Best Of Web
Best Of The Web
FAST COMPANY
Security Expert Proves Hacking the Smart Grid Is A Snap
CNN recently demonstrated how a hacker equipped with $500 worth of equipment could take control of the grid, and now security consultant IOActive reveals how hackers could disrupt the smart grid
PRESS GAZETTE
Princes' Phones May Have Been Hacked By Now
The mobile phones of Princes William and Harry may have been hacked by News of the World reporters, a senior police officer said yesterday
TECHNOLOGY REVIEW
Clarifiying An Antivirus Cloud
CEO of cloud-based security startup offers details on his company's new approach to AV
WASHINGTON POST
What To Do When Scareware Strikes
Don't panic, you can avoid infections
SECURITY WATCH
New Wave Of SQL Attacks From China
Researchers at Imperva say large portion of attacks emanate from a single region
EWEEK
Smartphone Users Ignoring Security Risks
Many users still unaware of threats they may face or pass on to other users
NETWORK WORLD
Privacy, Consumer Groups Want New Laws To Protect Web Users
Groups push to require opt-ins before collecting data about users
THE REGISTER
Yorkshire Startup Aims To Shake Up Telecoms Security
New platform for deep packet inspection and cloud security could lead to new services
FAST COMPANY
Security Expert Proves Hacking The Grid Is A Snap
Working with $500 worth of equipment, IOActive researcher takes control of smart meters
FEDERAL COMPUTER WEEK
DHS Needs To Plug Some Cybersecurity Holes, Study Finds
Control systems in factories and utilities could be vulnerable, auditor says
GOV INFOSECURITY
Don't Waste Time Waiting For Cyber Czar
The appointment of a cybersecurity coordinator will have little or no bearing on what agency security managers must do now to perform their jobs
THE REGISTER
UK Parliament Website Hack Exposes Shoddy Passwords
A vulnerability appears to be exposing confidential information, including unencrypted login credentials, a Romanian hacker wrote on his blog
MEDIA MUGHALS
Happy Birthday Internet
The 'Net turns 40 today: on this day in 1969, Arpanet was born at UCLA
MICROSOFT
Vulnerability In Internet Information Services FTP Service Could Allow For Remote Code Execution
Microsoft says it's working on a patch for a reported vulnerability in the File Transfer Protocol Service in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0
COMPUTERWORLD
Spam's Hidden Victims: Mobile Users
Spam costs organizations $712 per employee/per year, but that doesn't even include enterprise mobile users
CNN
Woman Held In Identity Theft Ring That Netted Fed Chief
A woman allegedly involved in an identity-theft gang that claimed Ben Bernanke among its victims has been taken into custody -- she's one of 22 people who now face charges in the $2.1 million scam ring
PANDA LABS
Be Careful With Your Search Results
Researcher finds 123,000 links being used to aid black hat SEO campaign
SOFTPEDIA
California Wildfires Search Results Lead To Malware
Attack may be part of a larger campaign that poisons search results for multiple current news topics
COMPUTERWORLD
Microsoft: Upgrade Messenger Or Else
Microsoft will force an upgrade of its Windows Live Messenger instant messaging software later this month to plug a hole Microsoft introduced when a programmer added an extra character to a code library
SC MAGAZINE
AV Makers Fault Apple On Snow Leopard Malware Scanner
Various antivirus vendors are questioning Apple's move to include an AV feature in Snow Leopard
TREND MICRO BLOG
Firefox Add-On Spies On Google Search Results
New spyware purporting to be an Adobe Flash Player update creates a Firefox add-on that can monitor the user's browsing activities
FIERCE TELECOM
Senate Issues Revised Cybersecurity Emergency Bill
Language in the first draft of the bill that gives the president the ability to shut down the Internet in the event of a major cyberattack has been rewritten, but not enough to satisfy some critics
GOV INFOSECURITY
NASA Remedies FISMA Compliance Failure
NASA has taken steps to remedy failures to comply with reporting requirements regarding its national security systems
REUTERS
U.S. Credit Card Hacker's Lawyer Says Client Not Ringleader
Attorney for Albert Gonzalez says the confessed hacker is only one of 11 co-conspirators worldwide
SOFTPEDIA
iPhone GPS Gets Robbers Arrested
Armed robbery victim was able to find the suspects who stole his credit cards and iPhone -- he used the GPS feature in his stolen smart phone
ARS TECHNICA
Game Server Admins Arrested For Chinese DNS Attacks
A denial-of-service attack that took down Internet access in parts of China earlier this year was the result of a game provider trying to take down rivals
BETA NEWS
DHS: Expect Your Computer To Be Seized Without Suspicion
The U.S. Department of Homeland Security clarifies its privacy policy with new guidelines for immigration and customs agents
PC MAGAZINE
Microsoft Lists Top 10 Windows Malware
Taterf was the most commonly found worm/malware found by Microsoft, according to its newest top 10 Windows threats report
IT NEWS
Crime Expert Backs Calls For 'License To Compute'
Australian Institute of Criminology executive says a "computer driver's license" should be taken seriously as an option for combating cybercrime
THE JAKARTA GLOBE
Indonesian Hackers Launch Independence Day Attack On Malaysian Websites
Indonesian hackers claim to have attacked a list of more than 120 Web sites as retribution for Malaysia's alleged theft of Indonesian cultural items and abuse of migrant workers
TAIWAN NEWS
President's Office Denies Site Hacked
Taiwan's presidential office denies reports that its Website was hacked by satirists lampooning its slow response to Typhoon Morakot
THREAT CHAOS
Watch Out Cisco -- Sleeping Dragon Breathing Down Your Neck
3Com's new firewall platform and integration with the TippingPoint IPS will challenge Cisco, Juniper
GOVERNMENT COMPUTER NEWS
New Threats Emerge From Once-Trusted Protocols And Services
Vulnerabilities in DNS and SSL open new avenues of attack
NETWORK WORLD
Developer Denies Software To Beat Chinese Censors Is Malicious
Software designed to beat Chinese censorship may behave in suspicious ways, but that's because it's aimed at fooling Chinese authorities, its developer says
WIRED
Accused TJX Hacker Agrees To Plea
Accused TJX hacker Albert Gonzalez accepts a plea agreement with prosecutors for his role in hacking TJX, Barnes & Noble, Office Max, and Dave & Busters; charges still pending against him include hacking into Heartland Payment Systems, Hannaford Bros., and 7-11 ATM machines
THREAT POST
Apache Site Hacked Through SSH Key Compromise
The Apache Software Foundation's main Website was compromised on Friday via a compromised SSH key, leading to concerns about the integrity of copies of the Apache Web server
TECHWORLD
FBI Fears Free Laptops Could Be Malware Scam
The FBI is investigating mysterious HP laptops sent to several state governors
IMPERVA BLOG
The China Syndrome
The recent SQL injection attack campaign appears to be originating from 60 different servers in China; as of Thursday, the malware distribution sites were still running and had logged more than 1.2 million downloads
SC MAGAZINE
Botnet Activity Drops As Spam Remains At High But Steady Level
Activity from Cutwail, one of the world's largest botnets, has dropped by as much as 90 percent since the takedown of an ISP in Latvia, according to Symantec's August MessageLabs Intelligence Report
HEISE ONLINE
Attack On WPA Refined
A known method for cracking the Wi-Fi Protected Access encryption standard has been refined by Japanese researchers and is much faster
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
- HP Newsletter with Gartner Research: Maximizing Your Infrastructure through Virtualization
- Understanding Holistic Database Security 8 Steps to Successfully Securing Enterprise Data Sources
- A How-To Guide on Using Cloud Services for Security-Rich Data Backup
- Holistic Risk Management: Perspectives from IT Professionals
- Aligning IT with strategic business goals: A proactive approach to managing IT risk to your business
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2012-4697
TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to obtain administrative access via an FTP session.
CVE-2011-4520
Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
CVE-2011-4519
Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
CVE-2011-4518
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2012-6563
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.


