Best Of Web
Best Of The Web
EXODUS INTELLIGENCE
Bypassing Microsoft's Internet Explorer 0day 'Fix It' Patch For CVE-2012-4792
Researchers were able to bypass Microsoft's Fix It solution for the new zero-day flaw in IE and compromise a fully patched system with a variation of the exploit
HELP NET SECURITY
Microsoft To Release Seven Advisories On Tuesday
Among the patches coming from Microsoft next week is a server patch that fixes a worm-able bug
MCAFEE BLOG
Losing A Mobile Phone Doesn't Have To Stink
Password-protect, back-up data, don't store app logins, record your serial number, and run antivirus that tracks lost phones
THREAT POST
Adobe To Patch Reader, Acrobat; Warns Of Coldfusion Exploit
Newly found bugs in Adobe Reader and Acrobat are not being exploited, but Adobe is working on a fix for a bug in ColdFusion that is being used in attacks
CHRISTIAN SCIENCE MONITOR
Secret US Cybersecurity Program To Protect Power Grid Confirmed
The National Security Agency is spearheading a program to develop technology to protect the power grid from cyberattack � and this has privacy rights groups concerned
INFOSECURITY MAGAZINE
Dissection Of 'Itsoknoproblembro,' The Ddos Tool That Shook The Banking World
A look at the DDoS attacks targeting U.S. banks that at one time peaked at 70 Gbps
NAKED SECURITY BLOG
How A Regular IT Guy Helped Catch A Botnet Cybercriminal
Sophos customer who saved a copy of the IRCBot and helped identify the damage of the malware helped authorities catch a bad guy behind a botnet
eSECURITY PLANET
Hacker AnonAcid Publishes Data On 50,000 Ohio Residents
Hacktivist says data dump is part of protest alleging that authorities are protecting members of Steubenville football team accused of rape
SOFTPEDIA
Over 18,000 PayPal Phishing Websites Identified In December
Cybercriminals launch growing number of sites that replicate popular companies
ESET
2013 Forecast: Malware, Scams, Security And Privacy Concerns
Accelerated malware development tops the list of potential issues in 2013
MICROSOFT
Fraudulent Digital Certificates Could Allow Spoofing, Microsoft Warns
Active attacks use fraudulent digital certificate issued by TURKTRUST Inc., software giant says
SYMANTEC
Elderwood Project Behind Latest Internet Explorer Zero-Day Vulnerability
String of watering-hole attacks is attributed to hacker group
JOURNALISM.CO
Major Global Facebook Botnet Taken Down
Fraud ring worth nearly $1 billion is taken out of action, social networking giant says
ZDNET
Japan Ministry Information Reportedly Stolen In Cyberattack
Government computers suspected to have been remotely controlled by overseas server
WASHINGTON POST
To Thwart Hackers, Firms Salting Their Servers With Fake Data
Enterprises create "rabbit holes" of bogus data in hopes of frustrating cybercriminals
ZDNET
Israel Launches Cyber Warfare Training Program
New initiative trains young people for cyberwarfare, and nation beefs up its National Cyber Bureau
CYBER WAR NEWS
1,000 Myanmar Sites Hacked & Defaced
Website defacements say happy new year, and full list of affected sites are on Pastebin
THE REGISTER
Facebook Fixes 'Peeping Tom' Webcam Bug -- After 5 Months
Facebook had a busy time over the holiday period fixing several security flaws, including a webcam-related vulnerability that allowed hackers to record video from a user's web camera and post it on their timeline
SOFTPEDIA
Case Against 5 Japanese Android Malware Developers Dismissed
Japanese authorities have had difficulty prosecuting a number of individuals suspected of developing and using malware against mobile phone users
BOSTON.COM
RI Labor Dept. Warns Of Possible Privacy Breach
The Rhode Island Department of Labor and Training says a technical issue may have resulted in a privacy breach for 700 callers to its phone line for unemployment and disability benefits
CNET
Anonymous: 'Expect Us 2013'
The hacking group issues a statement boasting of its cyberattacks against the U.S., Syrian, and Israeli governments in 2012, while warning people to continue to expect these attacks
THREAT POST
Bans On Employer Demands For Personal Passwords Go Into Effect
Some state laws take effect or will soon that make it illegal for employers to demand access to the social profiles of their employees and job applicants
THE NEXT WEB
New Services Bypass Apple DRM To Allow Pirated iOS App Installs Without Jailbreaking On iPhone, iPad
New services offer easy installation of pirated apps, even on devices that have not been jailbroken
SOFTPEDIA
Korean Responsible For Hacking Hyundai Capital Arrested In Philippines
A 39-year-old man was arrested this month by authorities in the Phillipines in connection with the breach of servers at Hyundai Capital in 2011
SECURELIST
Hashcat's GPU-Accelerated Gauss Encryption Cracker
Researcher releases free Gauss encryption cracker tool to help researchers trying to break the encryption scheme with the Trojan
WASHINGTON FREE BEACON
Chinese Hackers Suspected In Cyber Attack On Council On Foreign Relations
Sources say attackers penetrated server that runs the Council on Foreign Relations' website and infected members and others who visited the site
THREAT POST
Senate Reauthorizes FISA, Rejects Proposed Privacy Amendments
The Senate shunned four privacy-friendly amendments to the controversial Foreign Intelligence Surveillance Act (FISA) and voted to authorize the bill that grants the federal government the authority to clandestinely monitor electronic communications involving foreign citizens coming into or out of the United States without probable cause
SANS INTERNET STORM CENTER
Google Blocks Silent Chrome Extension Installation
Google Chrome 25 won't allow silent installations of Chrome add-ons
THE NEXT WEB
McAfee Predicts Anonymous Hacktivist Movement Will Slow Down In 2013, But Its Reasoning Is Flawed
McAfee says the hacktivist group will fade next year mainly due to lessened technical sophistication, but not some take issue with this prediction
RUSSIA BEYOND THE HEADLINES
Putin Urges FSB To Pay Attention To Counterintelligence, Resistance To Cyber Crime
Russian president Vladimir Putin told the Federal Security Service (FSB) to act "systemically and offensively," particulary when it comes to cybercrime
THE HACKER NEWS
Malware That Can DDoS Attacks From Your Smartphone
Doctor Web has discovered malware for Android that allows attackers to wage mobile denial-of-service attacks, unbeknown to the victim
SC MAGAZINE
Obama May Issue Cybersecurity Order In Early January
Executive order will outline objectives for critical infrastructure protection
SOFTPEDIA
Records Of 300,000 Verizon Customers Leaked, Firm Says Breach Affected Third Party
Hacker posts file containing customer records; says Verizon fails to fix vulnerability
TECHNOLOGY BANKER
Mobile Application Security: How To Respond To The Latest Threats
A look at the most current attacks on mobile devices, and what you can do about them
WASHINGTON POST
Healthcare Sector Vulnerable To Hackers, Researchers Say
Year-long study shows that healthcare lags other industries in addressing known security problems
NBC NEWS
2012: The Year Malware Surged 'Dramatically'
A look at what happened -- and didn't -- during the year of malware
HELP NET SECURITY
Most Unique Viruses Of 2012
A look at some of the most extraordinary exploits of the past year
WA TODAY
What Criminals Do With Stolen Passwords
A look at how cybercriminals collect information and profit from it
THE HACKER NEWS
Stuxnet Is Back! Iran Reported Another Cyberattack
A power plant and other industries in southern Iran targeted, civil defense official says
TREND MICRO BLOG
Best Practices For Email Autoreplies
Only set out-of-office replies within the organization or whitelist key ones for exernal parties -- bounce message can be used for spammers
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3744
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.
CVE-2013-3743
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 45 and earlier and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.
CVE-2013-2473
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2472.
CVE-2013-2472
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2473.
CVE-2013-2471
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2472, and CVE-2013-2473.



