Best Of Web
Best Of The Web
F-SECURE BLOG
Mass-Generating Fake Twitter Accounts For Profit
F-Secure is spotting more autogenerated malicious Twitter accounts that look real
CLICKFORENSICS BLOG
Beware The 'Bahama' Botnet
Researchers say the Bahama botnet appears closely related to the recent spate of scareware attacks
MICROSOFT ON THE ISSUES
Bad Ad: Going After The Malvertising Threat
Microsoft files five civil suits against promulgators of fake antivirus software
COMPUTERWORLD
Sophisticated Botnet Causing A Surge In Click Fraud
New botnet is able to skirt defenses of search engines, Web publishers, researchers say
ELECTRONIC FRONTIER FOUNDATION
Court Holds Disloyal Computer Use Is Not A Crime
Sending files to yourself doesn't constitute "unauthorized access" under Computer Fraud and Abuse Act, court says
DM News
Online Shopping Cart Deserters Today May Be Buyers Tomorrow, Study Says
Many shoppers abandoning online shopping carts due to security concerns, researchers find
MX LOGIC
Microsoft Ending Security Support For Windows Server 2000
Extended support for Windows Server 2000 and Windows Server 2003 will end next July
CHANNELWEB
Five Top Cybersecurity Risks
Unpatched apps account for two of the top five, report says
SECURITY PRO NEWS
Security Concerns Hindering Adoption Of Cloud Computing, Study Says
In survey, enterprises say that security and privacy are among the chief reasons for holding off
OFFICE OF INADEQUATE SECURITY
ID Theft Ringleader Back In Custody After Four Years On The Lam
Ronald Hyppolite pleads guilty after avoiding law enforcement for years
PUREWIRE BLOG
PBS Website Compromised, Used To Serve Exploits
PBS.org's Website serves exploits from a malicious domain via an iFrame -- possibly as part of a botnet buildout
THE REGISTER
IETF Forges Botnet Clean-Up Standard
Draft IETF standard provides techniques for ISPs to identify compromised machines, plus guidelines for notifying affected customers and how to help them clean up
THE WASHINGTON POST
Cyber Crooks Target Public & Private Schools
A gang of organized cybercriminals who stole millions from U.S. businesses have a new target
GOVERNMENT COMPUTER NEWS
Google Readies Government Cloud Offering
In response to the GSA's launch of its Apps.gov cloud computing storefront, Google says it will soon offer a set of cloud services to government through Apps.gov
FINEXTRA
Bankers Fear Budget Cuts Leave Them Exposed To Rising Tide Of Fraud: Survey
More than 70 percent of banks say fraud has increased during the past year
SECURITY PARK
One In Ten British Web Users Is Victim Of Online ID Fraud
A YouGov survey commissioned by VeriSign found that 12 percent of the U.K. population has been a victim of online ID fraud within the past 12 months
SANS INTERNET STORM CENTER
Why Is Rogue/Fake AV So Successful?
Persistence of attacks and attention to detail are both contributors
THREATPOST
Google + reCAPTCHA Could Raise Bar In Anti-Bot, Anti-Spam Fight
Google's deal to acquire reCAPTCHA gives Google the tools to provide a CAPTCHA that's nearly impossible for bots to decipher
BLOOMBERG
Homeland Security To More Than Double Staff For Cyber Threats
The Department of Homeland Security plans to more than double the number of employees in one of its cybersecurity units by next year
THE REGISTER
Trial Set For 'Botnet For Hire' Duo
The pair offered one buyer for 15 cents per bot if the buyer purchases 5,000 bot-infected machines or more
H-ONLINE
Survey: Three Out Of Four Administrators Don't Trust Anti-Virus Software
Recent study found CIOs and security administrators don't believe antivirus can prevent zero-day attacks
SEARCH SECURITY
Brute Force Attacks Target Yahoo Email Accounts
Attackers targeting Yahoo cracked passwords via automated password cracking scripts on a Yahoo Web services-based authentication application
SC MAGAZINE
Government Cloud Initiative Introduced, Security Focus Promised
Vivek Kundra, the federal CIO appointed by President Obama, has announced on a cloud computing initiative designed to cut spending on government data centers, but with a high level of security
THE HARMONYGUY
The Month Of Facebook Bugs Halfway Report
Hacker has reported 19 vulnerable Facebook applications -- all but one have been patched, 12 were verified by Facebook, 13 were vulnerable to clickjacking
TMC NEWS
Committee Examines Growing Cyber Threat To Businesses
Homeland Security and Governmental Affairs Chairman Joe Lieberman and Ranking Member Susan Collins participate in a hearing focused on how the federal government can help SMBs defend themselves against attacks
THE WASHINGTON POST
Data Breach Highlights Role Of 'Money Mules'
Maine-based heating and hardware firm Downeast Energy & Building Supply suffered a breach that resulted in the theft of more than $200,000 from its online bank account; hackers used online money mules to move money
TACTICAL WEB APPLICATION SECURITY
Distributed Brute-Force Attacks Against Yahoo
In large-scale attack, spammers beat the bushes to find valid email accounts
IT PRO PORTAL
NY Times Credibility Affected By Malicious Advertising Campaign
"Malvertising" causes readers to see bogus ads, newspaper says
WEBSENSE
Malicious Sites Grow 233 Percent In Six Months
Number of malicious sites has grown 671 percent in the past year, report says
YAHOO! TECH
Cybercriminals Targeting Small Businesses
Bad guys look to victims who don't have the resources to keep up with the threats, officials say
TECH HERALD
A Guide To Facebook Security And Privacy
Detailed guide offers users advice on how to safely use the social networking site
INFORMATION SECURITY RESOURCES
Developing Social Media Policies For Business
The NFL restricts the use of Twitter on game days. Should your company take a similar approach?
BIZ NETWORK
Spammers Turn To Social Networks To Proliferate Porn Spam
Approximately 15 percent of traffic on Twitter is porn spam, researcher says
GOVERNMENT INFORMATION SECURITY
Testimony: Hackers Better Organized Than Government
Attackers do a better job of information-sharing than defenders in business and government, DHS official says
SOPHOS
Shouldn't Protecting IPhone Users From Phishers Be Easier Than This?
Apple says iPhone OS 3.1 users aren't going through the proper process to launch its new anti-phishing feature; they need to launch Safari, connect to a WiFi network, and charge their iPhones with the screen turned off
MASHABLE
Joe Wilson's Payments Provider Reports DDoS Attack
Piryx says it was targeted in a DDoS attack due to its hosting of a fundraising campaign for Congressman Joe Wilson
BANK INFOSECURITY
Chase Bank Notifies Customers Of Breach
A computer tape with Chase Bank customers' personal information was reported missing from a third-party vendor's storage facility
COMPUTERWORLD
Windows Bug Enables PC Hijacking, Microsoft Warns
A bug in the Server Message Block (SMB) 2 network file- and print-sharing protocol in Vista, Windows Server 2008, and the RCs of Windows 7 and Windows Server 2008 R2 could be used to hijack PCs
SC MAGAZINE
ISPs Asked To Cut Off Malware-Infected Pcs
The Internet Industry Association has drafted a new code of conduct that suggests ISPs contact, and in some cases disconnect, customers that have malware-infected computers
CHANNEL INSIDER
California Leads The Nation In Breach Disclosures
A bill awaiting the governor's signature will require any company operating in California or holding data on its residents to provide victims of an unencrypted data breach with guidance on how to guard their identities and what to do after their identity was compromised
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3744
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.
CVE-2013-3743
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 45 and earlier and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.
CVE-2013-2473
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2472.
CVE-2013-2472
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2473.
CVE-2013-2471
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2472, and CVE-2013-2473.



