Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173


Best Of The Web

MERRITT GROUP
InfoSex Sells: The Disconnect Between News Priorities And Cybersecurity Defense Priorities
A look at how the media serves ? and sometimes fails to serve ? the security audience

DATABREACHES.NET
Estee Lauder Employees Notified That Their Data Were On Stolen Laptop
Estee Lauder reported that the company "recently learned" about the theft of a company-issued laptop that contained names and Social Security numbers of current and former employees and contractors

IT WORLD
Can The NSA And CIA Use Your Phone To Track Your Location?
National Security Agency's general counsel told Congress there are "certain circumstances where that authority may exist" for the spy agency to intercept location data from U.S. citizens' cell phones

THE WASHINGTON POST BLOG
Cyber Attack On RSA Cost EMC $66 Million
EMC disclosed in its earnings call this week that it spent $66 million in its second quarter on the breach at its subsidiary RSA Security -- on system-hardening and working with customers on remediation programs

NAKED SECURITY BLOG
Unpatched iPhones/iPads Secure Connections Not So Secure
Turns out Apple's updates for iWork and iOS were more serious than thought -- and a new update to sslsniff detects vulnerable Apple devices for man-in-the-middle attacks

KTNV NEWS
UNLV Confirms Possible Security Breach
The University of Nevada-Las Vegas has reported a possible information security breach that took place in 2008 and exposed personal information including SSNs of 2,000 current and former UNLV employees

THREAT POST
How I Taught The Senate To Hack
Chris Wysopal of Veracode and former member of L0pht, recently taught Senate staffers on the Homeland Security and Governmental Affairs Committee about SQL injection, spear phishing, and other attacks

CSO ONLINE BLOG
New Akamai Security Team In Place: McKeay Joins Corman, Smith, Ellis
Security blogger, podcaster and QSA Martin McKeay and former 451 Group analyst Josh Corman are joining Akamai in a new team called Security Intelligence

NETWORK WORLD
Black Hat Pwnie Award Winner Will Be A Criminal
The Pwnie Award for Epic Ownage at Black Hat will go to one of the nominees who face possible criminal charges -- Anonymous, LulzSec, Bradley Mannning, WikiLeaks, and the creators of Stuxnet

GOVERNMENT COMPUTER NEWS
Team Cracks Chips Used In Military, Aerospace
German team of researchers breaks encryption codes used on programmable chips

BBC NEWS
Hackers Hit Italian Cyber-Police
Attackers begin releasing gigabytes of stolen documents

SYMANTEC
Symantec Announces July 2011 Symantec Intelligence Report
Email-borne malware has doubled in the past six months, study says

INFO SECURITY
Anonymous And Lulzsec Hackers Hit Italian Cybercrime Unit
Hacker groups begin releasing classified documents

SECURITY NEWS DAILY
Why We Won't Soon See Another Stuxnet Attack
Sophisticated, multilayered attack will be hard to reproduce, experts say

SOPHOS
Obama Outlines Strategy To Combat Transnational Cybercrime
President urges greater international cooperation to defeat online crimes

THREAT POST
New Mac Backdoor Olyx Found Bundled With Windows
Exploit is another example of Mac OS and Windows malware in a single package

THE REGISTER
Suspects In PayPal Web Attack Not So Anonymous After All
Several arrested following DDoS attack say they didn't know they were committing a felony

THE SUNDAY MORNING HERALD
Kate, Family Likely Hacker Targets
The Duchess of Cambridge and her family might have been victims of the News Corp. phone hacking scandal

TREND MICRO COUNTERMEASURES BLOG
Why Don't Cybercrime Rewards Work?
Microsoft Anti-Virus Reward program has been around since late 2003, and successes are outnumbered by cold cases

ZDNET
Anon Hackers To Expose Aussie Cybercops?
A preview leak from a hacking group associated with the AntiSec movement has threatened to expose communications between one of Europe's top cybercrime divisions and its global partners

THE NEXT WEB
Google Is Learning Lessons From Google+ 'Fake Names' Debacle
Google over the weekend purged Google+ of accounts that appeared not to be using real names

PWNIE AWARDS
The Nominees For Pwnie Awards Announced
Sony has all five nominations for 'Epic Fail,' while the HBGary hack, Stuxnet, and LulzSec are among 'Epic Ownage' nominees

NAKED SECURITY BLOG
Twitter Phishing Attack Spreads Via Direct Messages
Some Twitter users have been receiving phony direct messages from other members of the network using lures, such as photo, video, or blog mentions

PC MAGAZINE
Suspected LulzSec Hacker Released On Bail In U.K.
A British teenager known as "Tflow," who is reportedly a founding member of the hacker collective LulzSec, has been released on bail, and Dutch authorities have also released four individuals associated with LulzSec, according to reports

BLOOMBERG
Ex-Akamai Worker To Plead Guilty To Espionage For Disclosing Trade Secrets
Former Akamai Technologies employee Elliot Doxer, 42, of Brookline, Mass., will plead guilty to the charge of foreign economic espionage

COMPUTERWORLD
Adobe Recants Knock On Apple's OS X Lion
After saying earlier this week that Flash doesn't work on Apple OS X Lion's hardware acceleration, Adobe says a testing error led to an incorrect conclusion, and that Flash is hardware-accelerated in the OS

THE REGISTER
Japanese Judge Jails Serial Malware Author
Masato Nakatsuji, 28, has been sent to jail for two-and-a-half years for writing malware that spreads via P2P file-sharing networks--and he wrote it while on probation for an earlier malware-writing incident

THE CYPRESS TIMES
Cybersecurity Enhancement Act Passes Committee
The Cybersecurity Enhancement Act of 2011, which will force federal agencies to tighten their network security and help R&D and in building out the cyberworkforce, goes to the House floor

SCHNEIER ON SECURITY
Is There a Hacking Epidemic?
It's not that things are getting worse -- it's that things were always this bad

INFOSEC ISLAND
What To Do If Your Gmail Account Has Been Hacked
Be sure you have a secondary email address that can be used to recover an inaccessible Gmail account, and if you get hacked, check your Google Gmail settings to be sure your messages aren't being automatically forwarded to the hacker

TECH EYE
Cisco Blasted For Arranging Arrest Of Whistleblower
A Canadian judge criticized Cisco for arranging for the criminal arrest of a whistleblower who was suing the company

HELP NET SECURITY
New French eID Card To Tackle Identity Theft
The French National Assembly passed a new law on identity protection, but the government must find a way to effectively manage biometrics and personal information to support the program

BUSINESS WEEK
China-Based Spies Said To Be Behind Hacking Of IMF Computers
Sources close to the investigation into the hacking of the International Monetary Fund say the attack was conducted by cyberspies connected to China

THE REGISTER
LulzSec Says It Will Partner With The Media On Murdoch Emails
Hacker group says it will work with media on slow rollout of publisher's emails

THE REGISTER
Major Overhaul Make OS X Lion King Of Security
Windows 7, Ubuntu meet their match, experts say

ABC NEWS
Terror Warning Warns Of Insider Threat To Utilities
Sabotage could provide Al Qaeda or other groups their best chance at a Sept. 11-like attack, officials say

ELECTRONIC FRONTIER FOUNDATION
Fragmenting The Internet Is Not A Security Solution
"Separate, secure Internet" could create inequities, privacy concerns

SOPHOS
Serial Virus Writer Jailed For Orange Cartoon Octopus Malware
For the first time, Japan applies property destruction laws to a virus creator

SEATTLE TIMES
20,000 Swedish Employees' Personal Data Breached
Data was inadvertently made accessible on the Internet for nine weeks

REUTERS
Sony Insurer Sues To Deny Data Breach Coverage
Zurich American might argue that general liability insurance doesn't cover digital attacks


Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)