Best Of Web
Best Of The Web
THREAT POST
Eugene Kaspersky Unveils Plans For New Secure SCADA OS
Engineers at Kaspersky Lab have begun work on a new secure operating system designed for SCADA and ICS systems
TECHNOLOGY REVIEW
China Busts 700 Cybercriminal Gangs
China's Web policing campaign has led to the arrest of 8,900 suspects and deleting of 1.88 million "harmful" Web messages, says the Ministry of Public Security
COMPUTERWORLD
Cyberthieves Loot $400,000 From City Bank Account
Attack on Bank of America accountholder Burlington, Wash., occurs days after RSA issued a warning that criminal gang planned massive attacks against U.S. banking customers
SECURELIST
Twitter Phishing Campaign Spreading Via Direct Messages
A direct message saying something along the lines of, 'Hey, someone is spreading nasty rumours about you' along with a malicious URL appears to be spreading through Twitter
INFOWORLD
5 Signs You've Been Hit With An Advanced Persistent Threat
Among the clues: odd network behavior, such as unexpected information flows
BANK INFO SECURITY
The 'Evil 8' Threats To Mobile Computing
Assessing current, future vulnerabilities to smartphones, tablet computers
DEPARTMENT OF DEFENSE
Transcript Of Comments By Defense Secretary To Business Executives For National Security
Panetta offers U.S. insights on Iran�s development of cyberstrategy
MASHABLE
How To Stay Safe On Ecommerce Sites
Cybercriminals are increasingly targeting e-business sites for attack. Here are some tips for consumers and businesses
SOPHOS
U.S. Court Says Reading Other People�s Online Email Is OK, Privacy Be Damned
Mailboxes provided by Internet services aren't "electronic storage" and aren't protected by Stored Communications Act, judge says
BOSTON GLOBE
TD Bank Misplaces Tapes With Data On 267,000 Customers
Tapes were unencrypted and contained extensive personal information, bank says
TECH NEWS DAILY
Eye Movements Could Be The Next PC Password
New biometric technology may offer a strategic solution for authentication
HOMELAND SECURITY NEWSWIRE
NIST Awards $9 Million To Promote Online Security And Privacy
Grant will support National Strategy for Trusted Identities In Cyberspace (NSTIC)
THREAT POST
Precision Espionage miniFlame Malware Tied To Flame, Gauss
Secondary surveillance tool follows compromise by infamous malware tools
THREAT POST
Firefox 16.0.1 Ready After Serious Vulnerability Forced Mozilla To Suspend Availability
Mozilla has rereleased Firefox 16 after suspending downloads of the latest version of the Firefox browser due to a serious vulnerability
THREAT POST
ReVuln Emerges As New Player In Vulnerability Sales Market
ReVuln is focusing on vulnerabilities in SCADA and ICS software -- it�s headed up by a researcher known for his work in SCADA software
ARS TECHNICA
Security Breach Briefly Hijacks Connections To Google.ie And Yahoo.ie
The domain provider that manages Internet addresses for Ireland's national .ie domain has temporarily taken some of its systems offline while officials investigate a security breach that temporarily hijacked the Irish websites for Google and Yahoo
NAKED SECURITY BLOG
Is Google About To Start Scanning Your Android For Malware?
New version of Google Play app has added capabilities for antivirus functionality
COMPUTERWORLD
Former LulzSec Member Guilty In Sony Pictures Hack
Raynaldo Rivera confessed to being involved in a cyberattack that resulted in the theft of user information from a Sony Pictures website
SC MAGAZINE
Conficker Working Group Claims That People Are Still Being Infected
The Conficker worm is still actively infecting users, but no clues yet as to who is behind it, according to a Conficker Working Group member
THE HACKER NEWS
Windows 8 Security Flaw: Logon Password Stores In Plain Text
Password security vendor Passcape found that Windows 8 saves a log-on password in plain text and lets users with admin rights to see the password details
NEXGOV
DHS Urged To Create Reserve Cadre Of Cyber Experts
A task force has recommended that the Department of Homeland Secuirty build a reserve army of cyberspecialists from across government and industry to handle emergencies
WIRED
WikiLeaks Goes Behind Paywall, Anonymous Cries Foul
Secret-spilling site has moved millions of documents behind paywall, asking for donations
TORRENTFREAK
SOPA Is Back! ... As A Ransomware Virus
Defeated anti-piracy bill is disguise of new, nasty cryptovirus
CSO
Presidential Candidates Quiet On Cyber Policy
Obama and Romney differences aired by analysts, not so much by one another
TRUSTEER
Project Blitzkrieg: How To Block Planned Prinmalka-Gozi Trojan Attack
Distant relative of Gozi malware operates much differently than its ancestor
SECURITYTUBE
Symantec: Data-Stealing Hackers Use DDoS To Distract From Attacks
DDoS attack acts as a bluff while cybercriminals quietly target another vulnerability
SAUDI GAZETTE
Aramco Identifies Hackers' Whereabouts
Disabling cyberattack emanated from Romania, sources say
SOFTPEDIA
Anonymous To Attack Akamai After Director Said Hackers Failed To Kill Evil
Hacktivist group plans retribution after Corman says Anonymous efforts only fill coffers of DDoS protection vendors
BANK INFO SECURITY
SunTrust Is Latest Attack Victim
Seventh U.S. bank suffers outage linked to DDoS attacks
WEBSENSE
Breaking News: The Malicious USA Presidential Spam Campaign Has Started...
Thousands of emails posing as a CNN breaking news alert about the presidential election redirect victims to a website that uses multiple exploits in an attempt to infect the user
DEFENSE TECH.ORG
NSA Director Pushes Cybersecurity Bill
Gen. Keith Alexander, director of the National Security Agency and commander of U.S. Cyber Command, says an executive order isn't enough
COMPUTERWORLD
Microsoft Patches 20 Bugs, Including Critical Word Flaw
Microsoft says MS12-066 vulnerability was used in 'limited, targeted attacks attempting to leverage this vulnerability against Microsoft online services,' the software giant said
TECHWEEK EUROPE
Art Coviello -- There's Proof Governments And Cyber Crooks Are Collaborating
RSA CEO Art Coviello said there�s proof that nation states and cybercriminals are selling gear to each other and working together to breach organizations
BLOOMBERG
Spyware Leaves Trail to Beaten Activist Through Microsoft Flaw
Pro-democracy activist Ahmed Mansoor clicked on a Word attachment in an e-mail that turned out to be rigged with spyware -- he since has been attacked and beaten as well
SECURELIST
Hidden Details About The Last Skype Spread Malware
The Trojan infecting Skype users has an Autorun functionality to spread via USB devices
COMPUTERWORLD
A Better Reason To Avoid Huawei Routers: Code From The '90s
Security researcher Felix "FX" Lindner says a bigger concern for what's inside Huwawei�s routers is their old-school security and vulnerabilities
SOFTPEDIA
Operation Ababil: Hackers Attack Capital One Website, Reveal Future Targets
Capital One was the latest victim of a distributed denial-of-service (DDOS) attack, but the bank's representatives told CNBC that no other systems were affected
SC MAGAZINE
Hacker TinKode Handed Two-Year Suspended Sentence
Accused of cracking, Oracle, MySQL.com, NASA, and the British Royal Navy, hacker gets light treatment in six prison sentences
MSN
Lady Gaga Visits WikiLeaks Chief At Ecuadorean Embassy
Would-be refugee Julian Assange enjoys celebrity visit
SOFTPEDIA
Merkel's Visit To Greece Sparks Fury Of Anonymous; Government Sites Attacked
German chancellor's visit elicits outcry from hacktivists as well as citizens
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



