Best Of Web
Best Of The Web
ALL SPAMMED UP
Bank/Customer Lawsuits Over Phishing Scams Rising
Banks, clients disagree about who's at fault when phishing scams work -- and who should pay
PC ADVISOR
Phishers Widen Their Net To Target New Businesses
Record number of new brands were targeted in Q4, study says
ESECURITY PLANET
Top Ten Wi-Fi Security Threats
Think the wireless threat is under control? Think again
GOVINFOSECURITY
Howard Schmidt Dismisses Cyberwar Fears
The federal government and private businesses that control 85 percent of the nation's critical IT infrastructure are better positioned than ever to fend off massive attacks, he says
ITWEB
China To Punish Hackers
China says it will punish hackers who attacked Google if there is evidence to prove it, but said it has yet to receive any complaint from Google
THREAT POST
As Memory Protections Advance, Exploits Stay A Step Ahead
Researcher Dino Dai Zovi demonstrated the Aurora IE vulnerability on Windows 7 running IE8
POLITICO
Cyberattacks Explode In Congress
Congress and other federal agencies get hit with cyberattacks an average of 1.8 billion times a month, according to Senate Sergeant-at-Arms
INTELFUSION
Russian And Ukrainian Criminals Favor The Planet For Their Web Hosting
Criminal enterprises operating out of Russia and the Ukraine use The Planet of Plano, Texas
MASHABLE
Hundreds Of Twitter Accounts Hacked
Users who have had their accounts hijacked are Tweeting the message, "I lost 20 lbs in 2 weeks!" with links to diet sites
US-CERT
Energizer DUO USB Battery Charger Software Allows Unauthorized Remote System Access
The software included with the Energizer DUO USB battery charger contains a backdoor that allows unauthorized remote system access that could allow an attacker to remotely control a system, list directories, send and receive files, and execute programs
PANDA SECURITY
Vodafone Distributes Mariposa Botnet
Vodafone HTC Magic with Google's Android OS came with Mariposa bot client
ABC NEWS
NATO Chief Calls Attention to Cyber Threats
International spies want to know what's going on inside NATO, and they also use cyberspace to achieve their goals, he says
COMPUTERWORLD
Microsoft's Tax-For-Hacks 'Horrible' Idea, Say Security Experts
Industry experts shoot down Microsoft exec's idea to fund the fight against malware with an Internet tax
CIO
Google Sheds Light on Chrome OS Netbook Security
Google's Chrome OS Netbook will feature built-in security technologies that fight malware and other threats, a Google engineer said
SECURITY PRO NEWS
McAfee: Intellectual Property Poorly Guarded In Aurora Attacks
Google and the other companies that were affected by Operation Aurora might have left their internal controls at risk, and attackers could steal and alter source code
BUSINESS INSIDER
In 2004, Mark Zuckerberg Broke Into A Facebook User's Private Email Account
How the Facebook founder hacked into the email accounts of two Harvard Crimson reporters using data obtained from Facebook logs
GOV TECH
Napolitano Announces Contest for Ideas to Promote Cyber-Security
Homeland Security Secretary Janet Napolitano has issued a contest to the IT security community that asks for ideas on how to develop a public education campaign on cyber-readiness
IT BUSINESS EDGE
Microsoft Has No Plans to Exit China
Plans to continue its search market development there despite Google's woes
ITWORLD CANADA
Former NSA Tech Chief: I Don't Trust The Cloud
Members of the National Security Agency and the Weizmann Institute of Science raised concerns about cloud computing at the RSA Conference this week
eWEEK
Tech Companies Partner In Web Identity Access Effort
Google, Paypal, Equifax, others form Online Identity Exchange
COMPUTERWORLD
Microsoft's Ballmer: 'For The Cloud, We're All In'
At conference, Microsoft exec says software giant is betting its business on cloud technology
TECH HERALD
Can You Trust The NSS Labs Report Touting The Benefits Of IE8?
Report says IE8 blocks more malware than other browsers, but are the tests valid?
CSO ONLINE
Security B-Sides: Perfect Authentication Remains Elusive
Human behavior sometimes defeats two-factor authentication, panel says
HOST EXPLOIT
Accused Spanish Hackers Used a Kit To Take Over PCs
Mariposa botnet took over nearly 13 million PCs, authorities say
VUPEN SECURITY
Opera Browser 'Content Length' Header Buffer Overflow Vulnerability
Flaw could cause browser to crash or execute arbitrary code, researchers say
SEARCH SECURITY
NSA, Crypto Experts Jab At RSA Cryptographer's Panel
Annual panel features good-natured conflict between security agency, top cryptographers
MICROSOFT
Microsoft To Issue Two Patches On Patch Tuesday
Vulnerabilities both rank as "important"
THE REGISTERE
Brass Necked Suspect Swallows USB Evidence
An alleged cybercriminal who swallowed a USB drive thought to contain credit card data to destroy evidence has been charged with obstruction
THE HILL.COM
Microsoft Exec Pitches Internet Usage Tax To Pay For Cybersecurity Programs
Scott Charney says a broad Internet tax would help defray costs of computer security breaches
KREBS ON SECURITY
Regulators Revisit E-Banking Security Guidelines
Federal regulators soon may outline more stringent steps that commercial banks need to take to protect business customers from online banking fraud
COMPUTERWORLD
Data Theft Creates Notification Nightmare For Blue Cross
Blue Cross/Blue Shield of Tennessee has been faced with the expensive and manual process of sorting through which of its 3 million customers to notify about a breach that occurred last fall
H ONLINE
Apple Hires Ex-Mozilla Chief
Window Snyder, ex-senior security strategist at Microsoft and former head of security at the Mozilla Foundation, is joining Apple as senior security product manager
MICROSOFT
Microsoft Issues Advisory for New Vulnerability In VBScript
The newly announced vulnerability affects Windows 2000, Windows XP, and Windows Server 2003 using Internet Explorer and Microsoft says it doesn't know of any attacks yet in the wild
THREAT POST
Google Researcher Researcher Ships Exploit to Defeat ASLR+DEP
The security researcher known as "SkyLined" released code that uses a new way to bypass Data Execution Prevention to launch an attack
COMPUTERWORLD
Narus Develops A Scary Sleuth For Social Media
Narus is building a new technology that investigates data on social networks and Intenret services to provide intelligence agencies and law enforcement information on cybercriminals on the Net
ASSOCIATED PRESS
Authorities Bust 3 In Infection Of 13M Computers
Authorities nabbed the operators behind the Mariposa botnet, which has infected as many as 12.7 million PCs, as well as over half of the Fortune 1000
CNN
Four Indicted In Online Ticket-Hacking Scheme
Group allegedly purchased as many as 1.5 million tickets to major events in scheme that netted $25M
SOPHOS BLOG
From Pizza To Cybercrime: DarkMarket Mastermind Jailed
Bad guy gets nearly five years in prison for operating a stolen-data trading site
HELP NET SECURITY
A 184 Percent Increase In Malicious Websites
Increase in traffic from Grum and Rustock botnets to blame for increase in spam, MessageLabs says
COMPUTERWORLD AUSTRALIA
Why 41 Percent Of You Would Fail A PCI Audit
Many organizations remain dependent on temporary compensating controls, Ponemon study says
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
- Three Principles to Improve Data Security and Compliance
- Aligning IT with strategic business goals: A proactive approach to managing IT risk to your business
- Connecting the Dots: Are You Seeing the Complete Big Data Picture?
- How crowdsourced testing has changed the game for innovative software companies
- Ensuring Your Apps Work in the Real World
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3661
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
CVE-2013-3660
The EPATHOBJ::pprFlattenRec function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPa...
CVE-2013-3634
The SNMPv3 functionality on Siemens Scalance X200 IRT switches with firmware before X-200IRT 5.1.0 does not properly validate credentials, which allows remote attackers to execute arbitrary SNMP commands by leveraging knowledge of a username.
CVE-2013-3633
The web interface on Siemens Scalance X200 IRT switches with firmware before X-200IRT 5.1.0 relies on client-side privilege checks, which allows remote authenticated users to execute arbitrary commands via unspecified vectors.
CVE-2013-1022 (quicktime)
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted mvhd atoms in a movie file.


