Best Of Web
Best Of The Web
WIRED
TJX Accomplice Gets Probation For Selling Browser Exploit
Security pro who wrote IE code that helped penetrate major retailers avoids jail sentence
NBC CONNECTICUT
Furnace Rebates Put Thousands Of Identities At Risk
Temporary employee might have accessed data on as many as 11,000 customers, state says
THE REGISTER
Unfashionable DDoS Attacks Still Menace Websites
New research aims to demystify denial-of-service attack methods
GOVERNMENT INFO SECURITY
Privacy Assessment Sheds Light On Einstein 3
Early documents offer glimpse of next-generation intrusion prevention system
WIRED
Unprecedented 25-Year Sentence Sought For TJX Hacker
Albert Gonzalez deserves the largest sentence in identity theft case history because he was at the center of the largest and most costly breaches in U.S. history, federal prosecutors wrote
NEW YORK TIMES
Academic Paper In China Sets Off Alarms in U.S.
Expert warns Congress that Chinese researchers have published a paper on how to attack a small U.S. power grid subnetwork, but the author of the report says he was merely trying to find ways to enhance the stability of power grids by exploring possible vulnerabilities
NETWORK WORLD
FBI Fights Cybercrime In E. Europe
The FBI has agents embedded with law enforcement agencies in Estonia, Ukraine, and the Netherlands to help investigate cybercrime cases
THE STAR.COM
High-Tech Copy Machines A Gold Mine For Data Thieves
When copy machines with hard drives are tossed out, sensitive data often remains stored in them
ENTERPRISE SECURITY TODAY
Is Your Boss Spying On You At Work?
Employee monitoring is on the rise, mainly due to financial pressures and that the technology is simple and inexpensive
SOFTPEDIA
New Scareware Leverages The Layered Service Provider
Trend Micro says a new FAKEAV version operates a ransomware-like component as a Layered Service Provider (LSP) routine, blocking access to Facebook, YouTube, MySpace, The Pirate Bay, and others
H ONLINE
Opera 10.51 Addresses Vulnerabilities
Opera has released version 10.51 of its browser that fixes "highly severe" security holes
THE REGISTER
Germany Warns Surfers Against Firefox
Germany's cybersecurity response team is advising citizens not to use Firefox until Mozilla releases a patch to defend against a critical flaw -- the patch is due March 30
WIRED
Hacker Disables More Than 100 Cars Remotely
Attacker takes advantage of immobilization system normally used for car buyers who don't make payments
HOST EXPLOIT
Proof Of Identity Now Required For .Ru Domain Registrations
As of April 1, registrants of domain names ending in .RU must file proof of their identities with their registrars in order to maintain their existing domain names and obtain new ones
TECH WORLD
Weak States Leave EU Open To Cyberattack
EU nations need to work more closely together, report says
V3.CO.UK
Social Networks Shrug Off FTC Privacy Concerns
At roundtable, Facebook and Google defend their practices to concerned regulators
TECH WORLD
Five Doomsday Scenarios For IT Apocalypse
End times for IT might be more likely than you think
McAFEE AVERT LABS
Facebook Suffers "Password Reset" Scam
Official-looking message is actually a cover for data-stealing malware
MESSAGELABS INTELLIGENCE
Word Usage In Spam
Spam exploits differ around the world, but there are some common elements you can look for
HELP NET SECURITY
Barclays Under Strong Phishing Shower
Attack hits more than 180 of bank's customers in less than three minutes
CNET
Report: Google To Leave China On April 10
Google is expected to announce on Monday that it will withdraw from China, according to a report in a Beijing-based newspaper
COMPUTERWORLD
Fired CISO Says His Comments Never Put Penn.'s Data At Risk
Robert Maley, former CISO for the state of Pennsylvania who was fired this month after speaking at the RSA conference, says he was terminated because he didn't have permission to speak at the conference
USA TODAY
States Give Inmates Access To Personal Data Of Others
Prisons in eight states let convicts work in jobs that give them access to Social Security numbers and other personal information for the public, a federal audit report found
PC MAGAZINE BLOG
Botnets Going Down, But Spam Still Up
Despite takedowns of Waledac and Mariposa botnets, spam levels appear unaffected
H ONLINE
20 Zero-Day Holes In Mac OS X To Be Exposed
Security researcher Charlie Miller plans to disclose 20 zero-day security vulnerabilities at next week's CanSecWest
TIME
To Battle Computer Hackers, the Pentagon Trains Its Own
U.S. military is training penetration testers and red-team specialists, but that won't stop the hundreds of daily hacks the Pentagon suffers
THE WASHINGTON POST
Dismantling Of Saudi-CIA Web Site Illustrates Need For Clearer Cyberwar Policies
Despite CIA's objections, U.S. military computer specialists mounted a cyberattack that took down a Saudi Website -- raising the issue of what the rules of engagement should be in cyberwar
PANDA RESEARCH
Vodafone Distributes Mariposa Botnet
New phone comes with an infection -- right out of the box
WIRED
SEC: Hacker Manipulated Stock Prices
U.S. regulators are freezing the assets and trading accounts of a Russian accused of hacking into personal online portfolios
FEDERAL COMPUTER WEEK
DHS, Industry To Try Fusion Centers For Classified Data Swap
The Department of Homeland Security plans to start a pilot program with state and local intelligence fusion centers to pass secret-level information on cyber threats to critical infrastructure to some industry officials with security clearances
MAKEUSEOF.COM
Are You Sure Your Email Isn't Being Hacked?
How to set up an electronic "tripwire" so that if someone breaks into your account, you'll know
">THE WASHINGTON POST
18- To 24-Year-Olds Most At Risk For ID Theft, Survey Finds
It also takes them longer to figure out that they have been defrauded -- an average of 132 days versus 49 days for older age groups
THE REGISTER
Google's Chinese Ad Partners Demand Satisfaction
Twenty-seven of Google's Chinese ad partners say their businesses are suffering while they wait to hear what Google plans to do and asks how they will be compensated if it pulls out of the country
TIPPINGPOINT BLOG
Predictions For Pwn2Own
TippingPoint expects the iPhone to be the first smartphone to fall in the CanSecWest hacking contest
SEARCHSECURITY
Major ISPs Can Remove Botnets, Malware, CISO Says
Mubai-based ISP Tata says technology exists for Tier-1 ISPs to detect and see malicious traffic on their networks
CASINO CITY TIMES
Computer Experts Stole ��33,000 In Casino Scam
Two computer experts cheated casinos by creating fake betting slips and hacking into software that controlled remote betting machines on live roulette wheels
SOCIAL HACKING
Facebook Adds Code For Clickjacking Prevention
Quietly, social networking site fortifies its code
KREBS ON SECURITY
Fiserve To Banks: Stay On Outdated Adobe Reader
Fortune 500 firm says security updates shouldn't be deployed
FINEXTRA
Criminals Install Fraudulent Terminals At U.S. Retailer
Hancock Fabrics says PIN pad units were replaced with "virtually identical, but fraudulent" units
HOST EXPLOIT
Curious Employee Foils Corporate Credit Card Fraud Scam
A look at a real insider scam; names have been changed to protect the innocent
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



