Best Of Web
Best Of The Web
PANDALABS BLOG
Blackhat SEO Aggressively Targets Halloween Related Keywords
Rogueware distributors are now poisoning search results to increase traffic to their sites -- using Halloween-related keywords as a lure
THE WASHINGTON POST
Former Anti-Virus Researcher Turns Tables On Industry
A security researcher shunned by the antivirus community has put up a Web service for malware writers to use to make their viruses stealthier and undetectable for longer periods of time
CNET
Fake Facebook Email Contains Trojan
New variant of Bredolab Trojan is attached to fake password reset confirmation
COMPUTERWORLD UK
Avalanche Phishing Gang Dominates Online Scams
Gang accounts for one-quarter of all phishing attacks in U.K.
CALIFORNIA AP NEWS
Judge Rejects TD Ameritrade Data Theft Settlement
Judge says deal offers little significant benefit to 6 million victims in class action lawsuit
SECURE COMPUTING AUSTRALIA
IBM To Open Business Intelligence Center To Tackle Cybercrime
Centers planned for Washington and London
INFORMATIONWEEK
Top 10 Email Blunders Of 2009, So Far
Many organizations have yet to deal with the risks of email, report says
REUTERS
Study U.S. Small Businesses Lack Cybersecurity Awareness And Policies
Survey shows discrepancies between needs and actions when it comes to security
INTERNATIONAL BUSINESS TIMES
China Strengthens Cyberwar Arsenal Against United States
Congressional panel says country's elite hackers may have ties to Chinese government
GOVERNMENT INFO SECURITY
House Talks Healthcare, Votes Infosec
In Congress, several security-related bills are pulled together and advanced
THE TECH HERALD
Researcher Discloses SQL Injection Flaw On Barackobama.Com
Web hosting firm Blue State Digital disputes hack of Barackobama.com site
PC MAGAZINE
Research Downplays Prospect of Cyber Wars
A new report from The Center for Strategic and International Studies downplays the prospects of serious cyber attacks and argues that existing cyberattacks in Estonia weren't true act of war
WIRED
Scan of Internet Uncovers Thousands of Vulnerable Embedded Devices
Researchers have found nearly 21,000 routers, Webcams, and VoIP products open to remote attack due to using manufacturer's default passwords
THE WASHINGTON POST
FBI: Cyber Crooks Stole $40M From U.S. Small, Mid-Sized Firms
FBI says scams stole online banking credentials via malware in spam messa
COMPUTERWORLD
Analysis: Real ID Program On Life Support
Congress has cut funding by 40 percent for the controversial Real ID national driver's license program
CBS NEWS
Socialite Charged With Hacking Voice Mail
Former Dolce & Gabbana publicist accused of hacking into voicemails of other women, including one who dated her ex-boyfriend
MAKE USE OF.COM
Facebook Impostors -- Tips For Your Profile To Stay Safe From Scammers
Remove yourself from public search listing, screen your messages, and be careful which apps you add
ZDNET
Guardian Site Hack May Affect Half A Million
Recent hack of The Guardian's jobs Website may have left personal data of up to a half-million people at risk
GOVINFOSECURITY
Search On For 1,000 DHS Infosec Pros
The Department of Homeland Security has begun the search process to hire the first 150 of the up to 1,000 cybersecurity professionals it has promised to add -- among the top two jobs are positions that pay up to $177,000 a year
THREAT POST
'Avalanche' Crimeware Kit Fuels Phishing Attacks
A cybergang called "Avalanche" executed nearly one-quarter of all identity theft-related phishing attacks in the first half of 2009, according to a new report by the Anti-Phishing Work Group
COMPUTERWORLD
Microsoft Wants ISO Security Certification For Its Cloud Services
Microsoft plans to have its suite of hosted messaging and collaboration products certified to the ISO 27001 international information security standard in an effort to reassure customers about the security of its cloud computing services
THE REGISTER
Botnet Click Fraud At Record High
Nearly 43 percent of fraudulent clicks in the third quarter of this year were generated by computers that were part of botnets, compared with 36.9 percent the previous quarter
COMPUTING
Zurich Loses Financial Details Of 51,000 UK Customers
Insurance company Zurich lost the personal data of 51,000 U.K. customers in South Africa last year when moving data offsite to a data storage center
VNUNET
One In Five Americans Use Social Networking Updates
New research from the Pew Internet and American Life Project found that 19 percent of people use services like Twitter, up from 11 percent less than a year ago
ARS TECHNICA
Nigeria Actually Arrests, Shuts Down Online Scammers
Nigerian law enforcement has shut down nearly 1,000 Websites and made 18 arrests as part of a new initiative to save the nation's reputation and crack down on Internet scammers
NETWORK WORLD
Privacy Advocate Has Ally In Social Security Numbers Fight
The Electronic Privacy Information Center filed a friend of the court brief asking the U.S. Court of Appeals to uphold privacy advocate Betty Ostergren's First Amendment right to republish Social Security numbers obtained from public records on government sites
WALL STREET JOURNAL
China Expands Cyberspying In U.S., Report Says
Congressional report says Chinese government is ratcheting up intelligence efforts
UK PAYMENTS ADMINISTRATION
Banking Industry Warns About A Growing Card Fraud Scam
Phone callers pretend to be bank officials, or even the police
ZDNET UK
'G Cloud' Offers New Approach To Security, Government Told
Cloud computing model could change security model, speakers say
PC WORLD
Experts See Forecast Worsen For Cybercrime
Bad guys becoming more organized, sophisticated, law enforcement officials say
BANK SYSTEMS AND TECHNOLOGY
Information Security Still A Priority In IT Budgets
PricewaterhouseCoopers study says security spending may even increase at some companies
AUSTRALIAN IT
Hacker's Gave Notice Before Striking PM's Website
Site's defenses should have been better, given early warning, experts say
GOVERNMENT COMPUTER NEWS
Cyber Threat Looms, But Its Full Scope Remains Murky
Defense agencies need to work more closely with security experts, observers say
TG DAILY
Australian Atheists Targeted By Hackers
DDoS attacks hit Websites of global convention organizers
COMPUTERWORLD
We've Been Blind To Attacks On Our Web Sites
Security manager finds his organization's Web sites are being "scraped" by its competitors
HEISE ONLINE/strong>
Researchers Read The Cryptographic Keys Of Mobile Phones
Security researchers at Cryptography Research have found a way to read the encryption and user authentication keys required for mobile devices
IANS
Nick Selby: Metasploit Acquisition Shakes Up The Pen-Test Landscape
Rapid 7's purchase of Metasploit gives enterprise customers three legitimate penetration testing tools and, ultimately, better prices, quality, and functionality
EWEEK
E-Health Records: Privacy Diagnosis Poor
New survey says 80 percent of health care organizations reported a data breach within the past year
THE DAILY MAIL
Fresh Hope For Gary McKinnon As His U.S. Extradition Is Delayed
The Home Secretary has halted Gary McKinnon's extradition to mull new medical evidence about McKinnon's mental state
WIRED
Time Warner Cable Exposes 65,000 Customer Routers To Remote Hacks
A vulnerability in Time Warner cable modems and Wi-Fi routers at 65,000 customer sites can allow a hacker to remotely access the devices' administrative menu and change the settings to intercept traffic
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3270 (vnx_control_station, celerra_control_station)
EMC VNX Control Station before 7.1.70.2 and Celerra Control Station before 6.0.70.1 have an incorrect group ownership for unspecified script files, which allows local users to gain privileges by leveraging nasadmin group membership.
CVE-2013-1014 (itunes)
Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
CVE-2013-1011 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
CVE-2013-1010 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
CVE-2013-1008 (itunes)
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.


