUSINESS WEEK
Tax Breaks Considered To Improve Cybersecurity On Vital Networks
Congressional members in the House are looking at tax breaks and liability protection to encourage banking, energy, and telecommunication companies to improve cybersecurity

BANK INFORMATION SECURITY
PCI: New Focus On Mobile
Mike Mitchell, chair of the Payment Card Industry Security Standards Council, says mobile is among his top priorities the Council this year, as well as point-to-point encryption, tokenization, and more compliance training

TECHWORLD
Citadel Banking Virus Adopts 'Open Source' Development
A Trojan that targets online banking users is evolving and spreading rapidly in the wake of an 'open-source' development model used by its creators, researchers from Seculert say

THE HACKER NEWS
Iran Shutdown Google, Yahoo & Other Major Sites Using HTTPS Protocol
The Iranian government reportedly has blocked access to websites using HTTPS including Google, Yahoo, and Gmail on the eve of the anniversary of the revolution that overthrew the country's monarchy and replaced it with an Islamic republic


Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)