Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173


Best Of The Web

NEW ZEALAND HERALD
MSN Website Hacked
Attackers replace news stories with pie-faced photo of Bill Gates on New Zealand site

SPAMFIGHTER
New Conficker Variant Enters Into Spam Business
Conficker.E spreads in much the same way that Conficker.B did, Symantec says

SPAMFIGHTER
Mounting Malware Threat To The U.S. Federal Government
Feds see nearly 5,5000 malware "breaches" in 2008, up sharply from 2007

EXAPROTECT
Loss Of Company Reputation Is Greatest Threat Posed By Stolen Laptops
Public breach disclosures can hurt a company's image, according to Dell study

IT BRIEF
250,000 Malicious Sites Created Daily
Malware sites going live at an unprecedented pace, AVG report says

THE WALL STREET JOURNAL
Oracle Agrees To Acquire Sun Microsystems
In a surprise twist, Oracle said it will buy for $7.4 billion, following failed talks between IBM and Sun

USA TODAY
Starwood Sues Hilton Hotels Over Alleged Corporate Espionage
Hotel giant alleges Hilton stole more than 100,000 electronic and hard copy files with trade secrets to help expand its luxury hotel offerings

THE IT SECURITY GUY
Federal Cybersecurity Report Almost Due
The administration's 60-day cybersecurity review is due to be completed this week, but expectations are low about what the report will recommend, and when it will go public

HEISE ONLINE
Mobile Phone Web Sessions Hijacked Via SMS
Italian security experts demonstrate how Web traffic on a mobile phone can be diverted to a proxy server controlled by an attacker

COMPUTERWORLD UK
Plans To Reveal Software Flaw Stopped By Vendor Concerns
Black Hat Europe researchers cancel a presentation set to expose a major security vulnerability after worries of potential attacks before the vendor could patch it

MX LOGIC BLOG
Waledac Variant Uses SMS Spy Social Engineering Theme
The Waledac botnet is using a new tack, luring victims to download a program that purports to read others' SMS messages online

COMPUTERWORLD UK
Three-Quarters Of IT Managers Find Inappropriate Material On Employee Laptops
A survey of U.S. security and IT professionals shows 75% have found "inappropriate" pictures, videos, or browser cache links on employee laptops

FOX NEWS
Feds Seeking Computer Hackers To Secure Nation's Networks
General Dynamics Information Technology advertises on behalf of the Homeland Security Department for someone who could "think like the bad guy"

WIRED
Documents: FBI Spyware Has Been Snaring Extortionists And Hackers For Years
FBI-produced spyware program used in federal investigations into extortion plots, terrorist threats, and hacker attacks in past seven years, newly declassified documents show

INFORMIT
Software Security Comes of Age: Reaches $500M Threshold
Despite recession, software security market is growing, says Gary McGraw

CNET
Pirate Bay Defendants Found Guilty
Swedish court found the four defendants in the high-profile Pirate Bay case guilty, sentencing each to a year in jail for illegal file-sharing operation

ZDNET
iBotnet: Researchers Find Signs Of Zombie Macs
Symantec researchers find first Mac OS X botnet, which is launching denial-of-service attacks

SILICON.COM
Phishing Attacks Costing Banks $350 A Pop
Gartner says average cost of a phishing attack to the U.S. financial services industry was $351 last year -- down 60 percent

WASHINGTON POST
Hackers Test Limits Of Credit Card Security Standards
The number, scale, and sophistication of data breaches has reignited debate about PCI DSS

IEEE SPECTRUM
New Chip Brings Military Security To Commercial Processors
Commercial version of CPU Tech's military-grade secure processor is targeted at firms and agencies responsible for securing public infrastructure, such as electric power generators and subway systems

CARNEGIE MELLON CERT
CERT Releases Free Tool To Reduce ActiveX Vulnerabilities
Open-source Dranzer tool for software developers tests code for certain kinds of ActiveX vulnerabilities before software products are released

WIRED
PIN Crackers Nab Holy Grail Of Bank Security
New ATM attack doesn't require skimming

ZDNET
Scareware Pops Up At Fox News
"Malvertising" campaign affects site visitors

INTERNET NEWS
Top VoIP Threats Detailed By Security Company
Emerging technology is an attractive target, WatchGuard says

INSURANCE NETWORKING NEWS
China Cyber Attacks Should Worry Insurers
Exploits could interrupt business, cause claims

SC Magazine
Pharmacy Hackers Busted In Romania
Attackers allegedly broke into systems belonging to U.S. pharmaceutical firms

KHOU.COM
Virus Cripples DPS Computer System
Infection takes out Texas state Department of Public Safety

NETWORK WORLD
Colleges To Duke It Out Over IT Security
Competition will pit hackers vs. defenders

BBC
Amazon Blocks Phorm Advertising Scan
Web giant concerned about user privacy

EWEEK EUROPE
Spam Emails 'Match Gas Emissions'
Spam email messages produce greenhouse gas emissions each year equivalent to that of 3.1 million cars, according to research conducted on behalf of McAfee

BUSINESS WEEK
Microsoft Ordered To Pay Uniloc $388 Million
A federal judge this month ordered Microsoft to pay $388 million in damages for infringing on a patent held by Uniloc

DAILY TECH
Symantec: Malware Continues To Explode Around The World
90 percent of all threats in 2008 attempted to steal confidential information, according to new study by Symantec

SC MAGAZINE
Pharmacy Hackers Busted In Romania
Romanian authorities have arrested five people for allegedly breaking into computer systems belonging to U.S. pharmaceutical firms

COMPUTERWORLD
Privacy Rules Hamper Adoption Of Electronic Medical Records, Study Says
Researchers at MIT and the University of Virginia say increased efforts to protect privacy of health data will hamper the adoption of electronic medical records initiatives

INFORMATIONWEEK
Chinese National Arrested For Source Code Theft
A Chinese citizen on a work visa was arrested by the FBI last week for allegedly leaking to a Chinese government agency proprietary software code owned by his U.S. employer

INTERNET EVOLUTION
Foolish Logic Undermines Electrical Grid Security
U.S. government has relied on the power companies to protect themselves, despite no real improvement during the years

CNET
Why A National Data Breach Notification Law Makes Sense
Legislation would protect people in states with no such laws and extend definition of private data into areas beyond financial and healthcare

MICROSOFT.COM
Microsoft Patches Eight Vulnerabilities
Five patches considered critical

BLOG.SPYWARE GUIDE
IM Password Stealer Available From Major Download Sites
Malware kit lets users disguise app to look like popular IM programs

ORACLE.COM
Oracle Issues 43 Security Fixes
Sixteen of the new patches affect the Oracle database


Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)