Best Of Web
Best Of The Web
NETWORK WORLD
Two Out Of Five At Risk From Wi-Fi Hijacking
Two out of five Web users are at risk of having their Wi-Fi connection hijacked, according to U.K. ISP Talk Talk, and 36 percent still use WEP
TECH TARGET
Gumblar Trojan Drive-By Exploits Spike Following Adobe Update
The attack targets users who failed to deploy patches released last week by Adobe Systems
WIRED
U.S. Spies Buy Stake In Firm That Monitors Blogs, Tweets
CIA investment arm puts cash into Visible Technologies
IT PRO PORTAL
Microsoft Security Essentials Clocks More Than 1.5 Million Downloads In Seven Days
Free scanner detects 4 million instances of malware in its first week
NEW YORK TIMES
When 2+2 Equals A Privacy Question
"Anonymous" customer data that is shared by businesses may not be so anonymous, experts say
GOVERNMENT COMPUTER NEWS
Patch Management: It's Not Sexy, But It Can Keep You Secure
Most attacks are patchable, experts say
SC MAGAZINE
Security Experts Emphasize Social Engineering Risks
Sophos, F-Secure offer proof of social engineering effectiveness
OFFICE OF INADEQUATE SECURITY
Retail Sales Associates Sentenced For Role In Credit Card, Bank Fraud
Insiders aided in thefts and identity fraud, judge says
NETWORK WORLD
Hiring Hackers: A Rebuttal
Former bad guys can be an important resource in the fight against cybercrime, expert says
COMPUTERWORLD
Hijacked Websites Attack Visitors
Some malware attacks target site visitors, rather than the site brands themselves
GOVERNMENT COMPUTER NEWS
Behind The Scenes, James Lewis Helped Bring Cybersecurity To The Fore
Director of the administration's cybersecurity review, James A. Lewis, has been a key voice and advocate for cybersecurity awareness and security of the nation's networks
PC WORLD
Delta Air Lines Sued Over Alleged E-mail Hacking
A passenger rights advocate accuses Delta of obtaining sensitive e-mails and files, and using them to derail the bill
GOVINFOSECURITY
Rockefeller: Be Wary Of The NSA
Senator cautions nominee for director of NIST that NSA won't be easy to work with in cybersecurity collaboration
THE DAILY MAIL
Phone Shopping Puts Card Details Of Millions At Risk As Fraudsters Target Call Centers
U.K. investigation finds 97 percent of call centers are breaking rules on storing personal data
SOFTPEDIA
Traffic Snooping Exercise At Security Conference Ends Ugly
An HTTP traffic-snooping exercise during the SecTor conference this month upset many attendees whose login credentials for various Websites were captured and displayed publicly
WJTV.COM
Patients Didn't Consent To UNC Study Later Hacked
Many women learned that their radiologists had submitted data to the UNC-Chapel Hill mammography study only when they received a letter warning them that their personal data may have been compromised in the UNC hack
GOVERNMENT TECHNOLOGY
The Most Spammed States In The U.S.
Potatoes aren't the only thing growing in Idaho, MessageLabs report says
SUNDAY STAR TIMES
Cybercrime Unit To Late For "Gullible" Pair Who Gave Away $1 Million
Police in New Zealand say they may not be able to help couple who gave up $1 million in Nigerian fraud sca
OFFICE OF INADEQUATE SECURITY
Two Charged For Their Roles In $30 Million Bank Fraud And Identity Theft Ring
Final two of 17 suspects are charged in major international scam
THE AGE
Windfall For Online Fraudsters Down Under
Cybercrime costs Australian economy more than $3 billion a year, official says
MALAYSIAN INSIDER
Wikileaks Founder: People Won't Tolerate Restrictive Laws Much Longer
Laws restricting freedom of speech can't last, hacker/activist says
SMALL BUSINESS TRENDS
Five Tips To Protect Your Business From Online Banking Fraud
Talk to your bank and know your rights in the event of cybercrime, expert advises
THE WASHINGTON POST
PayChoice Suffers Another Data Breach
The payroll services provider is hit with what appears to be a second stage of an attack that was first launched against its customers last month
PC WORLD
Delta Air Lines Sued Over Alleged E-mail Hacking
A passenger rights advocate accuses Delta of obtaining sensitive e-mails and files, and using them to derail the bill
GOVERNMENT COMPUTER NEWS
Behind The Scenes, James Lewis Helped Bring Cybersecurity To The Fore
Director of the administration's cybersecurity review, James A. Lewis, has been a key voice and advocate for cybersecurity awareness and security of the nation's networks
ARS TECHNICA
Deep Packet Inspection Engine Goes Open Source
European DPI vendor has open-sourced a version of its traffic detection engine
GOVINFOSECURITY
Rockefeller: Be Wary Of The NSA
Senator cautions nominee for director of NIST that NSA won't be easy to work with in cybersecurity collaboration
THE DAILY MAIL
Phone Shopping Puts Card Details Of Millions At Risk As Fraudsters Target Call Centers
U.K. investigation finds 97 percent of call centers are breaking rules on storing personal data
SOFTPEDIA
Traffic Snooping Exercise At Security Conference Ends Ugly
An HTTP traffic-snooping exercise during the SecTor conference this month upset many attendees whose login credentials for various Websites were captured and displayed publicly
WJTV.COM
Patients Didn't Consent To UNC Study Later Hacked
Many women learned that their radiologists had submitted data to the UNC-Chapel Hill mammography study only when they received a letter warning them that their personal data may have been compromised in the UNC hack
THE REGISTER
Google's Postini Clogs Email In US, UK
Google's Postini email security and spam filtering system is suffering from a slowdown today, as users in Europe and the U.S. are complaining that the service has been slow to deliver messages
GOVINFOSECURITY
White House Warns Public On Cyber Threat
Top homeland security adviser to President Obama cites in his blog estimates that one-quarter of all personal computers are part of a botnet
GOVERNMENT COMPUTER NEWS
Senior House Lawmaker Urges Obama To Appoint Cybersecurity Czar
Rep. Yvette Clarke (D-N.Y.), chair of a House subcommittee that oversees cybersecurity, called on President Barack Obama to quickly appoint a cybersecurity coordinator
GOOGLE BLOG
Show Me the Malware!
Google has built automated scanners that detect malware on Websites the search engine giant has indexed, and pages identified as dangerous by these scanners are accompanied by warnings in Google search results, and browsers
BANK INFOSECURITY
DHS Secretary, Bank Chiefs Confer On IT Security
Janet Napolitano said the talk focused on corporate needs, obstacles the financial community faces and global threats
TECHCRUNCH
The Evolution Of Click Fraud: Massive Chinese Operation DormRing1 Uncovered
A click fraud ring being run out of China involved 200,000 different IP addresses and racked up more than $3 million worth of fraudulent clicks across 2,000 advertisers in a two-week period
RETURNPATH
An Unwelcome Afterlife For A Long-Dead Blacklist
Bad guys set up new nameservers where blackholes.us nameservers that give a massive zombie blacklist new life, letting it respond to every query as if the IP address were actually on the blacklist
CRN
Twitter Now Outflanks Facebook In Spam Fight
Twitter this week added quick-click links to user pages for members to either block others or report them for spam
WIRED
Big-Box Breach: The Inside Story Of Wal-Mart's Hacker Attack
Newly revealed documents tell the story behind hacks on giant shopping chain in 2005 and 2006
THE WHITE HOUSE
Cybersecurity Awareness Month Part II
Obama adviser offers a look at current threats �� and what citizens should do about them
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3744
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.
CVE-2013-3743
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 45 and earlier and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.
CVE-2013-2473
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2472.
CVE-2013-2472
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2473.
CVE-2013-2471
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2472, and CVE-2013-2473.



