Best Of Web
Best Of The Web
GOVERNMENT INFO SECURITY
Ten R&D Cybersecurity Initiatives Congress Seeks
Senate Bill outlines wish list of areas to be studied
PC WORLD
Clock Winding Down On Windows XP SP 2
Older OS will soon fall off the list of versions that are tested for vulnerabilities
ABC NEWS
10 Of The Top Data Breaches Of The Decade
How does the recent iPad breach compare? Take a look at this list
SEARCH SECURITY
Next CyberStorm Exercise To Stress International Cooperation On Security
CyberStorm III to take place in September with greater overseas presence
THE NEW NEW INTERNET
Taliban Hacked, DoD Starts Cyber Offensive?
Taliban-endorsed site says it is subject of "infiltration operation"
VERACODE ZERO DAY LABS BLOG
Website Vulnerability Research And Disclosure
AT&T website vulnerability find part of a growing trend for vulnerability disclosures where bugs exist in code running on one organization's Web server and makes disclosure benefits issue different
H ONLINE
Microsoft Installs Another Firefox Add-On Without Asking Users' Permission
Search Enhancement Pack update included and installed a Firefox add-on -- without asking users whether they wanted it
H ONLINE
IRC Server Had Backdoor In Source Code For Months - Update
Open source IRC project devel-opers say file servers were compromised months ago, backdoor inserted
NEWS 10
Sacramento, Folsom, Placer County Detectives Find Credit Card Skimmers At Gas Stations
Credit-card skimming devices were found in various gasoline pumps in California counties; authorities are searching for the perpetrators
NEXTGOV
Bill: President Could Order Companies To Deploy Security Fixes
A Senate cybersecurity bill introduced last week would give the President authority to order companies to patch software or block incoming traffic from a particular nation
COMPUTERWORLD
Guidelines Released For Antivirus Software Tests
Could help put an end to long-running disputes about different testing methodologies
HA.CKERS.ORG
Turning XSS Into Clickjacking
Prototype uses generic reflected XSS attack to mount a clickjacking attack
SACRAMENTO BEE
Famous Hacker Finds Himself Infamous, In Some Quarters
Adrian Lamo says he has received death threats since he told federal agents he suspects a U.S. soldier leaked classified information
BBC NEWS
'Shady' Porn Site Practices Put Visitors At Risk
Researchers found that nearly four percent of porn sites contain malware, and many use questionable practices to keep visitors on their sites
SECURELIST
Offensive Attacks And The World Cup 2010
An attack on the Indonesian government Web server that defaced it with World Cup activities demonstrates a different kind of hacktivism, one that is based on sports competition motivations
SECRECY NEWS
Grid Protection and Cybersecurity
The House of Representatives has passed the Grid Reliability and Infrastructure Defense Act, a bill that would authorize the Federal Energy Regulatory Commission to issue emergency orders to protect critical electric infrastructure and to address current and potential vulnerabilities
THE DAILY BEAST
Pentagon Manhunt
The DoD is looking for the founder of the secretive Wikileaks website amid worries he may be about to publish secret, classified State Department cables
NEWSINFO
S. Korean Government Website Hit By Cyber Attacks
South Korea's intelligence service is investigating an attack on its government website by hackers traced to China
ADOBE
Adobe Patches Flash Player Flaw
A critical vulnerability in Adobe Flash Player 10.0.45.2 and earlier versions that could cause a crash and allow an attacker to take control of the affected system was patched yesterday by Adobe
FEDERAL COMPUTER WEEK
DHS Would Be Cyber Power Center Under Lieberman/Collins Proposal
Senators on Homeland Security Committee introduce comprehensive cybersecurity bill that sets up DHS center to protect critical infrastructure from attack
MALWARE CITY
Keyloggers Posting on Webpages
Several keystroke logger entries have been accumulating on Pastebin.com, suggesting a massive keylogger infestation
THE REGISTER
Bug Gives Attackers Complete Control Of Windows PCs
Windows Help and Support Center is vulnerable, researcher says
TRENDLABS MALWARE BLOG
Bye, Bye, Tequila Botnet
Emerging botnet appears to have been taken down by its operators, but new Mariachi botnet is discovered
STOREFRONT BACKTALK
Forgotten Apps Pose PCI Danger, Visa List Shows
Outdated applications may be still running--and still vulnerable, credit giant warns
MICROSOFT MALWARE PROTECTION CENTER
MSRT Targets Another Fake
Microsoft looks to out scareware program formerly known as Fakeinit
KOREA TIMES
Military Leaders Warn Of North Korean Cyber Attack
South Korean networks may be targeted during G-20 Summit in November, officials say
WALL STREET JOURNAL
AT&T Discloses Breach Of iPad Owner Data
Security hole in website may have disclosed customers' email address information, company says
MICROSOFT SECURITY RESPONSE CENTER
Windows Help Vulnerability Disclosure
Proposed workarounds could be easily circumvented, software giant says
CISCO BLOG
So Long V4! Here's To V6 Being Secure!
Criminal activity on IP version 6 is on the uptick, Cisco researchers say
COMPUTERWORLD
After Google Hack, Warnings Pop Up In SEC Filings
Tech companies are increasingly warning shareholders they may be materially affected by hacking attempts designed to take valuable intellectual property
TWEET SMARTER
Twitter's New Link Shortener Give You LESS Characters��But More Security
Twitter's new t.co link shortener automatically checks the safety of URLs
THE STAR NEWS
Cops Bust SMS Scam Ring With Arrest Of 26
A notorious multinational SMS scam syndicate that bilked victims of money after convincing them they had won prizes has been arrested
HEALTHCARE INFOSECURITY
Encrypted Laptop Stolen While In Use
An encrypted laptop in use by a hospice employee during a home visit to a patient was stolen while the device was on and an electronic records system was open
P2PNET
Does Limewire Owe The RIAA $1.5 Trillion?
A judge has ruled that LimeWire infringes copyrights of music, and one RIAA advocate wants LimeWare to pay $1.5 trillion for the alleged illegal downloads
COMPUTEWORLD UK
Insecure Online Sites Compromise Passwords For Rest Of Web
A Cambridge University study of security at password-protected websites found weak passwords in lower-security sites hurt protections at higher-security sites because users typically reuse passwords
GOVINFOSECURITY
IG Questions DHS Execution of Active Directory
The Department of Homeland Security's Windows Active Directory implementation at its headquarters didn't comply with the department's security guidelines, government auditors say
SUCURI SECURITY BLOG
Mass Infection Of IIS/ASP Sites
Several websites, including that of The Wall Street Journal, were hacked this week and hit with a malware script pointing them to a malicious site
SOPHOS
Olympus Stylus Tough Camera Carries Malware Infection
New camera could infect attached PCs, company warns
COMPUTER ECONOMICS
Malicious Insider Threats Greater Than Most IT Executives Think
Perceptions of risk often don't match reality, new report says
PC WORLD
Bank Of America Call Center Worker Pleads Guilty To Data Theft
Employee admits he stole sensitive client information and tried to sell it for cash
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



