Best Of Web
Best Of The Web
GOVINFOSECURITY
GAO To White House: Do More On R&D
The Government Accountability Office says the White House must do a better job in setting a prioritized national cybersecurity R&D plan
IT WORLD
Apple Says 400 iTunes Accounts Hit With Fraudulent Purchases
Apple says iTunes servers weren't hit, but users should change their iTunes passwords
HOST EXPLOIT
India Beats Netherlands, Brazil And Germany In Security World Cup
The U.K. came fifth with 107 attacks per 1000 PCs, more than double the level of 52 attacks per 1,000 PCs in India
EDUCATIONAL SECURITY INCIDENTS
Breached University Of Hawaii Server Contained Information On 53,000
University of Hawaii officials say a May breach exposed personal information on faculty, staff, and visitors doing business with its Parking Office -- as far back as 1998
SECURITY TRACKER
BlackBerry OS Unspecified Hotspot Browser Flaw Lets Remote Users Deny Service In Certain Cases
New vulnerability reported in BlackBerry OS could let an attacker wage a man-in-the-middle attack and crash a target application
THREAT POST
New Trojan Disguised As Windows IME
New attack technique lets attackers inject Trojan code onto victims' machines by disguising it as a Windows input method editor
BBC
China Jails US Geologist For Stealing State Secrets
A Chinese-born American geologist has been sentenced to eight years in jail in China for stealing state secrets -- he helped negotiate the seal of an oil industry database to his American employershelped
CRN.AU
FedEx Loses 138,000 Patient Records
CDs containing patient data from New York City's Lincoln Hospital were lost en route from bill-processing supplier Siemens Medical Solutions
EDUCATIONAL SECURITY INCIDENTS
Virus On Oklahoma University Laptop May Have Exposed Student Data
University of Oklahoma is notifying students after a laptop containing student information, including social security numbers, was infected with the Zeus Trojan
SOFTPEDIA
Upset Security Researchers Start Releasing Microsoft 0-Days
Security researchers unleash exploitation code for an unpatched Windows local privilege escalation vulnerability, citing their discontent with how Microsoft treated the Google engineer blamed for disclosing a critical Windows bug publicly last month
TECH DAILY DOSE
Senators Urge Obama To Back Planned Cybersecurity Legislation
Seven Senate leaders have urged the President to support their planned legislation for protecting critical information technology systems from attacks
SIFY.COM
British Teenagers Held For Online Bank Fraud
Two British teenagers were arrested for selling bank account information they stole -- 65,000 were hacked
ENGADGET
Apple Responds On iTunes Fraud, Vaguely Confirms Said Fraud
Rogue developer and his apps removed from App Store for violations, including fraudulent purchasing patterns
STOREFRONT TALKBACK
VISA Revokes PCI Approval From Ingenico PIN Pads Following Breach
Visa has ripped the PCI approval certification from two Ingenico PIN entry devices after data breach
FORBES BLOG
Five Critical Flaws In The Lieberman-Collins Cybersecurity Bill
Passed as-is, security experts say the Senate bill won't protect U.S. critical infrastructure from being compromised
SOFTPEDIA
Adobe Investigates/Launch Fix Workaround
Adobe is looking into a circumvention method disclosed by a Vietnamese security researcher that bypasses its new security patch
SOFTPEDIA
Spanish Firm Investigated For Selling Rigged Accounting Software
Spanish police have detained the managers of a company selling customized accounting software for SMBs that allegedly was rigged to fail at certain intervals so that customers would have to pay for maintenance
AVEKSA BLOG
Access Governance Issues Identified At FEMA
FEMA's access management troubles are part of a bigger trend of government agencies losing control of access-related issues in their networks
SECURITY WEEK
New Tool Reveals Internet Passwords
A Russian software firm has released a password-cracking tool that reveals cached passwords to websites in Internet Explorer, and mailbox and ID passwords in Outlook, Windows Mail, and Windows Live Mail
EMARKETER
Privacy Concerns Fail To Slow Social Activity
Although more than three-fourths of social media users in the U.S. have some concerns about privacy and security while using social media, that hasn't affected usage
GULF NEWS
Big Security Lapses Make Mideast Firms Easy Prey
A Google search and the use of an appropriate keyword string provides access to the Web server of some of the largest companies in the Middle East, German Web hacking experts say
BBC
Hackers Target Microsoft Windows XP Support System
High-tech criminals are escalating attacks on unpatched bug, researchers say
GOVERNMENT COMPUTER NEWS
'Encryption On A Chip' Raises Hopes For Better Security
Intel working on building random-number generation into future computer chips
THE AGE
Chinese Government Set To Reject Google Compromise
Search engine site will go dark in China if government refused to renew its license
GOVERNMENT INFO SECURITY
Top 10 Skills State CISOs Need To Succeed
Technological know-how isn't one of the 10, report says
THE REGISTER
Whirlpool Down Again After DDoS Intensifies
Australian ISP continues to be hit by persistent attack
SEARCH SECURITY
Perimeter Defenses Deemed Ineffective Against Modern Security Threats
What do you do when intruders are already inside your network? A panel discusses the options
HELP NET SECURITY
Virus Production From Russia Increases Again
Russia now responsible for more than 7 percent of world's malware, researchers say
WSB TV
Breach At Blue Cross/Blue Shield Of Georgia May Affect More Than 70,000
Error occurred during upgrade of Web applications, company says
BKIS BLOG
Adobe Fix Still Allows Escape From PDF
The new security updates for Adobe Reader and Adobe Acrobat (APSB10-15) are not working properly, researchers say
FACEBOOK BLOG
Applications Ask, You Receive: Simplified Permissions Launch
New Facebook privacy feature ensures apps access only public profile info
WCSH 6
University of Maine Investigating 8 Year Security Breach
Personal information from 4,585 students who sought mental health services from the campus counseling center was exposed in a breach that includes records dating back to 2002
GOV INFOSECURITY
NIST Revises Security Controls Bible
New document helps agencies implement continuous monitoring of their IT systems as they move away from traditional paper-based compliance rules under the Federal Information Security Management Act
WIRED
White Hat Uses Foursquare Privacy Hole To Capture 875K Check-Ins
A privacy hole on Foursquare's venue page that left the "who's been here" section exposed has been fixed
COMPUTERWORLD
Destination Hotels Card-Processing System Hacked
Guests who recently stayed at 21 of the resort's 30 hotels may have been victimized
FEDERAL COMPUTER WEEK
Meet The FBI's New Top Cyber Cop
Gordon Snow, FBI assistant director in charge of the bureau's Cyber Division, says citizens should be aware that there's no such thing as a secure system and security starts with the individual
COMPUTERWORLD
Google Steals Security Page From Mozilla's Firefox
Google will block outdated plug-ins from launching in its Chrome browser, the company said Monday
WIRED
FTC: Scammers Stole Millions Using Micro Charges To Credit Cards
Tiny charges add up to nearly $10 million, commission says
THE REGISTER
Rancid IE6 "More Secure" Than Chrome And Opera, Bank Says
Chase will support aging browser but drop support for Chrome and Opera
YAHOO! NEWS
Security Glitch Exposes Wellpoint Customer Data
Insurance firm notifies 470,000 customers about glitch in online program
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
- Three Principles to Improve Data Security and Compliance
- Aligning IT with strategic business goals: A proactive approach to managing IT risk to your business
- Connecting the Dots: Are You Seeing the Complete Big Data Picture?
- How crowdsourced testing has changed the game for innovative software companies
- Ensuring Your Apps Work in the Real World
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3661
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
CVE-2013-3660
The EPATHOBJ::pprFlattenRec function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPa...
CVE-2013-3634
The SNMPv3 functionality on Siemens Scalance X200 IRT switches with firmware before X-200IRT 5.1.0 does not properly validate credentials, which allows remote attackers to execute arbitrary SNMP commands by leveraging knowledge of a username.
CVE-2013-3633
The web interface on Siemens Scalance X200 IRT switches with firmware before X-200IRT 5.1.0 relies on client-side privilege checks, which allows remote authenticated users to execute arbitrary commands via unspecified vectors.
CVE-2013-1022 (quicktime)
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted mvhd atoms in a movie file.


