Best Of Web
Best Of The Web
THE JERUSALEM POST
Hackers Attempt To Crash Jerusalem Post Website
Flotilla incident spurs pro-Palestinian cyberattackers to action
WASHINGTON POST
Hill Staffer Bhalotra To White House Cyber Security Team
Congressional expert will become senior director for cybersecurity, working for Howard Schmidt
THE NEW NEW INTERNET
University Of Akron Student Pleads Guilty To Launching Botnet Attacks
University student used school computers to gain access to botnet and spread malware
SEARCH SECURITY
Federal Agencies Scrambling On DNSSEC Implementation
Despite threats of DNS poisoning, it took some agencies months to find all of their DNS servers
DAILY NEWS LOS ANGELES
Hackers Using More Sophisticated Methods To Obtain Personal Information
Scams becoming more frequent �� and harder to detect
JACKSONVILLE BUSINESS JOURNAL
Identity Theft Protections Due June 1
"Red flag" rules for identification, detection, and response to patterns that indicate ID theft go into effect on June 1
PC PRO
Microsoft Man: 'My Job Is To Destroy IE 6'
Head of the IE business group says part of his job is to get the outdated Internet Explorer 6 use "down to zero as soon as possible"
THREAT POST
Adobe May Change To Monthly Patch Release
After moving to a quarterly patch release schedule that coincides with Microsoft's Patch Tuesday, Adobe is considering more frequent patches to get fixes out faster
CNET
Privacy Groups Assail Facebook Changes
New privacy setting changes don't go far enough, they say, some calling for "opt-in" versus "opt-out" approach that Facebook uses
CNBC
Cyberattackers Are Using IPv6 To Tunnel Into Networks
Expert says IPv6 comes with security risks, including difficulty in spotting vulnerabilities in the protocol's implementations
CERT BLOG
CERT Basic Fuzzing Framework
CERT rolls out free framework for running automated, "dumb" fuzzing tests
IMPERVA BLOG
Three Things Facebook Should Do To Protect Privacy
Facebook should provide audit trails, make defaults the most conservative options, and provide de facto level of privacy to users
THE BREACH BLOG
Tri-City Medical Center Investigating Possible Facebook Breach
Oceanside, Calif., medical center says it's looking into possible breach of patient privacy over Facebook
CHARLOTTE OBSERVER
Personal Data On 5,200 City Of Charlotte Employees Lost
Consulting firm loses two DVDs containing Social Security numbers and other personal data
GOVERNMENT INFO SECURITY
Department Of Defense Mulls Defending Key Private IT Systems
Einstein 2, Einstein 3 systems might be made available to essential contractors
ADOBE
Security Update Available For Adobe Photoshop CS4
Patch is designed to fix a critical vulnerability, company says
STOREFRONT BACKTALK
American Express Form Spent Part Of Tuesday Sending Card Data In The Clear
Insecure form is fixed in less than four hours, company says
ABOUT.COM
VoIP-Aided Security Threat: Telephony Denial Of Service
Hackers attack users' personal accounts on one side, then flood their phones with calls to prevent user action
ZDNET
Hackers Targeting Phone Systems, Warn Australian Police
Security pros should do penetration tests on PBXs or risk compromise, officials say
WALL STREET JOURNAL
Regulators, Law Enforcement Coordinate To Fight Fraud
New initiatives are designed to help unify the effort to stop financial scams
PHILADELPHIA INQUIRER
Lower Merion's Laptop Tracking System Easily Hacked
Seattle security firm says it needed just hours to hack the system and could potentially have watched students via Webcams
THREAT POST
Google Patches 'High Risk' Chrome Flaws
Google has pushed an automatic Chrome browser update to fix multiple security issues, including denial-of-service flaws
PC WORLD
Lifelock Worries After Employee Data Leaked To Web
Lifelock asked the Phoenix New Times to remove a police report from its site that includes a redacted Social number of a Lifelock employee
H ONLINE
Vulnerability In IPhone Data Encryption
Even with encryption in place, new research shows you can gain access to photos and audio, for instance, on an iPhone via Linux
DATA BREACHES.NET
Wells Fargo Reports Two Insider Breaches In 6-Month Period
A Wachovia Security stock broker took personal information on more than 1,000 New Yorkers with him when he left the firm, and a former Wells Fargo employee was found to have documents with client names, dates of birth, SSNs, mortgage account numbers still in his possession
COMPUTERWORLD
Bank, Customer Settle Suit Over $800,000 Cybertheft
PlainsCapital Bank and Hillary Machinery have reached a settlement over funds stolen from the business' account by cyberthieves
THE REGISTER
Facebook Forces Users To Expose Or Remove Connections
If users don't link to education, work, location, employer, and likes pages with connections made public by default, Facebook will remove that data from their profiles
SOPHOS BLOG
Scaremongering Scientist Claims To Have Infected Himself With Computer Virus
British scientist at the University of Reading has implanted an RFID chip containing what he claimed to be virus code into his hand
THE LAST WATCHDOG
Heartland Payment Systems Asks Merchants To Help Stop Cyberthieves
Heartland is asking its merchant customers to purchase a new "E3" credit card-swiping terminal that encrypts payment card magnetic stripe data more quickly than existing systems
MSNBC
Man Sentenced In Scientology Cyberattack
Year in prison for member of group that accuses church of Net censorship
U.S. ARMY
Social Networks Open Door To Data Leaks, Cyberattacks
Email attachments are no longer the vector of choice for hackers and fraudsters, Army says
PRESS TV
Iran To Boost Cyberwar Deterrence
Top general says country needs to be ready for online attacks
STOREFRONT BACKTALK
What Will It Take To Make Chip-And-PIN Happen In The U.S.?
Despite push by Wal-Mart, some experts fear that government intervention may be necessary
CIO
Data Breaches Not Among Top Concerns For Tech Firms
Data security ranks low on list of risks, according to new survey
COMPUTERWORLD UK
IBM Hands Out USB Drives Stuffed With Malware
Security conference delegates get more than they bargained for
SCAM DETECTIVES
Beware "Tabnapping" �� A New Kind Of Phishing Scam
When users click away from a site, hackers take over the tabs -- and trick the user into logging in again
CIOL
Network Security: Coming Of Age
Market continuing to expand, experts say
AFP
China And Canada Among Top On US Piracy Watch List
U.S. legislators have accused Canada, China, Mexico, Russia, and Spain of "robbing Americans" by failing to crack down on piracy of movies, music, video games, and other copyrighted works
KREBS ON SECURITY
Revisiting The Eleonore Exploit Kit
Attackers care more about whether your third-party browser add-ons and plug-ins are out-of-date and exploitable
THE WASHINGTON POST
From Facebook, Answering Privacy Concerns With New Settings
Facebook founder responds to backlash over privacy policy, saying the firm will provide simpler-to-use controls and an easy way to turn off all third-party services
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



