Best Of Web
Best Of The Web
ZSCALER
Bing And Yahoo! Sponsored Advertising Leads To Malicious Websites
Search engine-driven attacks no longer limited to Google
COMPUTERWORLD
Windows Users Patch Fastest Amid Zero-Day Hype
Researcher says publicity is the top reason why IT moves quickly to patch zero-day bugs
GOVERNMENT COMPUTER NEWS
Old-Fashioned Tactics Still Can Beat The Botnets (Sometimes)
Microsoft, federal agencies score recent wins against malware
BUSINESSWEEK
Uncle Sam Wants You (To Fight Hackers)
U.S. government steps up effort to recruit engineers who can help wage cyberwar
FORBES
U.S. Government Effort Against ID Theft Said To Fall Short
Internal review says Department of Justice has not done enough to fight country's fastest-growing crime
NEWS OK
Oklahoma Brings In Millions By Selling Personal Data
Privacy experts say practice doesn't spur identity theft
TECHNOLOGY REVIEW
Hacking The Smart Grid
One researcher shows how your home's power could be shut down remotely
MEDPAGE TODAY
Hackers Could Target Medical Devices
Security analysis should be part of FDA approval process, researchers argue
COMPUTERWORLD
No One Can Duck Heartland Fallout Until It Stops
JC Penney breach almost buried in coverage of Gonzalez sentencing
INFO SECURITY
EBay Comes Under Attack, Says Red Condor
Auction site is victim of attack that exploits its own compromised server, researchers say
ECONOMIC TIMES
Journalists In China Say Yahoo Accounts Hacked
Google's Chinese search engine also intermittently blocked, reports say
SIEM BLOG
Implications Of Recent PDF/Launch Hacks
Are PDFs worm-able? Proof of concept says they might be
MSDN BLOG
Microsoft SDL Version 5 Now Available
The newest version of the Microsoft Security Development Lifecycle process guidance adds new requirements
US-CERT
VMware Releases Security Advisory for ESX Service Console Updates
VMware has released a security advisory to address vulnerabilities in the Samba and acpid packages of ESX Service Console -- the bugs allow an attacker to execute a denial-of-service attack, grab data or bypass security restrictions
CRN
Report: Ransomware, Botnets On The Rise
Ransomware rose last month propelled by an explosion in botnet activity and a malicious Internet Explorer attack is spreading rapidly across the globe, according to a Fortinet Threatscape Report
NEXTGOV.COM
Cybersecurity Bigger Than An IT Problem
Companies that don't include C-level executives in their cybersecurity programs put their bottom lines at risk, according to a report from the Internet Security Alliance and the American National Standards Institute
COMPUTERWORLD
DHS Studying Global Response To Conficker Botnet
The Department of Homeland Security is looking at how the Conficker Working Group's model of private sector organizations working together globally can be used to solve other cybersecurity risks
JURIST
Federal Judge Rules For Islamic Charity In NSA Wiretapping Case
U.S. District Court rules that the federal government illegally wiretapped conversations without a warrant
THE REGISTER
Ukrainian Cybercrime-Friendly ISP Hit By Fire After Clean-Up
A Ukrainian ISP hit by a fire was in the process of cleaning up its act after earlier being identified as a leading haven for cybercrime
KREBS ON SECURITY
Java Patch Plugs 27 Security Holes
A new version of Java is available that fixes at least 27 security vulnerabilities
V3
Facebook Bug Exposes Private Emails
An apparent technical snafu led to Facebook's temporarily disclosing the private email addresses of its users
ARS TECHNICA
Microsoft: Google Chrome Doesn't Respect Your Privacy
Microsoft video on TechNet Edge demonstrates how Google Chrome collects keystrokes, and Internet Explorer 8's In Private browsing feature
ESECURITY PLANET
FBI, DOJ Falling Short on Identity Theft: Report
The Inspector General says while the FBI and Justice Department have conducted efforts to fight identity theft in recent years, there's no coordinated plan for combating identity theft
TECHWORLD
Microsoft Uses Botnet To Detect Office Bugs
Microsoft uncovered more than 1,800 bugs in Office 2010 by running millions of fuzzing tests
THE DAILY PIONEER
India Wants To Team With U.S. In Cybersecurity
India has proposed a collaboration between the country and the U.S. in cybersecurity and cyberterrorism
COMPUTERWORLD UK
MIT And DARPA Working On Self Patching Applications
Researchers led by the Massachusetts Institute of Technology and funded by the Defense Advanced Research Projects Agency have developed software that keeps applications running during attacks, then finds and installs permanent patches to protect them
THE MIAMI HERALD
Miami-Dade Inmates Hack Into Strangers' Phone Lines
Inmates in Miami-Dade jails are billing tens of thousands of dollars in collect calls to unsuspecting citizens in a scam where they forward collect calls via a victim's fax line
COMPUTERWORLD
Millions In China Have No Antivirus Software, Survey Shows
There were 4.4 percent of Chinese users with no security software last year, up from 3.9 percent the year before, a new survey shows
NEW YORK TIMES
Journalists' E-Mails Hacked in China
Yahoo e-mail accounts of more than a dozen rights activists, academics and journalists who cover China have been compromised by unknown intruders who appear to have shut victims out of their accounts
MOZILLA BLOG
Plugging the CSS History Leak
Mozilla is about to fix a privacy leak in its browser that can let attackers and third-party Websites see other sites where users have visited
MASHABLE
Yale Delays Switch to Google Apps, Cites Security Concerns
Security and other issues in the way Google handles data in the cloud has led to Yale University's decision to halt its plans to go to Google Apps
THE EXAMINER
New Facebook Phish Steals Passwords
Scam comes with the subject line "My Facebook account got hacked"
THREATPOST
Hacker Finds a Way to Exploit PDF Files, Without Vulnerability
Researcher creates proof-of-concept PDF file that works without exploiting any security vulnerabilities
EPIC.ORG
New Jersey Supreme Court Rules in Favor of Employee Privacy
The New Jersey Supreme Court ruled in favor of a female employee whose employer read emails that she sent while using Yahoo Mail on a company-owned laptop
CNET
Researchers Find Security Holes In Smart Meters
Flaws in two-way smart meters that could allow a person with a laptop to tap into the communications between people's homes and utility companies
ORACLE
Oracle Issues Critical Patch Update Advisory for March
Oracle strongly recommends that customers apply the 27 fixes as soon as possible
CIO
JC Penney Tried to Block Publication of Data Breach
JC Penney argued to keep its name secret during Albert Gonzalez's trial for stealing more than 130 million credit card numbers from payment processor Heartland Payment System
MARKETWATCH.COM
Wet Seal Inc. Was Among Retailers Targeted by Major Credit Card Data Theft Ring in 2008
Wet Seal says it was one of the retailers hit by Albert Gonzalez and gang, but there's no evidence any customer data was stolen
THREAT POST
Apple Mega Patch Covers 88 Mac OS X Vulnerabilities
One of the biggest Mac OS X security updates includes 88 documented vulnerabilities, including patches for bugs that could lead to remote code execution, information disclosure, and denial-of-service attacks
GOVERNMENT COMPUTER NEWS
FISMA: A Good Idea Whose Time Never Came
The Federal Information Security Management Act of 2002 has created a culture of compliance rather than improving security for federal agencies
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
- HP Newsletter with Gartner Research: Maximizing Your Infrastructure through Virtualization
- Understanding Holistic Database Security 8 Steps to Successfully Securing Enterprise Data Sources
- A How-To Guide on Using Cloud Services for Security-Rich Data Backup
- Holistic Risk Management: Perspectives from IT Professionals
- Aligning IT with strategic business goals: A proactive approach to managing IT risk to your business
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2012-4697
TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to obtain administrative access via an FTP session.
CVE-2011-4520
Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
CVE-2011-4519
Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
CVE-2011-4518
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2012-6563
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.


