Best Of Web
Best Of The Web
TREND MICRO BLOG
Fake Windows Live Malware Spreads Via Email
The primary function of the botware appears to be MSN-spamming
INFORMIT
Common Activities For Getting Started With Software Security
BSIMM Begin was launched last week by Cigital and is a Web-based survey on BSIMM activities
THE CHARLOTTE OBSERVER
Hacker Breaks Into Research Study Data
The personal data of 236,000 women enrolled in a UNC Chapel Hill research study using mammography data is breached
THE WASHINGTON POST
'Money Mule' Recruitment Network Exposed
Security Fix interviews a mule hired to receive money from a Colorado school system that was bilked of $117,000 when hackers used the district's online banking credentials to send sub-$10,000 payments to this mule and others
GOVERNMENT COMPUTER NEWS
Sharing Threat Data Is Key To Securing The Power Grid
EnergySec organization helps organizations share threat and vulnerability information
MCAFEE
Inside The Password-Stealing Business: The Who And How Of Identity Theft
New programs take pictures of the victim's screen to capture passwords, and gaming passwords are the most targeted on the Net
MASHABLE
Twitter Worm Spreading Via Direct Messages
A new worm and phishing scam is making the rounds on Twitter and using DMs to take over user accounts
METASPLOIT BLOG
Forcing Payloads Through Restrictive Firewalls
Metasploit adds the ability to brute-force a connection through a restrictive outbound firewall
THREAT POST
Cisco Plugs Holes In IOS Software
Cisco issues an update for IOS that patches flaws that could allow denial-of-service or policy bypass attacks
COMPUTERWORLD
Google Chrome Add-In For IE: Speed Demon Or Big, Fat Security Hole?
IE8 with the Chrome Frame plug-in may be theoretically less secure than IE8 without the plug-in, but it's not a major security threat
FEDERAL COMPUTER WEEK
DOD Repurposed IT Equipment Without Scrubbing Sensitive Info, Audit Reveals
Inspector General audit also finds one DoD organization that had altogether lost track of an unclassified computer
PC WORLD
Contractor Pleads Guilty To SCADA Tampering
A former IT consultant for an oil and gas exploration company admits to accessing Pacific Energy Resources' SCADA computers after getting turned down for a permanent position
DEFENCE INTELLIGENCE
Half Of Fortune 100 Companies Compromised By New Information Stealing Trojan
Defence Intelligence says a new information-stealing botnet it calls Mariposa is alive in 50 Fortune 100 firms, as well as government agencies and universities
SOPHOS BLOG
Sophos Free Encryption
Sophos now offers a free encryption utility to encrypt and compress sensitive information
TIME
Are Med-Student Tweets Breaching Patient Privacy?
Sixty percent of medical school deans reported incidents of unprofessional postings, and 13 percent said they had experienced incidents that violated patient privacy
GOVSECURITYINFO.COM
Compelling Cybersecurity 'Czar' To Testify
An amendment introduced by Sen. Susan Collins would require the as-yet unnamed cybersecurity coordinator and other so-called 'czars' from the White House to testify before Congress or face losing funds for their offices
ZDNET BLOG
Modern Banker Malware Undermines Two-Factor Authentication
Crimeware can now bypass two-factor authentication by waiting for the crimeware-infected user to authenticate himself so the attacker can then attack in real-time
THE REGISTER
Email-Stealing Worm Slithers Across Livejournal
LiveJournal's security team disables some features on the blogging site after a worm stole user email addresses and exposed private areas on the site to all users
NEWSDAY
Madoff Investors' Security May Have Been Breached
More than 2,200 Bernard Madoff investors have been informed that their personal and financial information was potentially breached in the wake of the theft of a laptop in July
YAHOO NEWS
Chinese Cyberattacks Target Media Ahead Of Anniversary
Foreign media in China have been targeted with malware-infested email that appear to be tied to the run-up to the National Day military parade on Oct. 1
THREAT POST
Google: Cooperation Needed To Combat Malicious Ads
Google's head of anti-malvertising suggests an industrywide coalition of ISPs and others could help stop malvertisers
EWEEK
Lawmakers Revive Effort To Deny Retroactive Telecom Immunity
Key provisions of the Patriot Act are set to expire, and legislators are proposing a bill that would repeal immunity for telecom companies spying on U.S. citizens without warrants
INFOSECURITY MAGAZINE
PayPal Embraces Text Messages As Security Check System
PayPal has rolled out a text message security check system for its electronic cash and payment service
COMPUTER WEEKLY
Expert Challenges UFO Hacker's $700k Bill
An expert witness statement says the U.S. inflated damages charged to Gary McKinnon by including costs for patching the gaping holes the hacker had exposed in its computer security
SEARCHSECURITY
First Data, RSA Push Tokenization For Payment Processing
While tokenization help merchants meet PCI requirements, it doesn't replace encryption, Gartner says
TREND MICRO COUNTERMEASURES BLOG
Razer Downloads Distributing Malware
Gaming peripherals vendor has taken down its infected Webpages that were serving up malware to visitors
MIT TECHNOLOGY REVIEW
Real-Time Hackers Foil Two-Factor Security
One-time passwords may be vulnerable, researchers say
TECH TARGET
FCC Launches OpenInternet.gov, Proposes New Net Neutrality Principles
Service providers shouldn't be able to discriminate based on user, content, FCC chair says
eCAMPUS NEWS
Study: 600K Campus Records Hacked This Year
Report calls America's universities a "hacker's dream"
SEARCH SECURITY
Security Challenges With Cloud Computing Services
Panel discusses vulnerabilities, challenges for cloud environments
EZINE
The Five Most Dangerous Internet Security Myths
It's time to face reality on these five bits of popular wisdom
H SECURITY
Patent Infringement Lawsuit Against Apple and eBay
TQP alleges that others are using its patented technology for encryption key management
INFORMATION SECURITY RESOURCES
Should Cyberdefense Go On The Offensive?
There is no sane way to use government computers to launch a DDoS attack, expert says
IT PRO PORTAL
Scammers Trick BT Subscribers Into Giving Out Their Credit Card Details
Fraudsters "cut off" users' phone service to "prove" their authority
ABA JOURNAL
Feds Can Monitor Personal E-Mail Sent Privately To Gov��t Workers, DOJ Says
Recipients and senders have no reasonable expectation of privacy if an e-mail is opened by a federal employee logged into a work computer network, DoJ ruling says
GOVERNMENT COMPUTER NEWS
Security Will Not Come Naturally With IPv6
IPv6 can be used to block, shield, and hide data on your network, and the hackers already are studying how to exploit these features, expert says
TRADERS MAGAZINE
Code Thefts Don't Worry Brokerages
Despite the UBS and Goldman Sachs cases, electronic trading executives say they're not worried about employees walking out with trade-secret source code
SILICON.COM
Apple's Snow Leopard Won't Make Us Move To Macs, Say CIOs
Just one out of 12 surveyed CIOs say the launch of Snow Leopard will make their IT departments more likely to adopt Mac OS X machines
MICROSOFT TECHNET BLOG
Update On The SMB Vulnerability Situation
Microsoft says to disable support for version 2 of the SMB protocol as a defense against attacks exploiting the Microsoft Server Message Block Version 2 (SMBv2) vulnerability affecting Windows Vista and Windows Server 2008
CIO
Misdirected Spyware Infects Ohio Hospital
An Ohio man will plead guilty to federal charges after spyware he allegedly sent to a woman ended up infecting computers at Akron Children's Hospital
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3562
Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-3561
Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.
CVE-2013-3560
The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-3559
epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (integer overflow, and heap memory corruption or NULL pointer dereference, and application crash) via a malformed packet.
CVE-2013-3558
The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not terminate a bit-field list, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.


