Best Of Web
Best Of The Web
CNET
Many Ways To Activate Webcams Sans Spy Software
Lower Merion school incident opens hackers' debate on how to do remote spying
REUTERS
Spies And Hackers Exploit World Cyber Rule Void
Absence of cross-border regulation leaves green field for the bad guys, experts say
CNN
Hackers Expose Security Flaws With "Elvis Presley" Passport
Even with biometric passport bearing a photo of The King, white hats defeat scanning system
CNBC
US Pinpoints Code Writer Behind Google Attack: Report
U.S. government analyst sources believe a Chinese man with government connections wrote key elements of the malware used in hacker attacks on Google and others, according to The Financial Times
THE REGISTER
Chinese Schools Deny Google Cyber-Attack Links
The two Chinese schools traced to the attacks on Google and others deny they had any involvement or have links to the military
GARY WARNER BLOGSPOT
Phishers Target Blogger.Com Accounts
A new phishing campaign is targeting bloggers on Google's "blogger.com" and "blogspot" services -- driving victims to sites favored by the Avalanche/Zeus group
HELP NET SECURITY
Cloud Security Alliance And IEEE Join Forces
CSA and IEEE have been conducting a survey to identify and define the most critical security concerns surrounding enterprise cloud computing; results will be revealed at RSA
CTV
Dozens Of U.S. Defense Contractors, Agencies Hacked
DoD's Cyber Crime Center says between August 2007 and August 2009, 71 government agencies, contractors, universities, and think tanks with connections to the U.S. military had been penetrated by foreign hackers -- in some cases, multiple times
COMPUTERWORLD
China's President Skips Twitter, Opens State-Tied Microblog
Chinese president Hu Jintao has opened a microblog despite China's blocking of Twitter
COMPUTERWORLD UK
Gary McKinnon Extradition Review Set For May
NASA and DoD hacker gets one more shot to overturn government's decision to extradite him to the U.S.
SECURITY.EXE
Over 100,000 Payment Cards Stolen In Finland
Police say information was kept on poorly secured server, and questions arise about liability extending beyond the merchant
THE NEW YORK TIMES
2 China Schools Said To Be Tied to Online Attacks
The attacks on Google and other U.S. companies have been traced back to two educational institutions in China, one of which has ties to the Chinese military, sources say
CNET
Has Apple Banned Sexual Content From App Store?
Apple may be in the process of removing "overtly sexual" content from its App Store, according to a TechCrunch report
GRAHAM CLULEY BLOG
European Internet Explorer Users Invited To Choose Another Browser
Hackers could take advantage of new feature by Microsoft in Europe that displays lists of alternative browsers
COMPUTERWORLD
Pa. School District Denies Spying On Students With MacBooks
The Lower Merion School District of Ardmore says it only remotely activated the Web cameras to locate lost or stolen laptops, not for spying
AVIV RAF ON .NET
Skeletons In Adobe's Security Closet
Adobe Download Manager can be abused by attackers due to a design problem, plus there's a remote-code execution flaw in the app that would let an attacker force the download of a malicious executable, a researcher says
THE REGISTER
Attack Code For Firefox Zero-Day Goes Wild, Says Researcher
A Russian security researcher says he has released an exploit based on a vulnerability in the newest version of Firefox
BBC
WordPress Network Bug Throws Millions Of Blogs Offline
More than 10 million WordPress blogs were knocked offline for two hours yesterday due to a core router change that broke the site, according to WordPress
HELP NET SECURITY
Spybot.AKB Worm Spreads Across P2P Networks And E-Mail
A new worm called Spybot.AKB is on the loose and spreading using P2P programs and via e-mail
H SECURITY
New Approaches To Virus Protection
Huge database containing hashes of legitimate apps might make whitelisting more effective, Internet Storm Center says
SUNBELT BLOG
FTC Shuts Down 'Work From Home' Scammers
Commission ends operations for some 70 online job scams
OFFICE OF INADEQUATE SECURITY
Florida Man And Driver Convicted In $30 Million Bank Fraud And ID Theft Ring
Perpetrators attempted to access more than 100,000 bank accounts, attorney general's office says
SECURITY PRO NEWS
M86 Security Documents Increases In Spam Attacks
New report also says URL shortening, Twitter attacks are on the rise
HELP NET SECURITY
Spybot.AKB Worm Spreads Across P2P And Email
Program copies itself to shared folders with different names, PandaLabs says
SEARCH SECURITY
How To Prevent Memory Dump Attacks
Full protection means not only securing memory at rest, but also when data is in motion
WXVT NEWS
Louisiana Man Gets 309 Years In Prison For Identity Theft Scam
Sentence is the toughest ever handed down for white-collar crime in the region
INFOSECURITY
3,000 Small Dog Electronics Customers' Credit Card Details Compromised
Hackers got in through a Web app flaw, even though company passed a PCI audit and a pen test
TREND MALWARE BLOG
Keeping An Eye On The EYEBOT And A Possible Bot War
New botnet Eyebot's spyware behaviors indicate be readying for a bot war with Zeus
KREBS ON SECURITY
'Time Bomb' May Have Destroyed 800 Norfolk City PCs
The City of Norfolk, Va., is investigating how unidentified malware destroyed data on nearly 800 of its computers citywide
PRAGUE MONITOR
Czech Experts Uncover Global Virus Network
A global network of infected computers was discovered that steals bank account, email, and password data
VIRUSLIST
Kaspersky Security Bulletin 2009
The most dangerous applications of 2009 based on security incidents were Apple QuickTime, Microsoft Office, and Adobe Flash Player, according to a new Kaspersky Lab report
SEARCHSECURITY
MAAWG Documents Spam Statistics Stalemate
MAAWG executive director says spam volume is still at about 90 percent and holding, based on SP data gathered from 500 million mailboxes and 200 billion delivered email messages
H ONLINE
Symantec Says Rootkit Causes Windows XP Blue Screen Of Death
A rootkit is causing many of the "blue screen of death" incidents that are now occurring with Windows XP, according to Symantec
BANKINFOSECURITY
ATM Fraud: Six Steps To Improving Customer Awareness
What banking customers should look out for to prevent being a victim of ATM-skimming -- including wires, jammed ATM machines, and "no tampering" signs
INFOWORLD
Facebook Hit With Class Action Lawsuit Over Privacy Changes
A class-action lawsuit has been filed in California against Facebook over changes the social networking site made to its privacy settings last November and December
ADOBE
Adobe Issues Patch For New Critical Vulnerability
Flaw could subvert domain sandbox, crash application, or enable remote control
MONSTERS & CRITICS/strong>
Massive Security Breach Suspected At Latvian Tax Office
More than 7 million documents may have been leaked from database in tax agency
FINEXTRA
Iceman Gets 13 Years For Massive Card Data Theft
California-based hacker convicted of stealing more than 2 million credit card numbers
BBC
Internet Fraud Targeted By New Team
U.K. government to invest in new cybercrime-fighting unit
THE INDEPENDENT
Arrest Warrant Issued For American Cyclist Over Data Hacking
French police allege Landis hacked information in anti-doping case
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3270 (vnx_control_station, celerra_control_station)
EMC VNX Control Station before 7.1.70.2 and Celerra Control Station before 6.0.70.1 have an incorrect group ownership for unspecified script files, which allows local users to gain privileges by leveraging nasadmin group membership.
CVE-2013-1014 (itunes)
Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
CVE-2013-1011 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
CVE-2013-1010 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
CVE-2013-1008 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.


