Best Of Web
Best Of The Web
THE REGISTER
Pentagon Chiefs Buy Net-Security Early Warning System
Raytheon will provide a $28 million early-warning system for cyber attacks on U.S. military networks
WEB MONKEY
Mozilla Paves The Way For Firefox 3.6 With Second Beta Release
Two weeks after the first beta release of Firefox 3.6, Mozilla is pushing out a second beta, which fixes 190 more bugs
MICROSOFT
Microsoft Releases Six Patches For Windows
Three patches are for vulnerabilities listed as "critical," software giant says
FINEXTRA
U.S. Retailers Face $100B In ID Fraud Losses A Year
Total losses rise to $191B when cost of lost and stolen merchandise is added in, Javelin/LexisNexis report says
THE REGISTER
Raytheon Unveils "Insider Threat" Rooter Out Routers
Detector gear promises to sniff out moles, leaks, whistle blowers
SC MAGAZINE
BBC Site Reported As Vulnerable To Cross-Site Scripting
"Betsie" disability site could be open to attack, researcher says
NETWORK WORLD
Rutgers Researchers Cooking Up Safer Password Clues
NSF-funded research leading to "activity-based" password hints
CHANNEL INSIDER
Midsized Companies Under Siege By Hackers
Volume of attacks on midsize firms has leaped 322 percent over 2008, study says
BANK INFO SECURITY
ID Theft Red Flags Rule: What Have Exams Uncovered?
Most organizations falling into compliance, according to experts
CALGARY HERALD
Recession Heightens Risk Of IT Sabotage
Seventy-five percent of companies are concerned about potential attacks by former employees, Ernst & Young study reports
SOPHOS BLOG
75% Believe Worm Author 'Did Iphone Users A Favor,' Poll Reveals
Sophos poll asked whether the iPhone worm that's spreading in Australia on jailbroken iPhones was justified in that it revealed security issues
NEWS TIMES.COM
Blumenthal To Address Doctors' ID Data Breach
Connecticut Attorney General Richard Blumenthal was due to announce today that his office is investigating a data breach of 18,000 doctors and health care professionals' personal data in the wake of the theft of a Blue Cross/Blue Shield employee's laptop
TREND MICRO BLOG
Koobface Abuses Google Reader Pages
The Koobface gang is now using Google Reader to spam malicious URLs to Facebook, MySpace, and Twitter
INFORMATIONWEEK
Facebook Security Crisis Could Derail Social Nets
A rash of phishing attacks on Facebook users could derail the progress of social networking in business
NETWORK WORLD
Boston Celtics Clamp Down On Spam
Pro basketball team goes with Mimecast software-as-a-service option
THREAT POST
How To Take Down A Botnet
A look at how FireEye successfully disrupted the Mega-D botnet by knocking most of its command-and-control servers offline and working with the affected registrars
NEWS.AU.COM
Blackouts A Result Of Cyber Hacking
Massive power outages in Brazil in 2005 and 2007 were the result of hackers, according to a report on CBS' "60 Minutes"
THE WASHINGTON POST
Nastygram: MySpace Phish Plants Spy Software
A new spam campaign targeting MySpace.com users lures victims into giving up their MySpace credentials and then attempts to trick victims into installing password-stealing malware
TECH TARGET
NERC CSO Warns Of Cybersecurity Threats, Vulnerable Electric Grid
Says addressing security of smart grid poses new challenges for utility companies and security executives
SOPHOS BLOG
Mossad Hacked Syrian Laptop Before Bombing Nuclear Facility
Der Spiegel reports that agents working for Israel's intelligence service planted a Trojan horse on a senior Syrian government official's computer in order to gather information that later led to an air-raid on a nuclear project in Syria
THE WALL STREET JOURNAL
Google Creates Privacy Dashboard
Google Dashboard service lets users see and delete their search history
SC MAGAZINE
Mass. Data Law Finalized
Data security regulations for Massachusetts take effect March 1, 2010 -- this final version clarifies the deadline by which companies must impose the provisions on their third-party providers
CISCO
False Facebook Agreement Renewal E-mail Messages
Spam email claiming to be notifications from Facebook to update the user's account are increasing -- and contain an infected attachment
IT PRO
Cyber Criminals See Charities As Easy Targets
Nonprofits often hold sensitive information on donors, such as credit card transactions, yet much of the time don't have the budget to properly protect their data
INFORMATIONWEEK
Microsoft Plans Fixes For 15 Flaws
Four of the bulletins -- three rated "critical" -- affect Windows, and two "important" ones affect Microsoft Office for Windows and Mac
NETWORK WORLD
Three-Year-Old Office Patch Stymies Most Attacks
The MS06-027 patch, which was issued in June 2006, stops nearly three-fourths of all known attacks, according to Microsoft
NETWORK WORLD
Botnet Authors Crash Wordpress Sites With Buggy Code
Other sites that use complex PHP are also affected
CBS NEWS
Congress May Require ISPs To Block Fraudulent Websites
Bill would require providers to block access to online financial scams that invoke the Securities Investor Protection Corp.
TECH WORLD
Microsoft's Calls On Bug Exploits 'Worse Than A Coin Toss'Exploits
Software giant is rarely correct when predicting which vulnerabilities will be exploited, experts say
SYMANTEC
November 'State Of Phishing' Report (PDF)
Phishing attacks up 17 percent over previous month, Symantec report says
NETWORK WORLD
Review: Whitelisting Security Comes Of Age
Whitelisting products demonstrate why they may be the best solution for preventing modern malware
COMPUTERWORLD
Microsoft 'Neutered' UAC In Windows 7, Says Researcher
Only one out of eight Trojans are blocked from executing, Sophos says
H SECURITY
Cracking Keys On The Cheap In The Cloud
Cloud computing power may help hackers break encryption codes, study says
SEARCH SECURITY
FTC Announces Fourth Red Flags Rule Extension
Corporations will get more time to comply
GOVINFOSECURITY
Infosec Among Hottest Professions In U.S.
Money magazine says information security jobs get a personal satisfaction rating of an "A," with median pay at under $100,000 and $152,000 at the high end
ADOBE
Security Updates Available For Shockwave Player
Adobe has issued a patch for critical vulnerabilities in Windows and Macintosh versions of Adobe Shockwave Player 11.5.1.601 and earlier versions
HELP NET SECURITY
Intelligence Agency Hit By DoS Attacks
The Website of Sweden's intelligence agency -- Swedish Signals Intelligence Agency -- was hit with a massive distributed denial-of-service attack and had to be shut down temporarily
HARVARD UNIVERSITY BELFER CENTER
Melissa Hathaway: "Strategic Advantage: Why America Should Care About Cybersecurity"
Hathaway describes the vulnerable state of U.S. networks to cyberattacks
EWEEK
Man Indicted in Cable Modem Hacking Scheme
The FBI has charged Ryan Harris, 26, with developing hardware and software tools to enable people to configure their cable modems to give them free Internet access
NETWORK WORLD
Microsoft Re-Patches Last Month's Critical IE Update
Microsoft yesterday re-patched Internet Explorer for the MS09-054 vulnerability
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



