Best Of Web
Best Of The Web
GOVERNMENT INFO SECURITY
Proof: Continuous Monitoring Does Work
Agencies see results after moving from paper process
FAS PROJECT
FBI Has Found 14 Intelligence Leak Suspects In The Last Five Years
Malicious iFrame loads exploit cocktail
WIRED
NSA Gets Extremely Geeky After Dark, New Docs Show
Newly opened documents show that NSA geeks often join technology clubs after hours
HACKING EXPOSE
ICANN Chief Calls For Co-operation On Internet Security
Beckstrom calls for nations to work more closely together to protect DNS
COMPUTERWORLD
States Launch Joint Probe Of Google Wi-Fi Snooping
As many as 30 states may join investigation led by Connecticut attorney general
HEALTHCARE INFO SECURITY
Boards Losing Focus On Security
Top executives are too far removed from security and privacy decisions, and the gap is widening, study says
BCS
People Receive Scam Email Every Seven Seconds, Report Says
Email account recipients are targeted at a rate of about 420,000 per hour, according to expert
VERACODEE
Bet Your Career On Developers, Not Tools
Security pros wrestle with the pitfalls of on-premises code testing
TECH CRUNCH
Woops, Google's Street View Cars Collected Email Passwords And More Sensitive Data
Wi-Fi data collector picks up sensitive information from unprotected systems
DEPARTMENT OF HOMELAND SECURITY
US-CERT Makes Progress, But Hiring And Strategic Planning Still Needed
Report says US-CERT has hired only about half of the security people it is authorized to bring in
iPAD WEEKLY
iPad Hacker Released On Bail, Case Moved To Newark
Alleged hacker was arrested for drugs, but FBI now handling the case via cybercrime unit
CHICAGO TRIBUNE
Supreme Court Rules For Employer In Text Messaging Case
If you're sending romantic messages over the company messaging system, then don't expect them to remain private, court says
TORRENT FREAK
Three Arrested In Connection With 'Dark Side' File Sharing Servers
Antipiracy case might be the biggest ever in Europe, report says
COMPUTERWORLD
Supreme Court Ruling Lets Employers View Worker Text Messages With Reason
U.S. Supreme Court today ruled employers have the right to search through text messages, including personal ones, sent by workers if they have reason to believe that workplace rules are being broken
ABC NEWS
Facebook '09 Revenue Neared $800 Million
Facebook's growth in users and advertisers boosted 2009 revenue to as much as $800 million, according to two sources
SOPHOS BLOG
Apple Secretly Updates Mac Malware Protection
Apple's 10.6.4 operating system this week silently updated the malware protection built into Mac OS X to protect against a backdoor Trojan
COMPUTER SCIENCES SCHOOLS.NET
10 Convicted Computer Criminals
Profiles on high-profile hackers who performed computer crime -- including Kevin Mitnick, Robert Tappan Morris, Gary MacKinnon, Kevin Paulsen
DETROIT NEWS
Mortgage Fraud Ring Hit $100M, FBI Says
Local crime ring ran a mortgage fraud scheme that cost lenders more than $100 million and in four years involved 500 fraudulent loans and roughly 180 homes
F-SECURE WEBLOG
XSS Update
F-Secure hit with cross-site scripting vulnerability disclosure, which would have let an attacker execute JavaScript
UPI
Palin E-Mail Hacker Sentencing Date Set
David C. Kernell, former University of Tennessee student, will be sentenced on Sept. 24
KREBS ON SECURITY
Sophisticated ATM Skimmer Transmits Stolen Data Via Text Message
A look at cell phone-based skimmer that relays information via text message
COMPUTERWORLD
LinkedIn Communications At Center Of Unprecedented Lawsuit
Does networking with other professionals constitute a breach of a noncompete agreement? Case may decide
NEW YORK TIMES
Internet File Sharing Service Is Sued By Music Publishers
Limewire is accused of copyright infringement, may be held liable
TRENDLABS MALWARE BLOG
Months-Old Skype Vulnerability Exploited In The Wild
Older versions of Skype particularly vulnerable to malware, including Zbot, researchers say
CNN
U.S. Vulnerable To Cyber Threats, Experts Warn
BP oil spill could be a wake-up call for cyberdefense, former DHS official says
SLASHGEAR
MasterCard Trialling Smart Credit Cards With Display And Keypad
New card could help improve card security, company says
SEARCH SECURITY
How Google Used DNS Log Analysis To Investigate Aurora Attacks
A look at the incident response process in one of the industry's most infamous hacks
INFOSECURITY-US
Medicare Drug Plan Rebates Invite Data Theft Scammers
Cybercriminals will likely try to ride the rebate wave, experts say
COMPUTERWORLD UK
Major Boost For Domain Name Security System On The Internet
First cryptographic transmission sent; DNSSEC capability coming soon
TECHEYE
Ipad 'Hacker' Arrested On Drugs Charges
Andrew Auernheimer, who heads up Goatse Security, the research group that exposed a hole in AT&T's website that revealed iPad customers' personal data, was taken into custody for the FBI under drug charges
THE REGISTER
Researchers Probe Net's Most Blighted Darknet
A darkspace -- unused IP address space -- region of the Net is four times more "polluted" than any other, researchers find
FORBES.COM
One Man's Quest To Foil Hackers
Robert Carr, founder and CEO of Heartland Payment Systems, is urging credit card companies to force their other credit card processors and merchants to do more than use firewalls and updated antivirus software
HELP NET SECURITY
420,000 Scam Emails Sent Every Hour
More than 420,000 scam emails are sent every hour in the U.K., a new report says, and Brits were targeted by 3.7 billion phishing emails in the past 12 months
V3
Analysts Report Boom In Virtual Security
Virtualized security market has grown 119 percent in the first quarter of this year, according to Infonetics Research, and is expected to grow to nearly $16 billion by 2014
ARS TECHNICA
From Post Office To 'Net: FBI's Most Wanted Cybercriminals
Some of five date back to 1996 and include Nigerian, U.S. suspects
H ONLINE
Apple Releases Mac OS X 10.6.4 Update
Patches fix 28 security holes, including some that can be exploited to hijack a user's system
HOST EXPLOIT
Millions Of Risky Over-The-Phone Credit Card Transactions To Be Safeguarded By Simple New British Invention
A device developed by British firm could eliminate theft of customer payment data exchanged over the phone
REUTERS
Police Arrest 178 In Global Credit Card Scam
Detainees also suspected of sexual exploitation and armed robbery
INFO SECURITY
AT&T Sues Goatse For Stealing iPad Customers' Data
Group allegedly stole 100,000 email addresses from telecom giant's servers
SOPHOS
Tavis Ormandy, Are You Pleased With Yourself? Website Exploits Microsoft Zero-Day
Google engineer disclosed flaw just five days after discovering it
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



