Best Of Web
Best Of The Web
NETWORK WORLD
Domain-Name Abuse Proliferates; Rogue Registrars Turn A Blind Eye
Botnet and phishing operations abuse domain names with the help of rogue registrars
CONSUMERIST
Video: Guy Installing Skimmer On ATM
Surveillance video footage shows a man in Brazil installing a skimming device onto a bank ATM, followed by his arrest
MX LOGIC
Hacker Pleads Guilty In Identity Theft Scam Defrauding Wal-Mart
A California man pleaded guilty to charges of fraud and identity theft in an international scam that used personal information stolen with phishing sites to open fraudulent Wal-Mart credit accounts
ZDNET BLOG
Apple Plugs 33 Mac OS X Security Holes, Updates Flash On Leopard
Mac OS X update includes patches for Adobe's Flash Player plug-in, Clam AV, MySQL, and PHP, while another update fixes vulnerable Flash Player in Snow Leopard
THE REGISTER
Scareware Scumbags Exploit 9/11
Websites supposedly containing info about 9/11 actually contain fake anti-irus scams
CNET
Symantec Tool Calculates Your Data's Value To Thieves
Symantec's new Norton Online Risk Calculator assesses how much your online information is worth on the black market
SYMANTEC
Google Groups Trojan
A backdoor Trojan is using Google Groups newsgroups to distribute commands, according to Symantec
FEDERAL COMPUTER WEEK
Aides Defend Presidential Powers In Cybersecurity Bill
The bill doesn't give government sweeping control over the Internet, Senate aides say
THE GLOBE AND MAIL
Porn Spam On Social Networking Sites Overtaking Taking Porn Email
As much as 15% of Twitter traffic, 10% of MySpace traffic, and 7% of Facebook traffic is porn spam
GOVERNMENT COMPUTER NEWS
How To Measure Security? NIST Maps Out The Emerging Field Of IT Metrology
NIST says an objective, quantifiable way to measure security is missing
BURTON GROUP
U.S. Government Announces Open Identity Initiative
Project could be path to new "trust framework"
INTERNET EVOLUTION
Cybercrime Fighters Adopt Community Tactics
Initiatives may signal the beginnings of a netizen-based "Cyber Corps"
PC ADVISOR
Phishing Attacks Fell By 45 Percent In August
Trend is likely short-term, Symantec researchers say
SEARCH SECURITY
Security Vendors Can Learn From ConSentry Networks' Demise
Vendors must learn that enterprises will seldom change business processes to improve security
APPRIVER
Notice Of Underreported Scareware
Fake IRS messages could mislead unwary users, researchers say
MCAFEE
McAfee Researchers Release September Spam Report
"Chinese pharmacy" spam, Twitter DDoS attacks analyzed
OFFICE OF INADEQUATE SECURITY
Phisher Who Victimized Tens Of Thousands Pleads Guilty
International identity theft ring stole personal data from thousands of users, prosecutor says
TECH NEWS WORLD
Navigating The New Cybercrime Threat Landscape, Part 1
A look at where cybercrime has been -- and where it's going
THE REGISTER
Website Exposes Sensitive Details On Military Personnel
Vulnerabilities on a California commuter Website expose sensitive information of workers for hundreds of employers, including at least one military installation
CNET
Microsoft Faces Second WGA Lawsuit
Plaintiffs say Windows Genuine Advantage program acts as "spyware" on their systems
NETWORK WORLD
Beware The Evil Lurking Behind California Wildfire
Attackers are capitalizing on popular search terms, like "California wildfire," to direct people to fraudulent Web sites, according to Symantec
THREAT POST
Firefox To Check For Adobe Flash Patch
Firefox 3.5.3 and Firefox 3.0.14 will warn users if their version of Adobe Flash Player is out of date
COMPUTER WEEKLY
Congress Drafts Law To Prevent Web Profiling
The House is considering legislation that would prevent U.S. firms from collecting data to build profiles of people's Web surfing habits
PHILO SECURITY
What Does DHS Know About You?
A copy of a DHS travel record shows the U.S. Customs and Border Patrol stores credit card number and expiration, IP addresses used for Web travel reservations, hotel and itinerary, and full name, birth date, and passport number
SANS INTERNET STORM CENTER
Possible DDOS On Gov.Au Sites Starting Tonight?
The hacker group "anonymous" is threatening to launch a massive distributed denial-of-service attack on the Australian government in protest of the country's Internet filtering efforts
WIRED
NSA-Intercepted E-Mails Helped Convict Would-Be Bombers
The three men convicted in the United Kingdom this week of a plot to bomb transcontinental flights were prosecuted, in part, using e-mail correspondences intercepted by the U.S. National Security Agency
COMPUTERWORLD
New Flaw Causes 'Blue Screen Of Death' On Vista, Windows 7
Exploit code already released for flaw in Samba file-sharing feature
YAHOO!
Congress Weighs Landmark Change In Web Ad Privacy
New regulations would require opt-in before advertisers could collect user information
FINEXTRAE
Court Allows Suit Against Bank For Poor Online Security
U.S. couple who lost thousands say bank's single-factor authentication scheme was inadequate
THE AGE
Hacking Firms One Click Ahead Of The Law
Firms claim they can break into any email or other account
BBC
Mobile Phone ID Fraud Increases
Number of accounts being cloned, taken over is increasing, police say
PC MAGAZINE
Hackers Turn Attention To ATMs
Experts urge banks to re-examine their back-end infrastructure
BANK INFO SECURITY
Five Indicted In $4 Million Credit Card Fraud
Eastern Europeans alleged to be part of cyber gang
COMPUTER WEEKLY
Millions Of Web Users At Risk From Weak Passwords
Millions of users use the same password for financial transactions, email, and social networking
BUSINESSWEEK
Using Cybercitizens To Hunt Down Hackers
Symantec's new Norton Internet Security includes an opt-in program that will collect data about attempted computer intrusions and then forward the information to authorities
FINEXTRA
TJX Pays $525,000 To Settle Hacking-Related Suit
TJX has agreed to settle a putative class action suit from several banks related to the retailer's massive security
WASHINGTON POST.COM
More Business Banking Victims Speak Out
More small businesses speak out on how their bank accounts were hacked akin to other SMBs hit by Eastern European cybergangs
NETWORK WORLD
Oracle Delays Security Updates For User Conference
Oracle postphones patch release to Oct. 20 because many customers responsible for patch deployment will be attending Oracle OpenWorld on original date
SOPHOS
Woman Loses $4000 In Facebook Fake Friend Fraud
A Missouri woman was bilked out of $4,000 in three different wire transfers to scammers who posed as a Facebook friends claiming to be stranded in London with no money
COMPUTERWORLD
Microsoft To Deliver Five Critical Windows Patches Next Week
'Critical' update preview uncharacteristically came with few details
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3744
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.
CVE-2013-3743
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 45 and earlier and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.
CVE-2013-2473
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2472.
CVE-2013-2472
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2473.
CVE-2013-2471
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2472, and CVE-2013-2473.



