Best Of Web
Best Of The Web
NAKED SECURITY BLOG
How To Report A Computer Crime: Malware By Email
The Department of Justice website contains a Computer Crime and Intellectual Property Section with a contact page for reporting incidents to law enforcement -- how to use these resources in the event of a crime
THE REGISTER
UK Prosecutors, Cops Ponder New Probe Into NASA Hacker McKinnon
U.K. criminal prosecution lawyers will meet with law enforcement officials this month to decide whether or not to open a new investigation into Gary McKinnon's hacking case
POLITICO
Obama Win May Boost White House Stance On Cybersecurity
President Barack Obama's second term could provide new momentum to boost the country's cybersecurity defenses, improve the nation's wireless system, and develop rules to assuage consumers' online privacy fears
THREAT POST
Google Implements Do Not Track In Chrome 23
Google yesterday issued a new version of Chrome that supports the Do Not Track functionality that helps users prevent websites from following their movements online
COMPUTERWORLD
Adobe, Now 'Married' To Microsoft, Moves Flash Updates To Patch Tuesday
Adobe yesterday announced that it will pair future security updates for its popular Flash Player with Microsoft's Patch Tuesday schedule
CIPHER LAW GROUP
TQP Continues Enforcing Cryptography Patent; Identifies RC4 Algorithm + SSL/TLS
TQP Development this month sued Intel, Wind River Systems, and Hertz for allegedly infringing its patent covering cryptographic communication -- specifically alleged infringement by use of the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols in combination with the RC4 encryption algorithm
DAMBALLA BLOG
Persistent Threat Detection On A Budget
One way to quickly check whether your network has been taken over by cybercriminals or cyberspies is to check your DNS logs
ARIZONA DAILY STAR
US Report: Sophisticated Hacking By China Is Greatest Cyberthreat
China is most threatening actor in cyberspace, according to draft annual report mandated by Congress
FORBES
Security Researchers Warn New Jersey’s Emergency Email Voting Could Be An Insecure, Illegal Nightmare
State's decision to let Sandy victims vote via email could leave political storm in its wake
THE INDEPENDENT
Anonymous Hacktivist Arrested After Attacks On U.K. Home Office Websites
Man accused of DDoS attacks associated with hacktivist group
CSO ONLINE
Anonymous-Backed Demonstration Unfolds Outside U.K. Parliament
Protest is centerpiece of worldwide demonstration of "global strength and solidarity," group says
THE REGISTER
Ohio Voting Machines Have "Backdoor," Lawsuit Claims
Security of e-voting called into question -- again
THREAT POST
Google Patches 14 Flaws In Chrome 23
Six of the vulnerabilities found are rated as high
COMPUTER WEEKLY
IT Security Workers Must Support Business Needs, Says Ernst & Young
Some 57% said information security workers lack the ability to talk in business terms about things such as total cost of ownership
WIRED
Russian Underground Offers Cybercrime Services At Dirt-Cheap Prices
Hiring a botnet can cost as little as $2, according to Trend Micro report
TECHNOLOGY BANKER
New Blackhole Targets Mobile Banking Services
Blackhole continues to have the largest malware market share with 63% and 76% share of toolkits in the market
BLOOMBERG
Coke Gets Hacked And Doesn't Tell Anyone
Coca-Cola learned from the FBI in 2008 that Chinese cyberespionage attackers had stolen sensitive information about a planned, multibillion-dollar acquisition of a Chinese company -- the deal fell through soon thereafter
ABC NEWS
US Bank Cyber Attackers Deny Iran Connection
A hacker group that has claimed responsibility for massive attacks against the websites of several major U.S. financial institutions told ABC News it is not acting on behalf of and is not supported by the Iranian government
FULL DISCLOSURE LIST
Multiple Critical Vulnerabilities In Sophos Products
Researcher Tavis Ormandy today released research on how attacks could be waged against Sophos antivirus products exploiting weaknesses in the software -- he also issued a working exploit
COMPUTERWORLD
Smart Meters Not So Clever About Privacy, Researchers Find
University of South Carolina study found smart meters transmitting plain text information that could be used against home owners
CYBERWARZONE
Skype Hands 16-Year-Old's Personal Information To IT Company
Skype illegally distributed a user's personal information to a private company during a police investigation into Anonymous' cyberattacks on PayPal
CSO ONLINE
Election Sabotage: A Threat Much Older Than Hacked E-Voting
Concerns over the accuracy and security of e-voting continues to be an issue, but history is littered with hints of sabotage that predate the invention of these machines
CRN
Kaspersky: SMS Trojans Account For Over Half Of Smartphone Malware
57 percent of all malware detected on smartphones was made up of SMS Trojans designed to extract money from mobile accounts by sending SMS messages to numbers that automatically charge fees
THE NEXT WEB
Malware Authors Quickly Create Fake Antivirus Just For Windows 8
Windows 8 was released on Friday and now there's already a fake antivirus program out for the new operating system
CORNELL DAILY SUN
Breach In Cornell Information Technology Exposes Personal Data For Five Days
Personal information of up to 2,000 people was exposed online for five days on a computer in Cornell's athletics department, but officials say they are unsure whether that information was then abused by criminals
INFOWORLD
Firefox To Force Secure Connections For Selected Domains
Mozilla has pre-loaded in Firefox a list of domains that only can be connected to via HTTP Strict Transport Security
THREAT POST
Apache Server-Status Publicly Viewable On Top Sites
A researcher discovered that some top websites running on Apache have left open their server-status pages, including php.net, metacafe.com, cloudflare.com, Disney.go.com, latimes.com, staples.com, tweetdeck.com, nba.com, ford.com, cisco.com, chicagotribune.com, yellow.com, and apache.org
COMPUTERWORLD
Election Watchdogs Keep Wary Eye On Paperless E-Voting Systems
Some 16 states will use Direct Recording Electronic voting machines that don't employ a paper trail, of those New Jersey, Delaware, Maryland, South Carolina, Georgia, and Louisiana, will be completely paperless
THE EXAMINER
Info From 657,000 SC Businesses Exposed In DOR Cyber Attack
South Carolina officials now say information from up to 657,000 businesses was also exposed in the cyber attack on the Department of Revenue (DOR) that exposed SSNs and payment card information of residents
SECURELIST
IT Threat Evolution: Q3 2012
New Kaspersky Lab report finds among other things that 28% of all mobile devices attacked by malware were running Android OS version 2.3.6
NC STATE
Researchers ID 'Smishing' Vulnerability In Android
NC State researchers have discovered an SMS-phishing flaw in the Android where if a user downloads an infected app, the attacker can spoof an SMS text message from someone on the phone’s contact list or from trusted banks
SOFTPEDIA
Ransomware Locks Computers In The Name Of "Anonymous Hackers Group"
New attack uses name of famous hacktivist group instead of law enforcement
THREAT POST
DHS Chief Uses Sandy To Underscore Cybersecurity Threats
Blow to critical infrastructure is used to demonstrate potential of cyberattack
SYMANTEC
Malware Authors Using New Techniques To Evade Automated Threat Analysis Systems
According to new report, 400 million new variants of malware were created in 2011 – an average of one million new variants per day
BANK INFO SECURITY
How To Fight The New Gozi Banking Trojan
Crimeware exploits basic authentication used in U.S.
THE NEXT WEB
Jacksbot Java Malware Can Take Control Of Windows, Mac And Linux Systems
New variant of Java remote access tool (RAT) allegedly created by the jailbreaking group RedpoisOn; can target multiple platforms
THE REGISTER
Israeli Cops Penetrated By Army Of Fake Generals With Trojans
Trojan is targeted specifically at law enforcement networks; Syrian rebels also hit
IS SOURCE
New Hacker Weapon Surfaces
The High Orbit Ion Cannon is a dangerous free-to-download, open-source program that can turn any user of any skill level into a powerful hacker, at least in terms of one form of attack, a distributed denial-of-service
SOPHOS
Nuclear Power Plant Cybersecurity Warnings Silenced By Legal Threats
Two talks pulled after a supplier of nuclear plant equipment threatens to sue
CNET
Huawei Looks To German Security Researchers For Help
Huawei global security chief John Suffolk told Reuters the company has sent engineers to meet with the German researcher ‘FX’ who has found security flaws in their products
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



