Best Of Web
Best Of The Web
COMPUTERWORLD
Vulnerabilities Play Only Minor Role In Malware Spread, Says Researcher
About two thirds of all infections are due to duped users
MSNBC
Bad Economy Helps Web Crooks Recruit "Mules"
Money-laundering schemes pitched as "work at home" jobs
BANGKOK POST
Thailand Government's Secret Files Plundered
Protesters may have stolen sensitive national security data
TIMES OF INDIA
Expert: Russian Mafia Is Largest Cyber Crime Syndicate
Most serious crimes emanate from Russia and China, researcher says
HELP NET SECURITY
Enterprise-Wide Approach Improves Financial Crime-Fighting Performance
Broad approach to management of money laundering and fraud can lead to substantial cost savings
POPULAR MECHANICS
When Hackers Attack: Practicing Cyber Security At Home
How hackers expose the details of our private lives by attacking our browsers, cell phones, and personal electronics
NEW HAMPSHIRE UNION LEADER
Account Hackers: From Russia To Hampton
Gang of thieves broke into computers and stole log-in information, feds say
eWEEK
Five Years After CAN-SPAM
Has spam legislation done anything to solve the problem?
MICROSOFT.COM
Microsoft Issues Eight Patches On Patch Tuesday
Six vulnerabilities rated "critical" by software giant
THE REGISTER
New Trojan In Mass DNS Attack
Single box can pollute an entire LAN, researchers say
LAS VEGAS NOW
Major Organized Crime Bust In Las Vegas
Fed nail more than 20 suspects in crime ring specializing in counterfeiting, credit card fraud, and identity theft.
THE REGISTER
Brute Force SSH Attack Confounds Defenders
Assault targets specific servers and relies on coordination among botnet clients
CNET
Are SharePoint Sites the Weakest Link?
Eighty-seven percent of IT managers point to SharePoint as their top concern for leaking sensitive data, according to a survey by Courion
YAHOO NEWS
Microsoft's Morro Could Challenge Security Giants
Big AV companies McAfee and Symantec could be hurt as Microsoft moves to provide free antivirus software
SECURITYFOCUS
Brief Study Shows Difficulty In Detecting Malware
When malware writers release various iterations of their code, it gets past most antivirus defenses, researchers at FireEye found
WIRED
Under Worm Assault, Military Bans Disks, USB Drives
The Defense Department's geeks are spooked by a rapidly-spreading worm
eWEEK
Experts: Cyber-Crime As Destructive As Credit Crisis
Damage caused by cyber-crime estimated at $100 billion annually
MARKET WATCH
Congress Warned Of Google Privacy And Security Risks
New video exposes vulnerabilities in Gmail and other Google apps
GCN
NSA Posts Secret To Writing Secure Code
Case studyshows how to cost-effectively develop code with zero defects
SECURITY FOCUS
Metasploit Framework 3.2 Released
Free exploit development and attack framework offers modules for latest Microsoft flaws
INTERNET STORM CENTER
Two Cheat Sheets For Incident Handling
Save these checklists �� you'll need them
SCIENCE DAILY
RFID Chips: A Privacy And Security Pandora's Box?
Threats to personal privacy should be taken into account, scientists say
FCW.COM
Security Specialists In Demand
Increasing network threats drive need for professional experience and certifications
GOOGLE ENTERPRISE BLOG
Calculating The True Cost Of Fighting Spam
Google offers ROI calculator to determine how spam affects expenses and productivity
THE REGISTER
Lame Mac Trojan Limps Into View
Security researchers uncover rare Mac PC Trojan
ZDNET BLOG
Fake Windows XP Activation Trojan Goes 2.0
Kardphisher Trojan mimicking XP activation interface has gotten a facelift -- and looks very convincing
COMPUTER WEEKLY
Hackers Put Lives At Risk
Computer systems of three major London hospitals were shut down after being hit by the Mytob worm
THE DARK VISITOR
China��s Computer Virus Epidemic Shows 12% Increase
Most of these viruses were used by hackers to steal virtual property
SEARCHSECURITY
Cybersecurity Expert Sees PCI DSS Problems Ahead For Retailers
Retailers could face millions of dollars' worth of wireless upgrades to go to secure 802.11, IBM ISS governance expert says
FEDERAL COMPUTER WEEK
Industry Group Calls For Cybersecurity Partnership
Internet Security Alliance says Obama administration should form a cybersecurity social contract with industry using economic incentives
INFORMATIONWEEK
Chinese-Born Scientist Pleads Guilty to Tech Espionage
Quan-Sheng Shu faces up to 10 years in prison after pleading guilty to selling U.S. technology and military secrets for rocket propulsion to China
FEDERAL TRADE COMMISSION
Court Orders Halt To Sale Of Spyware
Restraining order placed on sale of CyberSpy keylogger software
SOPHOS
DDoS Attack Strikes Anti-Money Laundering Site
Bobbear.co.uk taken out by "huge" botnet
GROWTH BUSINESS
Fines Likely For U.K. Data Breaches
U.K. government agency seeks power to fine businesses up to 10 percent of their revenues
FOX NEWS
Oregon Woman Loses $400,000 To Nigerian Email Scam
Victim says she wasn't a sucker or an easy mark
ARS TECHNICA
Documents Show How Mobile Devices Can Be Lojacked Without Telco Help
"Triggerfish" fool cell phones and other devices into giving away their control data
OUT-LAW.COM
Visa's Digital Credit Card Could Raise Legal Stakes For Competitors
Innovation could force other card issuers and banks to follow suit
BBC
UK Identities Sold For $160 Online
Internet fraudsters sell complete financial identities for the price of an iPod
WIRED
Barack Obama's Privacy Challenge
Candidates ponder what to do with data collected from potential voters during campaign
FOXNEWS.COM
Cyber-Hackers Break Into IMF Computer System
Spyware was discovered on the International Monetary Fund's computer systems earlier this month
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3496 (vipnet_client, vipnet_coordinator, vipnet_personal_firewall, vipnet_safedisk)
Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.
CVE-2013-2849 (chrome)
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.
CVE-2013-2848 (chrome)
The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.
CVE-2013-2847 (chrome)
Race condition in the workers implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via unknown vectors.
CVE-2013-2846 (chrome)
Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2840.


