Best Of Web
Best Of The Web
HELP NET SECURITY
Viruses Up 300 Percent; More Threats Coming From India And Brazil
Number of viruses is at its highest this year, according to Network Box
THE REGISTER
Meter Insecurity Raises Specter Of Free Parking Hacks
Black Hat speakers tap link between meters, smart cards
SC MAGAZINE
Regulation Is Harming Computer Security, Experts Say
At Black Hat, CSOs complain of wasting time on useless jobs
BITDEFENDER
Trojans Total Half Of Top Ten E-Threats For July
Trojan.Clicker.CM tops list for second month in a row
CIO
HP Says Browser-Based "Veiled" Makes Darknets A Snap
Researchers at Black Hat describe "disappearing" networks that could be used by cybercriminals
DAILY TECH
Another Major Mac Security Flaw Discovered
At Black Hat, researcher outlines methods for owning Macs and stealing data that is supposed to be encrypted
WIRED
Spoofed Cell Phone Texts Pose Malware Threat
Messages appear to come from user's mobile carrier, Black Hat researchers say
INTERNET NEWS
Data Of Soldiers, Hospital Patients Found On P2P
Personal information on 200,000 soldiers, 20,000 patients may be at risk due to unauthorized software downloads
SC MAGAZINE
First Lady's Safe House Location Leaked Via P2P
P2P leak was also responsible for loss of sensitive nuclear data reported yesterday
REUTERS
Researcher Pressured To Pull Conficker Talk
Law enforcement agencies ask Black Hat speaker to withhold some information on botnet origins
SANS.ORG
Increasing Number Of Attacks On Security Sites
"Zero For Owned" e-zine reveals details of several different hacks
GOVERNMENT COMPUTER NEWS
Hacking Routers Can Be A High Value, And A High Effort, Activity
Black Hat briefing says cracking popular network devices isn't easy
PC ADVISOR
Security Breaches Cost Companies Customers
Cost of data loss is higher than some companies think, Ponemon study says
GOOGLE
Cybercriminals Targeting Social Networking Sites
Facebook, MySpace, other communities are ripe for the picking, experts say
GOVERNMENT COMPUTER NEWS
New Weapon Revealed For Defense Against Zero-Day Attacks
Trusted Computer Solutions prepares to re-launch CounterStorm anomaly detection tool
LONDON TELEGRAPH
Identity Theft Hackers Attack MI5 Website
Cybercriminals make bid to steal identities of Web users
WIRED
Data Detailing New York Stock Exchange Network Exposed On Unsecured Server
Sensitive information on the technical infrastructure of the New York Stock Exchange's network was left unsecured on a public server for more than a year
THE WASHINGTON POST
Report: Locations of All U.S. Nuclear Installations On P2P Networks
Classified document shows location of nuclear missile silos, as well as witness protection program information, and layout of emergency safe house for Michelle Obama
DIGITAL DEGENERATE
MMS Phishing Attack Targeting Texas Residents
Hack sent images and other multimedia to cell phones via infected email servers, targeting Houston and Dallas/Fort Worth Area area codes
MICROSOFT
Microsoft Issues Eight Off-Cycle Patches
Aside from ActiveX flaw, updates include patches for Publisher and a cumulative update for Internet Explorer
GOVINFOSECURITY
Algorithm Sought To Analyze Insider Behavior
The Air Force is looking for technology to analyze the conduct of insiders to determine if they pose a threat
IT BUSINESS.CA
Domino's 'Loses' $77,000 In Free Pizza After Promo Code Hacked
After an attacker guessed a promotional coupon code for a free medium pizza, the chain distributed $77,000 worth of free pizza
COMPUTERWORLD
Almost All Windows Users Vulnerable To Flash Zero-Day Attacks
Secunia says more than 90 percent of PCs run at-risk Flash, while nearly half run an unsecured version of Reader
ARS TECHNICA
Cheerleader Sues School, Coach After Illicit Facebook Log-In
A high school cheerleader is suing after her coach forced her to give up her Facebook account login information, and her account's contents were shared widely with school officials
BBC
Chinese Hack Film Festival Site
Attackers hit the Website of Australia's biggest film festival over a documentary about Uighur leader Rebiya Kadeer
HELP NET SECURITY
Shrinking Budgets Tie Hands Of Security Professionals
RSA Conference study shows security pros are most concerned about email phishing and securing mobile devices, but these tools are at risk of cuts in the budget
THE REGISTER
Remote IT Support Tool Hijacks Customer Webserver
TeamViewer remote management tool advertisement causes outage
ACLU
ACLU, EFF Ask Google To Fix Privacy Issues With Google Book Search
The American Civil Liberties Union of Northern California, the Electronic Frontier Foundation, and the Samuelson Law, Technology & Public Policy Clinic at Berkeley Law School wrote to Google asking for the search giant to consider reader privacy
iPHONE DEV TEAM
10 Tips For iPhone Users At DEFCON 17
Disable all your login cookies in Safari and change your root and mobile password, among other things
INFORMATIONWEEK
Apple iPhone Security Weaknesses Exposed On YouTube
Hacker demonstrates in video post how iPhone 3GS is vulnerable to deleted voice mail, e-mail, and other data
SOFTPEDIA
Identity Theft Kingpin Pleads Guilty
A Maryland man pleaded guilty of conspiracy to commit bank fraud after allegedly heading up an ID theft operation that resulted in $2.1 million in losses
SC MAGAZINE
Forrester: The Good And Bad Of Security Technologies
Businesses are using a variety of tools for security, but some of these products are more beneficial than others, according to a new Forrester report
WIRED
Ringleader Of High-Tech Pickpocket Gang Pleads Guilty
Identity thefts led to $2.1 million in losses by financial institutions
MSNBC
On Social Web, Beware Of Address Book Mining
Tagged.com accused of invading privacy, sending misleading spam
LAW.COM
Hacker Can Be Sued For Fraud Under Securities Exchange Act, Court Says
Man who hacked into corporate net to get advance financial information is liable, ruling states
ASSOCIATED PRESS
Report: Shortage Of Cyber Experts May Hinder Government
Federal agencies still short on skills needed to execute cybersecurity programs, study says
REDMOND MAGAZINE
U.S. Intelligence Chief: Source Of Cyberattacks Still Unknown
Authorities still haven't figured out who's responsible for attacks on government sites in U.S., South Korea
NEXTGOV
Panel Seeks Cybersecurity Records, Cites Privacy Concerns
Senate committee orders Obama administration to turn over records or lose funding for cybersecurity programs
IT WEB
Bandwidth Boost Brings Online Threat
Faster connection speeds in South Africa could lead to additional exploits, researcher warns
GOVERNMENT COMPUTER NEWS
National Security And Social Networking Are Compatible, Speakers Say
National defense strategies must take social networking into account, experts say
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



