Best Of Web
Best Of The Web
ENIGMA SOFTWARE
Fraud Alert: Avoid Fake U.S. 2010 Census Scams
Cybercriminals may look to take advantage of unsuspecting citizens, expert says
SECUREWORKS
The Underground Economy Of The Pay-Per-Install Business
Report describes methods and economics of distributing malware and spyware
SECURITY PARK
Academic Institutions Adopt Two-Factor Authentication To Filter Admission To Their Network
Universities also must comply with privacy laws, such as HIPAA and FERPA, so many are rolling out two-factor authentication for their networks
BBC NEWS
Anti-Wi-Fi Paint Offers Security
Researchers say they have created a special kind of paint that can block out wireless signals
SECUROSIS
Tokenization Will Become The Dominant Payment Transaction Architecture
Encryption is only a stop-gap -- tokenization is the future of transaction security
PC ADVISOR
BlackBerry Users Get Patch For Phishing Flaw
Research In Motion has released a patch to fix a site certificate bug that could be exploited by phishers
CNET
Targeted E-Mails Distribute Malware In Paychoice Breach
Paychoice employees received e-mail last week telling them to download a browser plug-in or visit a Web site so they could continue accessing the company's Onlineemployer.com portal, and the company temporarily shut down the site to investigate
INFORMATION SECURITY RESOURCES
Top Ten Smart Grid Privacy Concerns
Identity theft, targeted home invasions, determining personal behavior patterns, and real-time surveillance are among the security and privacy worries about the smart grid
THE GUARDIAN
Crackdown As Fraudsters Target Facebook Users
Facebook has closed down fake accounts that were being used to target the site's users
SC MAGAZINE
Two Accused Romanian Phishers Plead Innocent
Romanian men charged in a massive phishing scam plead innocent to charges of bank fraud and aggravated identity theft
SEARCH SECURITY
Phishing Websites, Rogue Antivirus Attacks Skyrocket In 2009
Anti-Phishing Working Group study says attacks continue to grow
ENIGMA SOFTWARE
Windows SMB2 Vulnerability: Ability To Run Unauthorized Software On Exploited Vista PCs
Newly released code could result in worm outbreak, researchers say
ZDNET UK
Researchers' Protocol Denies DoS Attacks
New method could help filter out denial-of-service attacks in enterprise networks
IT KNOWLEDGE EXCHANGE
Twitter Gets Condemned By CISOs At Forrester Forum
Security pros applaud keynote speaker's assertion that Twitter is dangerous -- but is this view realistic?
INTERNET NEWS
DHS Recruiting 1,000 Cybersecurity Experts
At kickoff of National Cybersecurity Awareness Month, agency announces funding to staff up
ASIAONE
Singapore Sets Up Cybersecurity Agency
New agency will help defend against online attacks from terrorists and criminals
AVG BLOGS
Automated Facebook Attack Under Way
Rogue spyware attacks appear to be emanating from Facebook, according to researcher
GOVERNMENT INFO SECURITY
Is Security Hampered By Decentralized IT?
California CISO sees decentralization as the state government's biggest security threat
PC WORLD
Texas Governor Blames Web Campaign Flop On Hackers
Rick Perry's 2010 re-election campaign began with a Web site outage that staffers are now calling a denial-of-service attack
SC MAGAZINE
One In 12 Websites Contains Inappropriate Content As Social Networking Sites Hit By Malware
New findings from Webroot reveal that one in 12 Web page addresses have been blocked or questioned due to inappropriate content
THE REGISTER
Bank Snafu Gmail Missive Never Opened
The email at the heart of a bank's lawsuit against Google was never opened, according to the bank, whose employee accidentally sent the message with the wrong Gmail account
THE GLOBE AND MAIL
IT Security Breaches Soar In 2009
IT security breaches cost the average Canadian organization $834,149 in 2009, almost double the amount reported the previous year
NETWORK WORLD
Two Romanians To Face Phishing Charges In U.S.
The men are accused of setting up fake phishing sites to steal user names and passwords from Citibank, Wells Fargo, eBay, and other financial institutions
COMPUTER WEEKLY
ITU Identity Standards Could End Multiple Passwords
Identity management proposal could reduce the number of passwords a user needs to just one
IDG NEWS
ICANN Freed From US Gov't Oversight
Internet Corporation for Assigned Names and Numbers has reached a new agreement with the U.S. Department of Commerce that provides the nonprofit more independence and allows other countries to oversee its operations
WEBSENSE SECURITY LABS
Microsoft Security Essentials SEO Poisoning
Websense Security Labs has discovered that search engine results for how to download Microsoft's recently released Security Essentials tool are returning links to Web sites that serve up rogue AV
THE WASHINGTON TIMES
EXCLUSIVE: Porn Surfing Rampant At U.S. Science Foundation
Investigations of employee misconduct, including accessing pornography from government computers, increased sixfold last year at the National Science Foundation
MAKING IT WORK
OnlineEmployer.Com Data Breach
Data breach at Web-based payroll firm may have been the act of a disgruntled employee
NETWORK WORLD
Organized Cybercrime Revealed
The U.S. attorney for Florida has filed charges against members of the Bonanno crime family organization for alleged cybercrime activity, including a hack at Lexis-Nexis
THREAT CENTER LIVE BLOG
Blackhats Quickly Saturate Google With Tropical Storm Ondoy
Many poisoned search results will take user directly to a Fake AV download, while others are more stealthy
AMERICAN BANKER
Non IT Security Cuts Can Still Hurt IT Security
Overall budget cuts are still hurting banks; 71 percent say fraud attacks have increased during the past year, and 67 percent say financial losses from fraud have increased
SC MAGAZINE
Number Of Phishing URLs At All-Time High
New data from MarkMonitor finds the number of phishing URLs reached a record high during Q2 '09 2009, with more than 150,000
INFOSECURITY MAGAZINE
McAfee Links With Adobe To Co-Develop New Security Software
McAfee and Adobe will jointly develop a combined Data Loss Prevention (DLP) and Enterprise Digital Rights Management (DRM) security software solution
THE REGISTER
Google Shuts Down Bank Snafu Gmail Account
Google resolves a lawsuit from a U.S. bank that accidentally sent 1,300 confidential tax IDs to an innocent Gmail account
THE CHICAGO SUN TIMES
School Cyber Attacks Draw Federal Scrutiny
Cyber-attacks on two Chicago-area school district may also be part of the Clampi virus attacks spreading across schools nationwide and under investigation by federal authorities
HEISE ONLINE
Trojan Hides In Windows Recovery
A Microsoft security specialist said stolen gaming login data has caused $1.2 billion in damage in the U.S.
ISLAND CRISIS
XSS Attack On Reddit -- Beware!
A powerful cross-site scripting attack hit Reddit.com
PRAVDA
New Trojan Virus Hacks the Unhackable
A new type of Trojan can send its owner a PC user's data in real time
MIRROR NEWS
Jail Chaos As Lag Hacker Is Left In Charge Of Computer System
A jailed hacker shut down a prison's computer system after being asked to write special software for an internal TV station in the prison
INFOWAR MONITOR
Targeted Malware Attack On Foreign Correspondents Based In China
Journalists based in China working for media organizations including Reuters, the Straits Times, Dow Jones, and Agence France Presse have been sent targeted emails that contain malicious PDF attachments
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-2059
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
CVE-2013-2007
The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.
CVE-2013-2006
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
CVE-2013-1977
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.
CVE-2013-1964
Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possible have other impacts via unspecified vectors.


