Best Of Web
Best Of The Web
MICROSOFT.COM
Microsoft Issues Ten Security Patches
Six patches considered "critical," software giant says
BBC
China's Computers At Hacking Risk
Compulsory screening software found vulnerable
CIO
RSA Chief: The Job Of The Security Guys Is Not To Be 'Doctor No'
IT security managers should enable cloud computing by learning to manage risk, Coviello says
HELP NET SECURITY
Vulnerability In Internet Explorer Discovered By Core Security Technologies
Flaw could cause browser to trust malicious sites, researchers say
SUNBELT SOFTWARE BLOG
An Inconvenient Zbot Lure
Users looking for Al Gore's climate site find themselves loading malware
USA TODAY
Scareware's Pitches For Fake Security Show Up In Odd Places
Phony antivirus, anti-malware tools encountered at popular mainstream sites
TECHWORLD
Business Fears ICANN Domain Changes Will Fuel Cybercrime
Liberalization of top-level domains may create problems with cybersquatters, study says
CNET
Report: Spam Reduced Following Pricewert Shutdown
FTC closure of malware-carrying ISP may be having positive effect
COMPUTERWORLD
Hidden Threat On Corporate Nets: Misconfigured Gear
New tool from Telcordia detects and tracks down network devices that might be vulnerable
STUFF.CO
Paypal's Security 'Flawed'
Vulnerability could cause customers to lose control of their accounts, researcher says
INFOSECURITY
Aussie Bank Customers Hit By Advanced Phishing Techniques
New breed of scam uses fake call centers to allay victims' fears
IT WIRE
Sydney Conference To Combat Cybercrime
Law enforcement, security experts will convene in Australian security summit
PITTSBURGH POST-GAZETTE
Our Brave New Cyberworld: It's A Jungle Out There
Former Clinton cybersecurity adviser says Obama's new cybersecurity team has its work cut out for it
THE SCOTSMAN
NASA Hacker Tells Of Extradition 'Nightmare'
Alleged master hacker Gary McKinnon generates sympathy in U.K.
TAIPEI TIMES
Hacking The Hackers Back
U.S., other foreign governments may launch denial-of-service attacks on known hacker networks, systems
NEWSWEEK
The Spy In Your Hand
Do-it-yourself spooks can now wirelessly transfer a wiretapping program to any mobile phone
RICHMOND TIMES-DISPATCH
Stolen VCU Computer Puts Social Security Numbers At Risk
The Social Security numbers of 17,214 current and former Virginia Commonwealth University students were on a computer stolen from a locked room at the university
DEPARTMENT OF HOMELAND SECURITY
Black Hat Founder Jeff Moss Among New Homeland Security Advisory Council Members
Former hacker "Dark Tangent" joins many notables at HSAC, which provides recommendations to Secretary of Homeland Security
MARSHAL8e6 BLOG
FTC's Shutdown Of ISP Results In Spam Dip
In the wake of closing Pricewert, spam is down about 15 percent -- though still not as dramatic as November's McColo shutdown
NETWORK WORLD
New DOS Attacks Threaten Wireless Data Networks
Inherent weaknesses in Mobile IP leave the door open for new types of denial-of-service attacks
SOFTPEDIA
Major U.S. Retailer Settles FTC Spyware Charges
Sears Holdings Management says it will settle charges by the Federal Trade Commission that it promoted a data-collecting software program to customers, but failed to disclose the scope of the personal information gathered
TREND MICRO BLOG
Reconfigure Your Outlook With Malware
Spammers are using various forms of phishing email posing as a Microsoft Outlook notifications
HELP-NET SECURITY
Gartner Survey Shows Worldwide IT Budgets To Decline 4.7 Percent This Year
CIOs say renegotiating contracts and headcount reductions are main focus, plus shifting more work to in-house resources and delaying capital expenditures
CNET
Tony La Russa Sues Twitter Over Alleged Fake Tweets
La Russa allegedly claims tweets were "derogatory and demeaning," and that the feed damaged his trademark rights
redORBIT
Judge Throws Out Wiretapping Lawsuits
Federal judge tosses out more than three dozen lawsuits filed against telecom companies for allegedly taking part in the government's e-mail and telephone eavesdropping program without court approval
GOVERNMENT COMPUTER NEWS
Federal IT Security Recommendations Released In Final NIST Draft
NIST issues "historic" draft document that provides security controls for national and non-national-security systems
SOPHOS BLOG
Iranian Media Falls For Obama BlackBerry Hack Hoax
A news Website is duped into following a "story" about Barack Obama's BlackBerry being hacked and secret email messages between the Obama and his aides being released to the world
MICROSOFT
Patch Tuesday To Include 10 Bulletins
Microsoft has six Windows, three Office, and one Internet Explorer vulnerability
PC WORLD
Adobe Will Deliver Its First Quarterly Patches Next Tuesday
Patches will cover Adobe Reader and Acrobat versions 7.x, 8.x, and 9.x for Microsoft Windows, and Apple's Mac OS X
TRENDLABS
Autorun Worm Invades ZIP
Worm has a unique way of hiding -- by copying itself in every ZIP-compressed file it finds on a system
ZDNET Blog
StrongWebmail CEO's Mail Account Hacked Via XSS
$10,000 challenge to hack CEO's email account ends with a team of contestants taking over the account via a persistent cross-site scripting vulnerability
SEARCH SECURITY
Stolen FTP Credentials Likely In Massive Website Attacks
More than 40,000 sites affected, researchers say
VNUNet
Twitter Users Plagued By Rogue Anti-Virus Attack
Malware spreads in the form of posts from hijacked user accounts
WALL STREET JOURNAL
FBI Director Anticipates New Crime Wave Of Financial Fraud
Criminals will look to take advantage of bank bailout and economic stimulus programs, Mueller says
ESET THREAT BLOG
Everybody Loves Facebook
A look at the Koobface exploit and how it affects Facebook users
NETWORK WORLD
Microsoft Reveals Some Of Its Cloud Security Measures
Strategy focuses on risk assessment and defense in depth
TECH CRUNCH
Phishing Scam Targets YouTube Partners
Phishing messages attempt to fool users into giving up their online credentials
SCHNEIER ON SECURITY
Cloud Computing: This Year's Overhyped IT Concept
For all the hoopla, cloud computing looks pretty much like time-sharing -- and carries the same trust questions
MSNBC
How To Retaliate In Cyber Attacks Debated
Obama official says U.S. faces "grave national security challenge" as it determines how to tackle new war-fighting domain without infringing on privacy and the Constitution
FEDERAL COMPUTER WEEK
Nominee: DHS Won't Lose Cybersecurity Authority
Rand Beers, the nominee for undersecretary of the Homeland Security Department's National Protection and Programs Directorate, testifies that administration officials told him the White House's new cybersecurity coordinator will not undercut DHS' role
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



