Best Of Web
Best Of The Web
NETWORK WORLD
China Will Not Enforce Green Dam Porn Filter Plan
PC makers don't have to bundle an Internet filtering program with computers sold in the country after all
INFORMATION SECURITY RESOURCES
Sound Advice For Evaluating SIEM Systems
A checklist of things to look for in an security information event management solution, including whether the server can support an agent
ERRATA SECURITY
UN's Website Still Vulnerable After 2 Years
Errata finds same SQL injection flaw on United Nations Website that led to sites defacement two years ago
COMPUTERWORLD
Twitter's Biz Stone: Lessons Learned From Crippling DDoS Attack
The company now realizes it needs to tune its systems to handle that scale of an attack, says Twitter founder
CSO ONLINE
Heartland CEO On Data Breach: QSAs Let Us Down
Heartland Payment Systems CEO Robert Carr says compliance auditors failed to flag key attack vectors
FARS NEWS AGENCY
FNA Managing Director Warns About Cyber War Against Iran
In Tehran, FNA managing director Hamid Reza Moqaddamfar urges Iranian officials, citizens to be at the ready for cyber threats from the West
APPLE
Apple Patches BIND Flaw
Vulnerability could allow an attacker to terminate DNS server
COMPUTING
UPS Encrypts Laptops And Smartphones After Data Breach
UPS has encrypted all of its U.K. laptops and smartphones a year after an unencrypted laptop was stolen from an employee
THE NEW YORK TIMES
Cellphones Largely Immune To Viruses, For Now
The tightly controlled mobile industry so far has helped keep cell phones from attack
THE SMOKING GUN
NBA Star Warns Over Stolen Laptop
Lawyers for Baron Davis are threatening legal action if "private images" stored on his stolen laptop are published
USA TODAY
Another Attack Downs Twitter, Briefly This Time
The outage was short and Twitter is investigating
CHINA DAILY
Eight Million Gamers Suffered From Computer Virus
A group of 11 people stole and sold personal details on more than 8 million gamers across 1,200 Websites
GOVERNMENT COMPUTER NEWS
Government, Industry Create Threat Forum For Power Grid
Power grid operators have joined with government regulators and security vendors in a forum for sharing information about threats to the U.S. energy infrastructure
DATABREACHES.NET
Hackers Strike UC Berkeley Again
A breach exposes Social Security numbers and birth dates of 493 applicants to the UC Berkeley Graduate School of Journalism between September 2007 and May 2009
COMPUTERWORLD
Microsoft Patches 19 Bugs In Sweeping Security Update
Security updates cover components of Windows, as well as in Windows Media Player, Outlook Express, IIS, Office, and several other products
THE REGISTER
WordPress Bug Resets Admin Password
WordPress blogging software developers release an update that fixes a vulnerability that let attackers reset the administrator password
YAHOO NEWS
Sex, Videos, Friends, Games Hot With Kids Online: Norton
Symantec says among the top searches conducted by kids are for videos, social networks, games, and porn
HEISE ONLINE
Apple Releases Security Update For Safari
The Safari 4.0.3 security update fixes six critical bugs
LUMENSION BLOG
Breaking Down The Military Fiefdoms By Building A 'Fifth Arm' To Combat Cyber Security
A call for a fifth military arm dedicated to looking at IT both offensively and defensively just like any other weapon
THE REGISTER
Two Convicted For Refusal To Decrypt Data
Two people in the U.K. could go to jail for up to five years for refusing to provide authorities with their encryption keys
MICROSOFT
Microsoft Security Bulletin Summary For August 2009
Microsoft issued nine patches today, including one for the critical flaw in Microsoft Active Template Library (ATL) and another for critical vulnerabilities in Office Web Components
SC MAGAZINE
Report: Mass. Bank Customers Getting Replacement Cards
Bank of America and Citigroup account holders in Massachusetts to receive replacement credit and debit cards after a fraud alert
FUDSEC
Showing The Oblomovs The Door
CEOs need to get away from managing risk by regulation and compliance
SANS INTERNET STORM CENTER
Wordpress Unauthenticated Administrator Password Reset
A vulnerability in WordPress blog software allows remote users to reset the administrative password
TRIUMFANT BLOG
Introducing The Worldwide Malware Signature Counter
AV companies have created 2 million signatures since the beginning of this year
GOVERNMENT COMPUTER NEWS
Sandia To Boot Behemoth Botnet
The Department of Energy's Sandia National Laboratories will launch a massive research botnet in October that can run 1 million virtual machines at a time
NEW YORK TIMES
An Interview With David Vladeck Of The FTC
New head of the Federal Trade Commission's Bureau of Consumer Protection talks about possible regulation of personal information shared online
WIRED
6 Reasons To Jailbreak Your iPhone
Apple's recent crackdown on unofficial apps for the iPhone makes jailbreaking more attractive again
NEXTGOV
White House Backing Could Leave Social Media Sites More Vulnerable
While experts say the Obama administration is right to embrace social media, it must do more to educate users on the risk of cyberattacks
ENTERPRISE SYSTEMS
July DDoS Damage Could Have Been Contained
The DDoS attacks that hit U.S. and South Korean Websites last month wouldn't have been so severe if the organizations that were victimized had taken better security steps
THE REGISTER
XML Flaws Threaten 'Enormous' Array Of Apps
Newly discovered critical flaws in open-source software that implements the Extensible Markup Language affects many applications used by banks, e-commerce Web sites, and consumers
JAVNO
China Nabs Hackers Who Robbed Korean Bank Accounts
Chinese police have detained two hackers who stole $366,600 from online bank accounts in South Korea
THE WASHINGTON POST
Hackers Target House.Gov Sites
Hackers broke into and vandalized more than a dozen Web sites for members of the U.S. House of Representatives in the past week
NETWORK WORLD
When Rogue IT Staffers Attack: 8 Organizations That Got Burned
A look at the damage insiders did during the past year -- including the City of San Francisco's Terry Childs and Societe Generale's Jerome Kerviel
Cops: Former Worker Hacked Casino Computers
A man from Luzerne County, Pa., is accused of hacking into a casino's computer system for revenge
HEISE ONLINE
Microsoft To Patch Nine Security Vulnerabilities On Patch Tuesday
Five of the security updates patch critical vulnerabilities that could lead to remote code execution in Windows and other Microsoft software
GOVERNMENT COMPUTER NEWS
Dot-Org Zone Offers Lessons Learned In Implementing DNSSEC
Federal agencies are working with the Internet community to develop a process for implementing the DNS Security Extensions (DNSSEC) for the root zone of the Internet
SECURE CHANNEL
Poor Password Management Eclipses Virus Problem
In 43 percent of security assessments, solution providers say they find poor password policies, enforcement, and practices
EWEEK
Mac OS X's Reputation For Security Wearing Thin
Apple's OS is becoming as susceptible to security problems as Windows
COMPUTERWORLD
ID Card Hacked, Cloned In 12 Minutes
Researcher Adam Laurie uses a laptpop and Nokia mobile phone to copy all of the data from the new identity card, create a clone, and change the information it
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3496 (vipnet_client, vipnet_coordinator, vipnet_personal_firewall, vipnet_safedisk)
Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.
CVE-2013-2849 (chrome)
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.
CVE-2013-2848 (chrome)
The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.
CVE-2013-2847 (chrome)
Race condition in the workers implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via unknown vectors.
CVE-2013-2846 (chrome)
Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2840.


