Best Of Web
Best Of The Web
YOUWEREWARNED
Apple Patches Critical Holes In Safari Browser
Apple released fixes for security vulnerabilities in its Safari and tells to upgrade as soon as possible
SOPHOS BLOG
Sophos Security Threat Report: Mid-Year 2010
Only 6 percent of respondents thought their country was doing enough to protect itself against Internet threats, and more than 60 percent approve of their governments using the Internet for foreign espionage
TREND MICRO BLOG
Protecting Your Router Against Possible DNS Rebinding Attacks
How to defend against attack that combines DNS rebinding and cross-site request forgery to trick the user's browser into communicating with the attack and the home router's administrative console
TAO SECURITY
Project Vigilant Is A Publicity Stunt
Security expert pokes holes in organization's claims to be a stealth membership of 500 people working together
DEVELOPER.COM
Google Hacking Evolves For Defense
New tools could help enterprises identify vulnerabilities more quickly, Black Hat speakers say
WALL STREET JOURNAL
Grid Is Vulnerable To Cyberattacks
Computer networks are vulnerable, Energy Department is warned
FEDERAL COMPUTER WEEK
U.S. Approach To Global Cybersecurity Falls Short, GAO Says
White House needs to improve interagency communication, according to report
ESET THREAT BLOG
Save Your Work! Microsoft Releases Critical Security Patch
LNK shortcut file vulnerability is patched, software giant says
KREBS ON SECURITY
Antivirus Products Mostly Ignore Windows Security Features
Products fail to take advantage of built-in capabilities
V3.CO.UK
Public Gives Approval For Cyberwarfare
Sophos research finds majority happy with state-sponsored attacks
NETWORK WORLD
Meet The Man Who Helped Lamo Turn In Manning, The Wikileaker
Destroying the evidence would have been too risky, says Defcon presenter
THE AGE
Hackers Fool World's Largest Companies Using Smooth Talk
Social engineering contest at Defcon shows how attackers can trick companies into giving up too much data
MICROSOFT SECURITY RESPONSE CENTER BLOG
Microsoft Releases Out-Of-Band Patch
Security Bulletin MS10-046 fixees a vulnerability in the handling of shortcuts that affects all currently supported versions of Windows XP, Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2
CNET
Researcher Detained At U.S. Border, Questioned About WikiLeaks
Jacob Appelbaum, a programmer for the online privacy protection project Tor, arrived at the Newark, N.J., airport from Holland and was detained
WSJ ONLINE
Microsoft Quashed Effort To Boost Online Privacy
Giving automatic privacy to consumers would make it tougher for Microsoft to profit from selling online ads
KREBS ON SECURITY
Texas Firm Blames Bank For $50,000 Cyber Heist
Telephone equipment company attempts to force its bank into a settlement over a cyberattack that cost the company $50,000
H ONLINE
Android Rootkit Demonstrated
Researchers showed off a rootkit for Android called "Mindtrick"
ZDNET
Researchers Peek Inside A Mini Zeus Botnet, Find 60GB Of Stolen Data
AVG discovered 60G of stolen account data from mini ZeuS botnet dubbed Mumba
NEW YORK TIMES
Emirates To Cut Data Services Of BlackBerry
The United Arab Emirates will suspend BlackBerry e-mail and text messaging beginning in October due to its encrypted data system
AFP
Elite U.S. Cyber Team Courts Hackers To Fight Terrorists
"Vigilant" cyber A-Team recruited hackers at Defcon on Sunday -- the group includes 600 volunteers and its secret ranks include technology chiefs at top firms and high-ranking cyberspies
MACWORLD
Bugs & Fixes: What's The Risk With The Citi Mobile Security Flaw
Citigroup's Citi Mobile iPhone app has been updated to fix a security flaw that could expose account numbers, bill payments, and security access codes
GOVINFOSECURITY
Recovering From An Information Security Disaster
Bob Carr, CEO of Heartland Payment Systems, recalls how he felt when he first learned his company had suffered the biggest data breach ever reported
MICROSOFT BLOG
Microsoft To Release Out of Band Release To Address .LNK Flaw
Microsoft on Monday will release a patch for the .LNK bug in Windows that is currently being exploited
ZDNET
U.S. Media Giants Sued Over 'Zombie' Cookies
ABC, ESPN, Hulu, MySpace, and MTV were named in a lawsuit accusing them of violating federal computer intrusion laws due to their use of Flash cookies
NETWORK WORLD
FBI Rings Organizers Over Defcon Contest
The Defcon social engineering contest gets the attention of the feds and the financial services industry's security group
COMPUTERWORLD
Black Hat Gets Its Video Feed Hacked
A security expert was able to view the talks at Black Hat for free, thanks to bugs in the video-streaming service used by the security conference
COMPUTER WEEKLY
Black Hat: GSM Hacking Tools Now Available
Security researcher Karsten Nohl rolled out tools that hackers can use to listen to GSM mobile phone calls
HHS
Department of Health And Human Services Pulls Breach Notification From Hitech Act
HHS is withdrawing the breach notification final rule from OMB review to allow for further consideration
INFOWORLD
AT&T Won't Stop Black Hat Demo Of Cell Phone Eavesdropping
Operator denies rumors that it will step in to stop presentation at conference
THE REGISTER
Smart Meters Pose Hacker Kill-Switch Risk, Researchers Warn
Bad guys could take advantage of ability to turn off power remotely
SEARCH SECURITY
Black Hat: Targeted Network Security Attacks Beating Forensics Efforts
Sophisticated approaches foil companies' layered defenses, researchers say
WIRED
Court Says Privacy Advocate May Publish Social Security Numbers
Federal appeals court tells Virginia attorney general to back off
ECOMMERCE-GUIDE.COM
FTC Leaning Toward Do-Not-Track List For Online Ads
New rules would allow users to opt out of online behavioral tracking
HOST EXPLOIT
Security Lessons From The "Adult" Web
Adult sites pose five to six times the risk of malware, according to study
CNET
DHS Tries To Defuse Privacy Criticism, Asks For Help
Concerns about Internet monitoring and surveillance are unwarranted, Lute says at Black Hat
V3.CO.UK
Black Hat: SSL Is Broken, Conference Founder States
Thirteen years after hacker conference began, customers still can't safely do business online, Moss decries
OFFICE OF INADEQUATE SECURITY
Rite Aid Agrees To Pay $1 Million To Settle HIPAA Privacy Case
One of the nation's largest pharmacies also agreed to take corrective action to improve policies and procedures to safeguard the privacy of its customers when disposing of identifying information on pill bottle labels and other health information
FBI
Cyber Chief Describes Efforts To Combat Cyber Crime On Social Networking Sites
Gordon Snow testifies before House Judiciary Subcommittee on Crime, Terrorism, and Homeland Security about cybercrime threats to social engineering sites
F-SECURE BLOG
Rogue AV Masquerades As A Firefox/Flash Update
The bad guys are now pushing rogueware to users via a Firefox "Just Updated" page
THREAT POST
Persistent, Covert Malware Causing Major Damage
Black Hat researchers show how stealthy, targeted attacks are working, including one on a sports bar in Miami that used a custom-designed rootkit
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



