Best Of Web
Best Of The Web
THREAT POST
Secunia Flags 'Highly Critical' Safari Zero Day Flaw
A zero-day vulnerability in Apple's Safari browser could expose millions of Windows users to drive-by download malware attacks, according to Secunia
SAN JOSE BUSINESS JOURNAL
Facebook Hires Former FTC Chairman Tim Muris
Facebook recruited Muris as its lawyer in the wake of government and industry pressure over its privacy policies
WIRED
Coder Journeys From Wall Street To Prison
Stephen Watt, who wrote the packet-sniffing program for convicted hacker Albert Gonzalez, begins his two-year prison term this week
KREBS ON SECURITY
Visa Warns of Fraud Attack From Criminal Group
Visa told financial institutions an organized criminal group plans to attempt to fraudulent payments through a merchant account in Eastern Europe
ROCKET.LY BLOG
Top Ten Reasons You Should Quit Facebook
Included on the top 10 list: Facebook's terms of service are one-sided,and it's difficult to actually completely delete a Facebook account
PC WORLD
Palin E-Mail Snoop Found Guilty On Two Charges
A federal has convicted David Kernell, 22, of two charges in connection with the 2008 episode in which he accessed the personal Yahoo e-mail account of then-Republican vice presidential candidate Sarah Palin
MICROSOFT SECURITY RESEARCH CENTER BLOG
Update On MS10-016 For Microsoft Producer
Microsoft has released a new version of Microsoft Producer that fixes a bug announced in MS10-016
SECURITY WEEK
U.S. Naval Academy Wins Cyber Defense Competition
The U.S. Naval Academy won the National Security Agency's 10th Annual Cyber Defense Exercise (CDX) last month
AVG BLOG
Treasury Website Hacked
For a short period of time, two treas.gov websites were hacked and reaching out to an attack site in Ukraine
THE ORANGE COUNTY REGISTER
St. Jude Patients' Data Stolen On Computers
Private information on about 22,000 patients is at risk in the wake of theft of 22 computers from St. Jude Heritage Healthcare
TUAW.COM
Ipad Jailbreak Released, Works On IPhone And IPod Touch
The "jailbreak" proof-of-concept has been released for the iPad, iPhone, and iPod Touch
KSL.COM
Computer Consultant To Spend 5 Years In Prison For Fraud
Utah County man hired to help four credit unions with their computer upgrades is heading to prison for stealing close to $2 million from the credit unions
PC WORLD
US Air Force Phishing Test Transforms Into a Problem
Security pros at Guam Air Force base's 36th Communications Squadron had to send a clarification notice on Monday after an in-house phishing exercise worked a little too well
SECURE COMPUTING
Warning: Why Your Internet Might Fail On May 5
Network managers are being urged to run a series of checks on their routers and firewalls to ensure their users will still be able to connect to Internet sites in the wake of the first phase of DNSSEC rollouts
TECHEYE
Teen Hacker Gets A Year's Probation
A teen who bought down Sony's gaming network has been sentenced to a year's probation, 250 hours of community service, plus $5,000 in damages
HELP NET SECURITY
Majority Unaware Of How Sensitive Data Is Stored Online
Most U.S. citizens are unaware of how their online data is stored and who secures it, according to a Business Software Alliance (BSA) survey; 60 percent said they did not know what "in the cloud" means
BANK INFO SECURITY
Ex-Bank Employee Charged With Fraud, ID Theft
Man faces maximum sentence of 30 years in prison and a $1 million fine for each mail fraud and bank fraud charge. He also could face a mandatory, two-year prison term upon conviction of each count of aggravated identity theft
MICROSOFT
SharePoint XSS Issue
Microsoft is investigating new reports of a possible vulnerability in Microsoft Windows SharePoint Services 3.0 and Microsoft Office SharePoint Server 2007 that could allow an attacker to run arbitrary script that could result in elevation of privilege within the SharePoint site
CTV
India Bans Chinese Telecom Equipment, Citing Security
India told its mobile operators not to import any network equipment manufactured by Chinese vendors, such as Huawei and ZTE, due to concerns that their equipment could have embedded spyware or malware
FORBES BLOG
Seven Cyber Scenarios To Keep You Awake At Night
Among the threats are state-sponsored spying, hardware backdoors, and malcious software updates -- scenarios that have already occurred
CNET
On iPhone, Beware Of That AT&T Wi-Fi Hotspot
Any wireless network can be made to look like an AT&T hotspot, researcher says
CHINA ECONOMIC REVIEW
Chinese Authorities Require Technology Firms To Disclose Encryption Codes
Manufacturers will have to disclose codes to authorities in order to participate in government procurement programs
BIZ REPORT
Just 8 Percent Of Businesses Make Online Consumer Protection Honor Roll
Vast majority of customer-facing websites still exposing their visitors to potential threats, OTA says
HEALTHCARE INFORMATION SECURITY
HIPAA Violation Leads To Prison Term
Surgeon repeatedly peeked at celebrity medical records, prosecutor says
SECURELIST
Crimeware: A New Round Of Confrontation Begins
Paper discusses methods for stemming the volume of malware hitting financial sites
COMPUTERWORLD UK
Eight Out Of Ten UK Firms Were Hacked In 2009
Widespread use of Web 2.0, remote access could be contributors, study says
GOVERNMENT COMPUTER NEWS
Can Agency Systems Handle New FISMA Requirements?
Standards are designed to reduce paper, but security issues remain
TRENDLABS MALWARE BLOG
Spam Poses As Twitter Email Notification
Attack is designed to simultaneously steal personal information and infect the user with malware
ZSCALER RESEARCH
WordPress Sites Hacked, Again!
Zscaler found that 87 percent of hosts infected with malicious iFrames or JavaScript are running WordPress
ARS TECHNICA
Senators Complain About Facebook Privacy Changes
Sens. Al Franken, Charles Schumer, Michael Bennet, and Mark Begich wrote an open letter to Facebook yesterday, urging the company to take "swift and productive steps" to make user information more private and warning that the FTC may get involved
M86 SECURITY LABS BLOG
New, More Advanced PDF /Launch Attack
The Pushdo botnet is spamming mails with attached PDFs that exploit the \Launch action feature to run an executable file
TOP TECH NEWS
Palin E-Mail Hacking Case Goes To Jury
David Kernell's lawyer said the alleged hacking of Sarah Palin's e-mail account was merely a prank and the result of "stupid" decisions with no criminal intent
THREAT POST
Google Fixes Three Critical Flaws In Chrome
A new version of the Chrome browser for Windows addresses vulnerabilities in earlier versions of the browser
BLOOMBERG BUSINESS WEEK
McAfee Calls Gain On Hewlett-Packard Acquisition Bets
McAfee options jumped to the highest in almost a decade after Friedman Billings Ramsey & Co. said the security firm might be acquired by HP
YAHOO NEWS
Google: Fake Anti-Virus Software A Growing Online Threat
In an analysis of 240 million Web pages by Google during the past 13 months, the search engine giant found fake antivirus programs accounted for 15 percent of malware
V3
Infosec 2010: Europe To Mandate Reporting Of Serious Breaches
An upcoming European Union directive could force organizations to report all serious data breaches to the Information Commissioner's Office
COMPUTERWORLD AUSTRALIA
Cereal Hacker On Defacement Rampage
More than 70 websites hit in local attacks in Australia
THREAT CENTER LIVE BLOG
Pharma-Fraud Continues To Dominate Spam
Pharmacy spam reaches 140 billion messages a day, researchers say
REALWIRE
Media Up Their Interest In Hacking
Study shows marked increase in public profile of security
BBC
Web Security Attack 'Makes Silicon Chips More Reliable'
Defense method developed to stop attack could eventually make chips work better, experts say
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3744
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.
CVE-2013-3743
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 45 and earlier and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.
CVE-2013-2473
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2472.
CVE-2013-2472
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2473.
CVE-2013-2471
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2472, and CVE-2013-2473.



