Best Of Web
Best Of The Web
COMPUTERWORLD
Microsoft Pushes Windows Web Bug Patch To Everyone
Microsoft released its latest emergency patch for a flaw in the ASP.Net website and application framework that let attackers steal important data from Web servers, including account usernames and passwords
H ONLINE
Report Says Cyber Attacks Should Trigger NATO Alliance
According to a newspaper report, NATO General Secretary Anders Fogh Rasmussen wants to extend the definition of attacks that trigger activation of the alliance to include cyberattacks
CBS 12
Security Breach At University Of Florida
The personal information, including Social Security numbers, of more than 230 University of Florida students has been stolen via a computer archive created by a faculty member
THE REGISTER
US Military Cyber Command Won't Go Operational As Planned
The Cyber Command's plans to go operational today is on hold due to difficulties finding qualified staff and uncertainty about what "operational" means for a cyberforce
TECH DIRT
Even Without COICA, White House Asking Registrars To Voluntarily Censor 'Infringing' Sites
The White House Intellectual Property Enforcement Coordinator has been meeting with ISPs, registrars, payment processors and others to urge them to voluntarily do what the "Combating Online Infringement and Counterfeits Act" (COICA) would do if it passes
THREAT POST
Gaps In International Cyber Law Could Threaten Mariposa Case
Legal issues could make it difficult to prosecute botnet creators
THE REGISTER
Judge Orders Turnover Of Woman's Deleted Facebook Posts
Statements made on social networking site are fair game in legal discovery process, court rules
NEW YORK TIMES
In A Computer Worm, A Possible Biblical Clue
Origins of a word used in Stuxnet code could provide hints about the perpetrators
PR NEWSWIRE
PandaLabs Publishes Exclusive Interview With Masterminds Behind "Operation Payback"
Anonymous attackers say their DDoS attacks against anti-piracy groups will continue indefinitely
SOFTPEDIA
Facebook Knows Who The Koobface Authors Are
Authorities are investigating the individuals, Facebook security expert says
BLUE COAT
Country-Coded Malware
Malware creators are giving some countries a break, while infecting others
REUTERS
EU Seeks To Boost Defenses Against Cyberattacks
Policy-makers say they want to fight large-scale attacks that could affect business
SOFTPEDIA
BT Suspected Of Breaching Data Protection Act
Company admits to transmitting customer data without encryption
TREND MICRO BLOG
ZeuS Now Bypasses Two-Factor Authentication
Some ZeuS/ZBOT variants now can defeat two-factor authentication systems, using mobile malware to defeat those authentication techniques that rely on text messages sent via mobile phones on Symbian OSS
THE REGISTER
Jailbreak Hole Found In Apple TV Firmware
Apple TV has nearly been jailbroken already, a hacker group known for freeing Apple devices
CNET
Fake Linkedin E-Mails Lead To Zeus Trojan
Phony LinkedIn invite e-mail attack tries to get users to click links that activate the Zeus data-stealing Trojan
MCAFEE AVERT LABS
Is Application-Based Control The Future of Botnets?
McAfee Labs reveals how cybercriminals can use common social networks and common Web applications, such as Twitter and XMPP-enabled applications like Google Talk, to bot-infect and take control of a user's machine
MSNBC
BlackBerry CEO Suggests Route To Eavesdropping
Research in Motion co-CEO Jim Balsillie says the company cannot give government officials with the text of encrypted corporate e-mail, but if the companies that employ BlackBerry phones want to hand over the encryption keys to their e-mail, it won't object
USPS
Customers Be Aware Of Fraudulent Package Delivery Messages Sent By Email
Phishing attack poses as email from the U.S. Postal Service about attempted or intercepted package delivery
H ONLINE
Microsoft Hotmail Gets Account Theft Protection
Microsoft has added password reset via SMS in the event that a user's Hotmail account was hacked and locked out the legitimate user
THREAT POST
Google Expands Malware-Alert Services For Site Operators
Google is offering a new alert service that will let the owners of large blocks of sites quickly know of malicious content on any of their sites
WIKIPEERS
China's Industrial Security Threatened By Web "Superbug"
Stuxnet has become a threat to the Chinese economy, experts say
CISCO
Cisco Security Tracks LinkedIn Spam Attack
Cisco researchers call it "the largest such attack to date"
MICROSOFT
Microsoft Releases Out-Of-Band Patch For ASP.net Vulnerability
Critical flaw could allow information disclosure, software giant says
NEW YORK TIMES
India's Surveillance Plan Said To Deter Business
Government's insistence on being able to decrypt digital messages could deter businesses from operating in the country
WIRED
Comcast.net Hijackers Sentenced To 18 Months
Jail sentence follows stunt that replaced Comcast home page with shout out to other hackers
FORTINET
Zeus In The Mobile (Zitmo): Online Banking's Two-Factor Authentication Defeated
New mobile malware is designed to intercept SMS messages sent by banks as confirmation
BIZ REPORT
PubMatic Launches Firewall To Protect Online Data
System lets publishers see who is dropping pixels on their sites
SC MAGAZINE
Rolling Stone Attacker Convicted
Botnet operator who attacked news sites now faces up to 10 years in jail
KREBS ON SECURITY
Spam Affiliate Program Spamit.com To Close
Spamit will close up shop at the end of September, noting increased public attention to its program
TOWNHALL.COM
Judge: Verdict Stands In Hacked Palin E-Mail Case
A federal judge upheld the convictions of a former University of Tennessee student for hacking Sarah Palin's e-mail account during the 2008 campaign
HELP NET SECURITY
USB Drive Identifies And Extracts Data, Leaving No Footprint
Harris Corp. has rolled out a customizable USB thumb drive that rapidly extracts targeted data from computers and is aimed at military, intelligence, and law enforcement
INFOSEC ISLAND
Few BitLocker-Equipped PCs Encrypt Data
Only 1.47 percent of Windows PCs with the BitLocker feature actually use the encryption, OPSWAT says
THE NEW NEW INTERNET
Hackers Steal Hundreds of Credit-Card Numbers From Restaurant Patrons
Police in Roseville, Calif., say nearly 200 customers had their credit-card numbers stolen after patronizing local restaurants
MICROSOFT SECURITY RESPONSE CENTER BLOG
Workaround Updated For Security Advisory
Microsoft has added a step to the workaround for Security Advisory 2416728 that helps block attackers from exploiting the vulnerability
FOX NEWS
U.S. Wants Broader Internet Wiretap Authority
The Obama administration is developing a plan to require encrypted BlackBerry email, Facebook, and Skype services to comply with federal wiretap orders, a report said
HOMESECURITY SOURCE
Top 5 Credit/Debit Card Skimming Attacks
ATM-skimming accounts for $350,000 in fraud each day, and more than $1 billion in losses each year, the U.S. Secret Service says
INFOSECURITY
Senate Hears Testimony On National Data Breach Legislation
Industry and government representatives testified before a Senate subcommittee about a proposed national data breach notification law -- but with November elections just around the corner, no one knows whether it will get through
STOREFRONT BACKTALK
Amazon Deliberately Bypassing Site Privacy, Says Carnegie Mellon
A new study from Carnegie Mellon University says Amazon uses a privacy loophole in Internet Explorer to get its cookies onto customers' PCs, whether they want them or not
COMPUTERWORLD
FBI Investigating 'Here You Have' Worm
The FBI has launched an investigation into the "Here you have" worm that disrupted corporate e-mail systems in the U.S. two weeks ago
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3270 (vnx_control_station, celerra_control_station)
EMC VNX Control Station before 7.1.70.2 and Celerra Control Station before 6.0.70.1 have an incorrect group ownership for unspecified script files, which allows local users to gain privileges by leveraging nasadmin group membership.
CVE-2013-1014 (itunes)
Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
CVE-2013-1011 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
CVE-2013-1010 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
CVE-2013-1008 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.


