Best Of Web
Best Of The Web
COMPUTERWORLD
Symantec Hit With Class-Action Lawsuit Over Auto-Renewals
N.Y. man alleges Symantec automatically charged his credit card and renewed his subscription to Norton Antivirus without notifying him
HELPNET SECURITY
Zero-Day Vulnerabilities On The Market
TippingPoint researchers say when governments are involved, a vulnerability discovery can sometimes yield as much as $1 million
KREBS ON SECURITY
Zeus Attack Spoofs NSA, Targets .gov And .mil
Emails spoofing the National Security Agency and loaded with the Zeus banking Trojan are being sent to government emails, and initial reports say a large number of government systems may have been compromised by the phishing attacks
THREAT POST
Google Attack Was Tip Of The Iceberg
The attacks themselves were neither unique nor clever, and that's what should worry lawmakers and organizations' security officials
WEBSENSE
Websense Security Labs Report Finds 95% Of Blog, Message Board, Chat Is Malicious Or Spam
Around 35 percent of malicious Web attacks included data-stealing code, and 58 percent of data-stealing attacks are conducted over the Web
INVISIBLE ENEMY
The Pushdo DDoS Enigma: Some Theories
The mysterious SSL connections to hundreds of Websites may be measuring how fast the victim's Internet connection is
V3
Microsoft's Mundie Calls For 'Internet Driving License'
Microsoft CSO Craig Mundie said at the World Economic Forum in Davos that people should undergo mandatory training before being allowed online, and that there should be a three-tier system of authentication for people, devices, and apps
COMPUTERWORLD
Update: VeriSign Fails To Take Action Against Malicious Sites, Researcher Says
A security researcher says VeriSign hasn't acted quickly enough to take down several dozen sites known to be spreading malware
CNET
Billions To Be Spent On Smart-Grid Cybersecurity
Utility companies around the world will spend $21 billion by 2015 to improve cybersecurity for the smart grid, according to a new report
PC ADVISOR
Microsoft To Patch 26 Flaws, 5 Critical
Microsoft will deliver a record 13 security updates next Tuesday -- the patches fix more than two dozen vulnerabilities in Windows and Microsoft Office
SOPHOS BLOG
Mozilla Admits Firefox Add-Ons Contained Trojan Code
Mozilla says two add-ons available from its Add-ons Website were infected by malicious code capable of infecting Windows computers
H ONLINE
Hackers Paralyze Emissions Trading Scheme
Attackers cracking databases to steal and sell emissions permits, authorities say
COMPUTERWORLD
Verisign Fails To Take Action Against Malicious Sites, Researcher Says
Domain registrar not acting fast enough to take down malware-spewing sites, according to researcher
MINNEAPOLIS STAR TRIBUNE
Hacker Attacks Ceridian; Data Of 27,000 At Risk
Compromise of bank account data could be more serious than recent credit card data thefts, expert says
WASHINGTON POST
Google To Enlist NSA To Help It Ward Off Cyberattacks
Alliance will allow the two organizations to share information on recent attacks from China
MICROSOFT
Microsoft Issues Patch For Critical IE Flaw
Vulnerability could allow attackers to access files, software giant says
SCHNEIER ON SECURITY
Anonymity And The Internet
Mandating universal identity and attribution is wrong, expert says
DEFENSE NEWS
NATO Chief: Nations Must Unite On Cyber Warfare
Next conflict will likely begin with a cyberattack, not a physical attack, official says
IT BUSINESS EDGE
Rogue iPhone Apps Could Jeopardize User Privacy, Expert Says
Be careful of the apps you download, security researcher warns
SEARCH SECURITY
Attackers Zero In On Web Application Vulnerabilities
Exploitable flaws abound in poorly written Web apps, experts say
LAW
Time To Review Corporate Computer Policies Corporate
Recent court decisions could change the way you look at computer-use policies, experts say
GOVERNMENT TECHNOLOGY
Report: China Suspected Origin Of Hacked Iowa Agency
Gaming commission breach likely emanated from China, officials say
WALL STREET JOURNAL
Officials Warn Al Qaeda 'Certain' To Try Attack Soon
Cyberattack is one possibility, National Intelligence director says
NEW YORK TIMES
Hacking For Fun And Profit In China's Underworld
Most of China's hackers aren't skilled coders, anonymous hacker says
THREATPOST
One In Every 150 Legitimate Sites Infected By Malware, Study Says
Frequency of infection has skyrocketed during the past few years, according to Kaspersky researchers
MEDIAPOST
Facebook Asks Court To Dismiss Click Fraud Cases
Users must pay for all clicks, whether or not they're valid, social networking company argues
eWEEK
Google, China, And The Anatomy Of The Aurora Attack
A look at how the attack unfolded
SOPHOS
Revealed: Which Social Networks Pose The Biggest Risk?
New Sophos Security Threat Report 2010 shows that among 500 enterprises surveyed, 60 percent say Facebook is the biggest danger
REUTERS
China Internet Users Use VPN Servers To Cross Firewall
Paid virtual private networks in China are an increasingly popular way to access forbidden Websites
IT BUSINESS
Hackers Peddling Stolen Twitter Accounts For $1,000
A Twitter account with more than 320 followers was offered for $1,000 in an underground hacker forum, according to researchers from Kaspersky Lab
H ONLINE
Multiple Vulnerabilities In Vmware Products
VMware has issued an advisory for 47 vulnerabilities in several of its products, including ESX, Server, VirtualCenter, and vCenter -- many of which are tied to problems in the Java Runtime Environment
IT PRO
Met Police Start To Combat 2012 Olympics Cybercrime
U.K. Metropolitan Police have established two specialist units dedicated to tackling cybercrime at the 2012 London Olympics -- one for fraud and hacking and the other for preventing ticketing fraud
COMPUTERWORLD
Google To End Support For IE6
Google is phasing out support for Microsoft's Internet Explorer 6 browser starting in March
NET MARKETSHARE
Chrome Gains In January: Takes Share From Internet Explorer And Firefox
Google Chrome browser gained 0.6% of global usage share in January, while Firefox and Internet Explorer lost share last month
THE WASHINGTON POST
Can We Stop The Global Cyber Arms Race?
First we have to acknowledge and stop the large number of cyberattacks originating from the U.S.
INFOSECURITY
Verified By Visa And MasterCard SecureCode Security In Question
The 3D Secure method of online card transaction protection, or Verified by Visa and MasterCard SecureCode, may not be as secure as the banks are saying
THE REGISTER
Many Voice Encryption Systems Easily Crackable
Majority of voice encryption products are seriously flawed, according to controversial tests by an anonymous hacker
WIRED
Pentagon Searches For 'Digital DNA' To Identify Hackers
DARPA is launching an effort to create the cyber equivalent of fingerprints or DNA that can identify even the most stealthy hackers
SAN DIEGO NEWS
San Diego Set To Become Cyber Security Leader
U.S. Attorney Karen Hewitt said goal is to create a cultural shift in the community, affecting how every San Diegan behaves on computers at home and work
COMPUTERWORLD
FBI Arrests Alleged Cable Modem Hacker
Federal authorities arrested a 26-year-old man for allegedly selling modified cable modems that enabled free Internet access
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3496 (vipnet_client, vipnet_coordinator, vipnet_personal_firewall, vipnet_safedisk)
Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.
CVE-2013-2849 (chrome)
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.
CVE-2013-2848 (chrome)
The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.
CVE-2013-2847 (chrome)
Race condition in the workers implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via unknown vectors.
CVE-2013-2846 (chrome)
Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2840.


