Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173


Best Of The Web

NETWORK WORLD
Microsoft Patches Hotmail After 0-Day Remote Password Reset Exploited In The Wild
Microsoft has now fixed a zero-day password reset and setup flaw in Hotmail that cybercriminals were already exploiting

THE CHICAGO SUN TIMES
House Passes CISPA Cybersecurity Bill Obama Opposes
The U.S. House of Representatives voted in favor of the Cyber Intelligence Sharing and Protection Act (CISPA), which would encourage companies and the feds to share information on cyberattacks

COMPUTERWORLD
Engineers Look To Fix Internet Routing Weakness
Internet traffic can be maliciously routed in order to spy on communications, so experts are studying for an easier fix to remedy this

THREAT POST
Critical Bug Reported In Oracle Servers
Proof-of-concept exploit code is out for a remotely exploitable bug in all current versions of Oracle's database server -- Oracle reported the bug fixed, but actually only fixed it in upcoming, not existing, versions of the software

SEARCH SECURITY
Google Vulnerability Reward Program Increases, Microsoft Unfazed
Google has increased its bounty for vulnerabilities that allow for code execution to $20,000, but lowered it bounty for lower-risk bugs

CNET
Globalsign Breach Stemmed From Unpatched Server
CA GlobalSign's Web server breach last year was tied to a piece of open-source software not being updated, a senior GlobalSign executive told ZDNet UK

BLOGSPOT
The Facebook Hack -- What Really Happened
Convicted hacker tells the story in his own words

THREAT POST
Backdoor In Equipment Used For Traffic Control, Railways Called 'Huge Risk'
Security researchers warn of risk posed by embarrassing security hole in industrial control software

SECURITY WEEK
Trustworthy Internet Movement Looks To Fix SSL, Certificate Authority Ecosystems
TIM announces that it has chosen SSL governance and implementation as its first project

IT WORLD
FBI Steps UP 'Internet Doomsday' Awareness Malware Campaign
FBI says infected users must deal with DNS changer malware or risk losing Internet in July

CNET
House Approves CISPA Despite Last-Minute Push By Opponents
Bill that allows Internet companies to open their networks to the feds passes by 248-168 vote

TRENDLABS MALWARE BLOG
Usenix LEET 2012: Observations On Emerging Threats
A look at the characteristics and trends in today's most sophisticated exploits

IT WORLD
World's Most Dangerous Hackers Want To Steal How You Make Money
Intellectual property becomes an important currency in cybercrime

CyberCrime & Doing Time
SOCA and FBI Seize 36 Criminal Credit Card Stores
U.K. and U.S. agencies complete joint operation targeting 36 criminal websites

F-SECURE BLOG
A Tumblr Of Rogues
Rogue AV is now lurking in Tumblr accounts, according to F-Secure

THREAT POST
Firefox 12 Debuts With Silent Update Mechanism
Mozilla has released version 12 of Firefox and the browser now includes an automatic update mechanism so users don't have to install patches themselves anymore

ASHIMMY BLOG
Hiding Behind A Mac Is No Longer An Option
The honeymoon is over for Macs, with the recent Flashback malware attack that infected more than 600,000 machines, and Apple's not-so smooth response to the attack

BBC
Insecure Websites To Be Named And Shamed After Checks
Nonprofit Trustworthy Internet Movement (TIM) plan to publish a list of secure and unsecure websites

GOVERNMENT COMPUTER NEWS
Major Cyberattack On U.S. 'Inevitable,' Experts Tell Congress
A panel of cybersecurity experts told Congress yesterday that voluntary guidelines for securing the nation's critical infrastructure have failed and that lawmakers need to enact strong cybersecurity legislation that sets basic security standards

INFORMATIONWEEK
Healthcare's Checklist Security Mentality Failing, Report Says
Despite conducting regular risk analysis, 27% of healthcare organizations suffered a data breach in the last 12 months, twice the percentage reported in 2010

FORBES
Chinese Espionage: The Risks Within U.S. Companies
An equally dangerous cyberespionage threat is from employees or other insiders who steal trade secrets from their corporate employers and hand it over to foreign governments or companies

WEBSENSE BLOG
Weibo Accounts Compromised To Spread Phishing Campaign
New phishing campaigns are rapidly spreading on the Chinese social network Sina Weibo, which has more than 300 million registered users

ARBOR NETWORKS
DDoS Attacks On SSL: Something Old, Something New
As more transactions and services are protected by SSL, DDoS attacks on SSL secured services are on the rise

THE REGISTER
Hackers Now Pick Tools From Script Kiddies' Toybox -- Report
Automated attack weapons help black hats spread the pain

HELP NET SECURITY
Web Application Attack Report From Firehost
Company says it has blocked more than 19 million attacks

MARKETWATCH
One In Every Five Mac Computers Harbors Malware, Sophos Research Reveals
Mac devices may be "carriers" of Windows infections, study says

COUNCIL ON FOREIGN RELATIONS
Understanding Illicit Networks
Globalization is benefiting transnational criminal enterprises as well as mainstream business

RAPID7
Automated Security Assessments Can Stop Untargeted Attacks
Nothing can replace a manual security assessment, but with so many untargeted attacks, why are penetration testers still doing most of their work by hand?

INFOWORLD
Cyber Crime Not A Big Deal? Get Real
Microsoft report indicates that cybercrime stats are wildy inflated, but expert says those stats underestimate the problem

THE REGISTER
UK Biz Pays Heavy Price For Skimping On Security -- PwC
One in seven big firms penetrated by cybercrime, study says

HELP NET SECURITY
New WordPress Update A Must For Users
Open-source blogging tool WordPress has issued an update that fixes some major security flaws

TREND MICRO BLOG
Bogus Olympics 2012 Email Warning Blindside Users With Malware
New Olympics scam email warns recipients of fake websites and organizations selling tickets to this summer?s London Olympics

HUFFINGTON POST
Cybersecurity Bill Loses Key Provision, Dem Blames 'Extremely Partisan' House Republicans
House Republicans removed a key provision from the PRECISE Act bill for securing the power grid and other critical infrastructure -- allowing the Department of Homeland Security to help create cybersecurity standards that companies must meet

CIO
Weak Passwords Still Subvert IT Security
Data breach at the Utah Department of Health last month that exposed Social Security numbers of more than 280,000 people demonstrated how weak and default passwords can be deadly

THREAT POST
Accountability -- Not Code Quality -- Makes iOS Safer Than Android
Apple's policies that demand accountability from iOS developers as well as stricter controls on what apps can do on Apple devices have made the platform more secure than Android

WLTX
228,000 South Carolinians Medicaid Info Sent To Email
A state employee for the South Carolina Department of Health and Human Services has been fired after transferring Medicaid information on 228,000 people to his own e-mail account -- thus far, the agency doesn't know why he stole the sensitive information

ARS TECHNICA
TV-Based Botnets? DoS Attacks On Your Fridge? More Plausible Than You Think
Vulnerabilities in Samsung and Sony TVs demonstrates how these consumer devices could also be attacked for denial-of-service purposes

ZSCALER BLOG
French Budget Minister Website Hijacked
The French Minister of Budget?s website was recently hijacked and rigged with obfuscated JavaScript at the top of the page

ZDNET BLOG
3 Million Bank Accounts Hacked In Iran
An Iranian hacker who discovered a security vulnerability in Iran?s banking system reported it to the banks nationwide; when they ignored his findings, he hacked 3 million bank accounts, belonging to at least 22 different banks, to prove his point

SAN INTERNET STORM CENTER
OpenSSL Security Advisory -- CVE-2012-2110
The OpenSSL team has issued a pathc for a newly found vulnerability that exposes applications that use specific features of OpenSSL


Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)