Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173


Best Of The Web

WASHINGTON POST.COM
PC Invader Costs Ky. County $415,000
Ukraine-based cybercriminals stole $415,000 from Bullitt County, Kentucky, with the help of malware and dozens of "mules" in the U.S.

SANS INTERNET STORM CENTER
0-Day In Microsoft Directshow (Msvidctl.Dll) Used In Drive-By Attacks
A zero-day exploit in Microsoft DirectShow is being actively exploited in drive-by attacks using thousands of newly compromised Websites

THE H SECURITY
Security On Symbian Mobiles: Early Signs Of Crumbling
Researcher releases paper that shows how to find and exploit vulnerabilities in Symbian and Symbian applications

ECONSULTANCY
Facebook Threatens National Security
Family details of the incoming Chief of the British Secret Intelligence Service were posted on Facebook by his wife, posing a serious security threat

NEWS ABOUT FRAUDS
Australians Warned On Card Fraud After $6m Bust
Seven people were charged for allegedly running a $6 million credit card scam using stolen personal information to create fake credit cards, Medicare cards, driver's licenses

TECHWORLD
Malware Authors Hit By Recession, Too
German software security company G Data says the number of unique malware signatures dropped by 30 percent between May and June -- mainly due to the economic forces

MCAFEE AVERT LABS
McAfee's July Spam Report Released
The most popular subject line in six continents this quarter was "Viagra"

MSN MONEY CENTRAL
When A Parent Steals Your Identity
Parents victimizing their own kids' identities to establish credit or set up fraudulent accounts is more common than you'd think

SECURITY FOCUS
Juniper Pulls Talk On ATM Vulnerabilities
Researchers agree to withhold disclosure of flaws until vendor can fix them

NETWORK WORLD
New Trojan Puts Sneaky Twist On Click Fraud
Malware invisibly funnels search queries through its own site, cheating Google out of money

CHINA DAILY
Plug Not Pulled On Green Dam
Despite delay, China says controversial Internet filter requirement will go forward

COMPUTERWORLD UK
Forrester: Don't Take Cloud-Based Mail Security At Face Value
Users should ask hard questions before choosing a provider, analyst firm says

BCS
Cybercriminals Target New Harry Potter Film
Fans should wait until legitimate sources are available before downloading film, security firm says

IT-DIRECTOR.COM
Finjan: Second Indian Government Website Hacked By Cybercriminals
New attack takes place despite stepped-up security

NETWORK WORLD
Cybersecurity Boondoggle?
Developments suggest federal efforts to promote cybersecurity may already be out of control

WASHINGTON POST
Obama Administration To Involve NSA In Defending Civilian Agency Networks
Department of Homeland Security chief says NSA's involvement will be "guided"

BBC
China Delays Internet Filter Plan
China puts on hold a controversial plan requiring all new computers sold in the country to be equipped with Internet filtering software

SUPERMARKET NEWS
Heartland Receives Encrypted Card Data From Retailer
Heartland says it has completed the first phase of an end-to-end encryption pilot project designed to enhance its security

HEISE ONLINE
Swatting Phreaker Swatted And Heading To Jail
A 19-year-old phreaker was sentenced to more than 11 years in prison for making phony emergency calls that sent special police units or SWAT teams to investigate

INFORMATIONWEEK
Zeus Trojan Variant Steals FTP Login Details
Malware was found harvesting FTP account information from compromised computers by Prevx, which says the number of affected accounts is roughly 74,000

THE REGISTER
Mitnick Site Targeted In DNS Attack On Web Host
Kevin Mitnick's Website is compromised by attackers who accessed a domain name server maintained by the site's Web hosting company, redirecting visitors to porn

DEFENSE SYSTEMS
New Proposal Would Require Cybersecurity Workers Be Certified
Senate measure would require national licensing, certificatio,n and periodic recertification program for cybersecurity professionals

GOOGLE
Google Spam Report
Old-style spam surged in the second quarter, according to new Google spam email data

SOPHOS BLOG
Michael Jackson Email-Aware Worm Hits Inboxes
Email that claims to come from sarah@michaeljackson.com says an attached ZIP file contains secret songs and photos of the King of Pop

RISKY BIZ
Juniper Networks Gags "ATM Jackpot" Researcher
A live ATM machine hack by a Juniper researcher scheduled for Black Hat next month has been pulled at the request of the ATM's manufacturer

MOZILLA
New Content Security Policy Revealed
Mozilla is proposing a new mechanism to combat cross-site scripting that browsers can choose to enforce

SPYWARE GUIDE
Hackers Target Neopet Users
A new malware scheme targets kids' social network

SCHNEIER ON SECURITY
The Problem With Password Masking
Clear-text passwords reduce errors, and shoulder-surfing isn't very common, Schneier says

INFORMATIONWEEK
Web Filtering Company Reports Cyber Attack To FBI
Solid Oak Software, which claims China's Green Dam software illegally uses its code, says it's under cyber attack

SECURITY PRO NEWS
MessageLabs Gives Botnet Rundown
Cutwail botnet is responsible for 45 percent of all spam

FEDERAL COMPUTER WEEK
Improved FISMA Scores Don't Add Up To Better Security, Auditor Says
GAO official says metrics don't measure how well security controls are established in agencies

WIRED
Superhacker Max Butler Pleads Guilty
Butler admits to stealing nearly 2 million credit card numbers from banks, businesses, and other hackers, and tallying up $86 million in fraudulent charges

THE NEW YORK TIMES
U.S. And Russia Differ On A Treaty For Cyberspace
Russia wants an international treaty akin to one for chemical weapons, and the U.S. wants improved cooperation among international law enforcement agencies

SOFTPEDIA
Cybercrooks Target Harry Potter Fans
Malware is being sent via a new Harry Potter movie streaming application

VNUNET
Microsoft Issues Critical Sharepoint SP2 Fix
Microsoft has released a patch for a licensing flaw in its SharePoint software

ZDNET UK
G20 Protesters Hit Gov't With Email Attacks
The U.K. government suffered targeted email attacks by G20 protesters in April, according to MessageLabs, which handles the government's email security

BNET
Data Privacy Rules Coming As Massachusetts Trumps The Feds
A bill under consideration by Congress may be moot due to a Massachusetts regulation with the same basic provisions

MASHABLE
Warning: Twittersblogs Is Another Twitter Phishing Scam
Hundreds of tweets have spread so far linking to a phony subdomain of twitterblogs.com

ECOMMERCE TIMES
New ICANN Chief Eager To Mediate Internet Policy Wars
Former U.S. director of cybersecurity may have to referee for warring factions in the Internet policy front

SOPHOS BLOG
Britney Spears Isn't Dead -- But Her Twitpic *Is* Hacked
An attacker posted a tweet to Spears's Twitter stream earlier today that she had died


Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)