Best Of Web
Best Of The Web
THE REGISTER
Newfangled Cookie Attack Steals/Poisons Website Creds
A researcher discovered a flaw in a core browser protocol that lets an attacker tamper with the cookies set by Google, Facebook, and other Websites
TREND MICRO COUNTERMEASURES BLOG
Sophisticated Banking Trojan -- Human Consequences
The inside story of a victim of the Bebloh /URLZone banking Trojan whose bank account was pilfered, and the unwitting money mule who was to transfer the stolen funds overseas
V3.CO.UK
USB Stick Security Flaw Puts Data At Risk
Security firm warns of imminent threat to sensitive information
SOPHOS
Windows 7 Vulnerable To Eight Out Of Ten Viruses
In early tests, new OS doesn't look so squeaky-clean
ZDNET UK
Former YouSendIt Chief Accused Of DoS Attack
Co-founder launched four attacks against his former company, FBI says
InSING.COM
Firms See Opportunities In Cybersecurity Industry
As governments expand cybersecurity initiatives, market opens up
TECHWORLD
Microsoft Security Patches Go Past 400 Mark
Software giant has dealt with 745 vulnerabilities since 2003, according to informal count
IT BUSINESS CANADA
Banking Fraudsters Target Internet Phone Systems At SMBs
Cybercriminals use hacked phone systems to try to convince bank customers to give up their passwords
eWEEK
Security Vendors Take A Hybrid Approach To Web Filtering
Cloud-based URL filtering is likely to continue to gain traction, experts say
SC MAGAZINE
Security Industry "Not Making Much Difference," Report Says
McAfee study reports 500 percent jump in malware last year
THE HUFFINGTON POST
Cyberattacks Traced To North Korea
The North Korean government was behind hacks that caused Web outages in South Korea and the United States in July, as the attacks were traced to North Korea's Ministry of Post and Telecommunications
CIO
FTC Delays Identity Protection Rules Till June 2010
The Federal Trade Commission has delayed the enforcement of its Red Flags identity protection rules until June 1, 2010, at the request of Congress
THE WASHINGTON POST
Dozens In Congress Under Ethics Inquiry: An Accidental Disclosure
A confidential House Ethics Committee report detailing investigations of over 39 lawmakers and some Congressional aides was inadvertently made available on a file-sharing network
NETWORK WORLD
Typewriter Puts Identity Thieves In Federal Prison
A typewriter ribbon containing 400 names and Social Security numbers was discovered and used as evident to charge its owners with identity theft
THE WALL STREET JOURNAL
Manhattan DA: Computer Technician Charged In Identity Theft
A computer technician was charged with allegedly stealing the identities of over 150 Bank of New York Mellon employees and using them to steal more than $1.1 million from charities, non-profit groups and others, prosecutors say
SPAMFIGHTER
W32/Xpaj Botnet Expanding Fast
A new computer worm named W32/Xpaj is spreading fast and evades detection and elimination
FBI
Former CEO Of YouSendIt Charged With Denial of Service Of Attack
Khalid Shaikh, a former CEO of YouSendIt, was indicted by a federal grand jury for allegedly launching denial-of-service attacks on the company's servers
TREND MICRO BLOG
Malware Conceals Itself As Boss's Letter
Researchers found spammed messages that pose as a letter coming from the "boss" that includes the Cutwail Trojan in an executable file attachment
TREND MICRO BLOG
Trick Or Threat?
October is a big month for social engineering tactics with a Halloween theme, and many result in identity theft
COMPUTER WEEKLY
Facebook Gets $711m Damages In Spam Case
Facebook has been awarded $711 million in damages by a court in California in an anti-spam case against an online marketer
RANDOM HACKS OF KINDNESS
Random Hacks of Kindness Events Begin With 'Codejam'
Camp brings together disaster relief experts and software engineers to work on identifying key challenges to disaster relief, and developing solutions
IT WIRE
When Hackers Get The Blues
Australian technician started a Website called bluehackers.org for hackers who suffer from depression
THREAT POST
Gumblar Attacks Spread To Thousands Of New Sites
Kaspersky Lab researcher has found Gumblar pointing victims to thousands of servers in more than 200 countries, and over 7,200 servers in the U.S. are spreading Gumblar
YAHOO NEWS
US-CERT Moves In With NCC, NCSC
A new unified operations center in Arlington, Virginia, will be home to the U.S. Computer Emergency Readiness Team (US-CERT), the National Coordinating Center for Telecommunications (NCC), and the National Cyber Security Center (NCSC)
COMPUTERWORLD
Amazon Downplays Report Highlighting Vulnerabilities In Its Cloud Service
Amazon says it has taken steps to mitigate a security issue in its cloud computing infrastructure recently revealed by MIT and the University of California at San Diego
GOVERNMENT COMPUTER NEWS
DOD Open-Source Memo Could Change Software Landscape
The Defense Department's new guidelines on the military's use of open-source software should ease the widespread security and other concerns
TECHNOLOGY REVIEW
Vulnerability Seen In Amazon's Cloud Computing
New research reveals how to find would-be victims within cloud hardware
MASHABLE
New Twitter Phishing Scam Spreading Via Direct Message
Social networking organization warns users not to fall for scam
FINEXTRA
Two-Headed Trojan Attacks Online Banks
W32.Silon bypasses tokens, banking card readers to deliver malicious payload
INFO SECURITY
Outsourcing Providers Should Prove IT Security Credentials
Prevalence of outsourcing means third parties should prove their security chops
CNET
Survey: Few Companies Addressing Cyberterrorism
Only one-third of companies include cyber attacks in their disaster recovery plans
ABC AUSTRALIA
New Group Spies Rise In Cybercrime
Newly formed group in Australia calls attention to current trends
GOVERNMENT INFO SECURITY
Feds To Build Cybersecurity Data Center
NSA will run $1.5 billion facility near Salt Lake City
FORBES
Is Your Online Bank Account Safe?
If hackers get into a commercial account, you're out the money
COMPUTERWORLD
Internet Phone Systems Become The Fraudster's Tool
Cybercriminals have hacked into dozens of business telephone systems across the U.S., using them to trick customers into divulging their bank account numbers and passwords
SOPHOS
Critical Flaws Fixed In Firefox 3.5.4
Mozilla has issued an important update that fixes a number of critical flaws
TERRANET
Swiss Foreign Ministry Hit By Computer Attack
Hackers broke into the Swiss foreign ministry's computer system to seize data, which resulted in parts of the system being shut down for several days
SEARCHSECURITY
Group To Shed Light On Secure Identity Management Threats
The Center for Applied Identity Management Research (CAIMR) says identity address management isn't keeping pace with the constantly changing threat landscape
AUSTRALIA.TO
Hacker Indicted For Targeting Websites He Found Objectionable
A Pennsylvania man was indicted by a federal grand jury on hacking charges in which he allegedly built a botnet and DDoS'ed Rolling Stone's Website, among others
RIM OF THE WORLD
Lake Arrowhead Pharmacist Arrested On Drug Charges
Pharmacist who peddled pills online and in store was arrested for allegedly illegally selling a muscle relaxant
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
- HP Newsletter with Gartner Research: Maximizing Your Infrastructure through Virtualization
- Understanding Holistic Database Security 8 Steps to Successfully Securing Enterprise Data Sources
- A How-To Guide on Using Cloud Services for Security-Rich Data Backup
- Holistic Risk Management: Perspectives from IT Professionals
- Aligning IT with strategic business goals: A proactive approach to managing IT risk to your business
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2012-4697
TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to obtain administrative access via an FTP session.
CVE-2011-4520
Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
CVE-2011-4519
Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
CVE-2011-4518
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2012-6563
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.


