Best Of Web
Best Of The Web
INFORMATIONWEEK
Google Helps Webmasters Spot Malware
Search engine automatically scans for malware as it indexes Web pages
HELP NET SECURITY
NASA Hacker Loses Another Extradition Appeal
High court in U.K. says it won't hear Gary McKinnon's case
NETWORK WORLD
Data-Theft Trojans And The Changing Face Of The Web
Everything you always wanted to know about these nasty exploits but were afraid to ask
WASHINGTON POST
Avoid Windows Malware: Bank On A Live CD
Simple steps allow users to temporarily turn their PCs into Linux machines, reducing the security threat in online banking
TECH REPUBLIC
Crimeware: Looking For Solutions
A look at man-in-the-browser attacks �� and how to stop them
ZDNET AUSTRALIA
NAB Eyes Three-Factor Authentication
National Australian Bank considers adding another layer of security for online banking users
FEDERAL COMPUTER WEEK
DHS Websites Vulnerable To Hackers, Inspector General Says
Audit finds that despite compliance with security protocols, many flaws still exist in DHS systems
CNET
Missing Sidekick Data May Be Gone For Good
Server crash may leave some data unrecoverable for users, T-Mobile warns
ZDNET
Oracle To Patch 38 Flaws
Oracle on Tuesday will issue 38 patches, including critical ones that fix holes in its Core RDBMS, Oracle JRockit, and Oracle Network Authentication
ARS TECHNICA
One Week Of MSE: 1.5 Million Downloads, 4 Million Detections
The free Microsoft Security Essentials tool was downloaded more than 2.6 million times by the second week after it became available, and in the first week, MSE made detected infections on 535,752 distinct machines
INTERNET EVOLUTION
Comcast Takes Revolutionary Security Step
Major ISP takes responsibility for attempting to mitigate bots that are serviced by its network
GOVINFOSECURITY
Fed Regulation Of Private Data Mulled
House Cyber Panel Chair suggests national data breach law to help federal government regulate how the private sector handles and stores data
HEISE ONLINE
Firefox Blocks, Then Unblocks, Microsoft Add-On
Mozilla last week began blocking Microsoft's .NET Framework Assistant add-on for Firefox due to a serious vulnerability, but has reversed its decision after Microsoft confirmed it wasn't vulnerable
CHOSUN
N.Korean Hackers Infiltrated S. Korean Military Networks
South Korea's military network was breached for 24 hours by North Korean hackers on March 5, causing around 2,000 national secrets to leak, according an upcoming issue of the Monthly Chosun
THE WALL STREET JOURNAL
Gartner Eases Forecast For IT Decline
Gartner lessens its projection for how much IT spending will fall this year and says it expects a 3.3 percent rebound in 2010
CNET
Q&A: Defcon's Jeff Moss On Cybersecurity, Government's Role
Black Hat and DefCon leader says DHS needs some of NSA's cybersecurity talent and expects a "loaner program" between the two agencies at first
THE WASHINGTON POST
PayChoice Suffers Another Data Breach
The payroll services provider is hit with what appears to be a second stage of an attack that was first launched against its customers last month
ARS TECHNICA
Deep Packet Inspection Engine Goes Open Source
European DPI vendor has open-sourced a version of its traffic detection engine
SCANSAFE
Stolen Hotmail/Gmail Accounts: Why Data Theft?
Patterns in stolen information indicate the possible presence of a data theft Trojan, researcher says
MICROSOFT
Microsoft To Delay Release Of Next-Gen Security Tool
New Forefront product previously code-named "Stirling" will roll out in the second half of 2010
CLICKFORENSICS
'Bahama' Botnet Hurts Google, Too
Botnet operators are able to steal traffic and revenue from Google via DNS poisoning
RAND
U.S. Must Focus On Protecting Critical Computer Networks From Cyberattack
Study finds that national infrastructure could be targeted in conflicts
V3.CO.UK
Classic Cybercrimes Could Pose Future Threats
Old-school exploits, such as financial market manipulation and social engineering, could morph into threats of tomorrow, experts say
SYMANTEC
Malware-Bearing Spam On The Increase, New Report Says
Nearly 5 percent of all spam contains malware, according to Symantec's State of Spam study
SAULT STAR
Canadian Privacy Czar Issues Warning
Young people are giving up too much personal information on the Web, Stoddart warns
SEARCH SECURITY
FBI Raids Phishing Crime Ring, Nearly 100 Arrested
Group may have ties to cybercriminals based in Egypt, feds say
MASHABLE
More Than Half of Employers Now Block Twitter, Facebook, MySpace
A new survey of 1,400 CIOs found that 54 of companies completely block their employees from social networking sites at work
ZONE-H
FBI Jobs Site Gets Hacked
A Turkish hacker gang exploited a SQL injection flaw on the FBI's jobs site and redirected it to an image with its site name
VISA
Top Five Data Security Trends Impacting Franchise OperatorsBR> Flat networks, default or weak passwords, and using payment processing systems to surf the Web are among the risky practices putting retailers at risk, according to Visa
ITWALES.COM
Cybercriminals Set To Ride Google's Wave
As interest in Google's new Wave technology rises, so will the number of scammers trying to divert Web searches from Wave to malicious sites
COMPUTERWORLD
Former DuPont Researcher Hit With Federal Data Theft Charges
A former research scientist at DuPont USA facing civil charges for allegedly trying to pilfer corporate secrets has now been served with a federal criminal complaint on the same charges
READWRITEWEB
Amazon Web Services Gets DDoS Attack And The Client Waits
An apparent DDoS attack on Amazon Web Services over the weekend left a Web-hosting code service down for about 20 hours before the service came back
THE WASHINGTON POST
Zeus Trojan Infiltrates Bank Security Firm
Security firm Silver Tail Systems infected with the Zeus Trojan a week after the company held an in-depth online seminar for its bank and e-commerce clients about the data-stealing Trojan
SUNBELT BLOG
Trojan.Brontok: 103,000 Infections On One Machine
A machine was discovered harboring six different pieces of malware -- one of which was a Trojan with 102,793 instances on the machine
YAHOO!
World War III Could Be Fought On Internet, Says ITU Head
In cyberspace, there's no such thing as a superpower, expert says
BARRON'S
Emerson Acquiring Avocent For $1.2 Billion
Maker of LANDesk management and security software will become part of Emerson
NETWORK WORLD
How To Stop IT Managers From Going Rogue
New technology focuses on controlling insider threats posed by privileged users
CHANNEL NEWS ASIA
Are Zombie Computers Going To Take Over The World?
Botnet threats continue to grow, researchers say
DAMBALLA
Asprox Rearing Its Ugly SQL Injection Head Again
Exploit launches barrage of SQL injection attacks against Web applications that display potential flaws
INTERNET NEWS
HP Hacking Challenge Yields Surprising Results
If you thought automated security tools were good enough, think again/P>
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.


