Best Of Web
Best Of The Web
COMPUTERWORLD
Def Con: How To Hack All The Transport Networks Of A Country
A look at social engineering, subway attacks, and other potential attacks presented at Def Con conference
CNBC
Senate To Vote On Weakened Cybersecurity Bill
Bill would introduce voluntary process for U.S. companies to follow
ZDNET
Power Pwn: This DARPA-Funded Power Strip Will Hack Your Network
It may look like a power strip, but it's actually a tool for hacking Bluetooth, wireless, and Ethernet networks
INFOSEC ISLAND
Information Security, Hackers, And Vigilance
Black Hat classes teach security professionals how to think like a hacker
THREAT POST
Millions Of Mobile Phone Users' Data Leaked In South Korea Scam
Almost 9 million users' data leaked, law enforcement officials say
AVG
Scammers Compromise Pinterest Accounts
Accounts hijacked; affiliate links posted on user boards
HACK IN THE BOX
Hackers Crush Huawei Routers
Def Con speaker details vulnerabilities in three small routing devices built in China
SOPHOS
Team Poison Hacker Jailed Over Tony Blair Security Breach
Teenage hacker stole data from former prime minister
HOMELAND SECURITY NEWS WIRE
The Five Biggest Stories At Black Hat
A look at some of the news coming out of last week's conference in Las Vegas
BANK INFO SECURITY
Michaels Breach: Fraudsters Sentenced
Two men convicted of stealing debit card information
THREAT POST
New Tool From Moxie Marlinspike Cracks Some Crypto Passwords
Vulnerable MS-CHAPv2 protocol is used for VPNs and some wireless networks
SEARCHSECURITY
Poor Mobile App Security Drains Enterprise Data
Malicious mobile apps designed to steal sensitive data get a lot of attention, but one expert says legitimate apps could pose more danger to enterprises
COMMITTEE TO PROTECT JOURNALISTS
For Journalists, Danger Lurking In Your Email
University of Toronto's Citizen Lab shared research into the likely use of a commercial surveillance program called FinFisher to remotely invade and control the computers of Bahraini activists
SEARCH SECURITY
Black Hat 2012: Dan Kaminsky Tackles Secure Software Development
Dan Kaminsky's Black Ops talk focused on secure software development not only for Web applications, but also OS kernel development, as well as a new technical means for improving the time it takes to find bugs
THREAT POST
Vasillis Pappas Wins $200,000 Microsoft Blue Hat Prize
Vasillis Pappas won with his kBouncer ROP mitigation technology that will be integrated into Microsoft software
PACKET STORM SECURITY
Stuxnet Moral Crime Or Proportionate Response?
Marcus Ranum said it's a "moral crime" for putting civilian infrastructure on the front line of "a non-existent war" while Jeff Moss said that he was more supportive of using malware as a military option
WIRED
NSA Chief Tells Hackers His Agency Doesn't Create Dossiers On All Americans
Dressed in blue jeans and a T-shirt, Gen. Keith Alexander called DefCon was "the world's best cyber community" and appealed to attendees for help in solving some of the problems of security and privacy
COMPUTERWORLD
New Mac Trojan Hints At Ties To High-Priced Commercial Hacking Toolkit
A new Mac Trojan does not exploit a vulnerability but relies on social engineering to get the user to self-infect his Mac with the so-called 'Crisis' /�Morcut� Trojan that spies on IM, browsing, and Skype communications
THE REGISTER
Chip And PIN Keypads 'Easily Fooled' With Counterfeit Cards
Retail Chip and PIN devices might easily be attacked using a specially prepared chip-based credit card, according to security researcher
EWEEK
'Gameover' Financial Botnet Compromises Nearly 700,000 Victims
Infection affects 14 of Fortune 500 companies, researchers say
CYBER WAR ZONE
Iran: U.S. Cyber Attack Will Face 'Teeth-Breaking' Response
Country plans to fight back after Stuxnet, official says
ELECTRIC CO-OP TODAY
Cyber Security In Capital Spotlight
Electric cooperatives push hard at home and in Washington to protect themselves from cyberattacks
THREAT POST
From Three Nations And Three Different Perspectives, Blue Hat Finalists Focus On Defense
A look at the winners of Microsoft's security awards, revealed this week at Black Hat USA 2012
CNET
Pen And Sword Equally Mighty For Science Fiction's Stephenson
Reclusive writer makes a rare appearance at Black Hat USA 2012
RSA
Lions At The Watering Hole -- The 'VOHO' Affair
New type of attack discovered by security researchers
SEARCH SECURITY
Black Hat 2012: Poor Mobile App Security Drains Enterprise Data
Legitimate apps could pose an even greater threat than malicious apps, speaker suggests
INVINCEA
Mapping Malware Genomes -- Advanced Visualization
Security visualization technique is demonstrated at Black Hat 2012
GAZETTE TIMES
OSU Notifying Individuals Of Data Security Breach
Law enforcement is investigating a security breach by a vendor under contract to Oregon State University copied information from a check register database without permission
THE REGISTER
Japanese Govt Sucked Dry For Two Years By Trojan
Japanese government officials say an advanced Trojan attack leaked confidential data for over two years
THREAT POST
Experts Say Better Security Rests On Cooperation, More Data
Panelists at Black Hat say while defenses have improved, so have attackers and achieving the upper hand requires a cooperative effort among users, the security industry, and government
NETWORK WORLD
Symantec President And Ceo Replaced By Company's Chairman
Symantec president and CEO Enrique Salem stepped down after the company reported that its revenue for the quarter ended June 29 grew just 1 percent year-over-year to US$1.7 billion, while its profits sagged by 10 percent
BBC
Stuxnet Thwarted By Control Code Update
German engineering giant Siemens has issued a fix for the software loopholes used by the notorious Stuxnet worm
SEARCHSECURITY
Black Hat 2012: Windows 8 Security Features Beat Buffer Overflow Attacks
Windows 8 includes Windows Heap Manager and Windows Kernel Pool Allocator, and researchers will demonstrate how they beat the new heap overflow mitigations
TIME
Mom Hacks Into School Computer System, Changes Her Kids' Grades
A Pennsylvania woman faces six felony charges for hacking into the Northwestern Lehigh School District computer system and altering the grades of her two children
COMPUTERWORLD
OS X Mountain Lion To Launch Wednesday, Apple Says
OS X 10.8, known as Mountain Lion, arrives tomorrow
THREAT POST
Feds Show Up At DEF CON And Black Hat, But This Time To Talk, Not Snoop
Federal government officials used to be considered as interlopers and objects of derision at Def Con and Black Hat, and now they are a part of the conferences
NAKED SECURITY BLOG
Malware Attack Spread As Email From Your Office's HP Scanner
A jump in malware spreading as emails from HP devices has been spotted by Sophos
FORBES
Eight Million Email Addresses And Passwords Spilled From Gaming Site Gamigo Months After Hacker Breach
Four months after the gaming site Gamigo warned users about a breach that accessed some of its users' credentials, more than 8 million usernames, emails, and encrypted passwords have been dumped online
PC WORLD
Hacker Arrested For 2008 DDoS Attacks On Amazon.Com
A 25-year-old Russian has been arrested for allegedly heading up two DDoS (Denial-of-Service) attacks on Amazon.com and eBay in 2008
EWEEK
Black Hat Conference Spotlights Mobile Security, Critical Infrastructure
The 15th annual Black Hat conference will be the largest ever and the conference will feature privacy, critical infrastructure, and mobile security issues
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-2059
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
CVE-2013-2007
The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.
CVE-2013-2006
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
CVE-2013-1977
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.
CVE-2013-1964
Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possible have other impacts via unspecified vectors.


