Best Of Web
Best Of The Web
FIREEYE BLOG
How Advanced Malware Bypasses Process Monitoring
Malware evades detection by directly attacking the operating system's kernel
SYMANTEC BLOG
Trojan.Milicenso: A Paper Salesman's Dream Come True
The Trojan.Milicenso is responsible for an attack of massive print jobs being sent to print servers, printing garbage characters until the printer runs out of paper
SEARCH SECURITY
Google Detects 9,500 New Malicious Websites Daily
Google's Safe Browsing initiative, blocks some 9,500 new malicious websites every day, says Niels Provos, a member of the Google security team
WIRED
DefCon: 20 Years Of Hackers, Hijinks And Snooping Feds
Jeff Moss, a.k.a. The Dark Tangent, launched DefCon in 1992 when he invited several of his hacker pals to Las Vegas to party in the desert
FORBES
CEO Of Internet Provider Sonic.net: We Delete User Logs After Two Weeks. Your Internet Provider Should, Too
Small ISP Sonic.net has reduced the length of time it stores its customers Internet activity logs in order to avoid dealing with legal requests for user data in copyright infringement cases, for example
THREAT POST
PayPal Starts Bug Bounty Program For Security Research
PayPal's CISO announced that the site will pay researchers who report to them new cross-site scripting, cross-site request forgery, SQL injection, and authentication bypass flaws in its website
SECURITY WEEK
Vulnerable SAP Deployments Make Prime Attack Targets
A Russian security firm says close to one-fourth of organizations running vulnerable versions of SAP are leaving them exposed to attack with access to the Internet
THREAT POST
It's The Stupidity, Stupid: How Absurd Pitches Help Online Scammers Find Their Marks
Outlandish claims of Nigerian 419 scams helps separate the skeptics from the suckers, study says
THE REGISTER
Windows 8 "Harder For Malware To Exploit," Says Security Analysis
Microsoft's forthcoming operating system is step forward in security, researcher says
MALWARE BYTES
You Dirty RAT! Part 2 -- BlackShades NET
Remote administration Trojan DarkComet can do some pretty scary things, researcher says
PAYPAL BLOG
PayPal "Bug Bounty" Program For Security Researchers
Company upgrades its bug reporting process into a paid program for finding security vulnerabilities
FAST COMPANY
Ford Schools Apple With Clever Phone Login App...Wait, What?
Ford wants to promote its keyfree car entry, so it created an app that solves password management on Macs
TECHWEEK EUROPE
Microsoft Pressured To Patch Zero Day As VUPEN Creates Serious Exploit
New threat is being exploited in the wild; vulnerability seller finds way to make new threat work across all Windows platforms
REUTERS
Iran Says It Has Detected "Massive Cyber Attack," Says State TV
Iran says it has found a planned attack against its nuclear facilities, according to state television report
THREAT POST
Twitter Denies Hacktivists Behind Severe Outage
Twitter officials say outage was caused by a "cascading bug," and not hacktivists
CSO ONLINE
Virtual Analysis Misses A Third Of Malware
Damballa expert says one-third of malware that goes to a virtual environment for analysis is able to evade detection
ECONOMIC TIMES
Facebook Provides Rare Peek At How Site Is Policed
Teams of Facebook staffers monitor the website for content that violates its policies, including hate speech, bullying and harassment, and pornography.
NAKED SECURITY BLOG
LinkedIn Spam Leads To Pump-And-Dump Stock Scam
New spam posing as LinkedIn emails pushes pump-and-dump stock manipulation scams
SC MAGAZINE
iTunes Vulnerability May Enable Remote Code Execution
A newly discovered heap buffer overflow in iTunes could allow attackers to run remote code on targeted machines -- the flaw was patched in last week's update of the music app
CNN
Police Seek WikiLeaks Founder Assange's Arrest After Asylum Claim
Julian Assange can be arrested for breaking the terms of his bail after he attempted to to claim asylum at the embassy of Ecuador in Britain
ARS TECHNICA
Windows Driveby Attack On Aeronautical Website May Be State Sponsored
European aeronautical parts supplier website was infected with an exploit using an unpatched Windows vulnerability, researchers from antivirus provider Sophos said
SOFTPEDIA
Class-Action Lawsuit Filed Against LinkedIn Over Security Breach
LinkedIn is accused of failing to protect its customers by using an "outdated hashing function"
CNET
Hackers Grab Customer Data, Demand Cash From Payday Lender
AmeriCash Advance said it did not pay the $15,000 ransom that hackers demanded after stealing customer data from its website
FIRE EYE
Dave DeWalt On Why He Joined FireEye
Former chief of McAfee offers his own views on why he moved to smaller firm
THREAT POST
LinkedIn Victims Do Not Connect With Legitimate Notifications
Many users regarded breach notification as spam
PERIMETER E-SECURITY
MLB.Com Distributing Fake Anti-Virus Malware Via Compromised Ad Network
Major League Baseball unwittingly spreading malware, researchers say
INFOSEC ISLAND
FBI Announces Executive Appointments In Cyber Division
Joseph Demarest becomes assistant director working with cybercrimes
SECURITY AFFAIRS
Malware And New Sophisticated Cyber Techniques Against Banking
Banks are key target for both cybercriminals and nation-states, research says
SCHNEIER ON SECURITY
The Failure Of Anti-Virus Companies To Catch Military Malware
A look at why AV didn't catch Stuxnet, Duqu, or Flame
WIRED
Open Letter To Internet Companies: Tell Us How Much We Are Being Surveilled
A call from users to find out how often -- and how deeply -- their privacy is being violated
HELP NET SECURITY
US-CERT Warns Of Intel CPU Flaw
The US-CERT says a flaw in Intel chips leaves users x64-based operating systems vulnerable to system hijacking -- the good news is most affected vendors have issued patches for the flaw
MALWAREBYTES BLOG
You Dirty RAT! Part 2 -- BlackShades NET
A new deadly remote access Trojan tool called BlackShades spreads via P2P, social media, chatrooms, driveby attacks, Java exploits, and phishing emails
ZDNET BLOG
Attack Code Published For 'Critical' IE Flaw; Patch Your Browser Now
Metasploit now has an exploit for a new, critical IE browser flaw that was being used in targeted attacks
NEXT GOV
NSA Chief Endorses Cloud For Classified Military Cyber Program
A spokeswoman for Gen. Keith Alexander says he believes the cloud is a logical place for sharing classified intelligence on cyberthreats with critical industries
THE DAILY BEAST
The Stuxnet Leak Was A Valuable Warning Shot
Experts say the discovery of Stuxnet and Flame are a wakeup call to show that not only the military is able to come up with such high-end malware
THREAT POST
New Fake Android Security App Is Zeus Malware
New malicious Android applications masquerading as a premium security app for the mobile platform is based on Zeus
V3
Firms Wary Of Microsoft Security Updates After Flame Spoof
The F-Secure security chief worries that firms may now stop installing critical Microsoft updates in the wake of the phony updater attacks in Flame, which will make them easier targets for attackers
THE REGISTER
Tech Boffins: Spend Gov Money On Catching Cyber Crooks, Not On AV
A University of Cambridge report concluded that the UK government should be spending more on catching cybercriminals instead of on antivirus software
THE IVIZ BLOG
5 Lessons From The LinkedIn Breach
Have a robust encryption scheme, respond to vulnerability disclosures, have an emergency response team, and penetration-test your application
THREAT POST
Are You 'Siri-less'? Security Firm Urges Closer Look At Popular Personal Assistant App
F-Secure says Apple's Siri voice-activated personal assistant app leaves enterprises vulnerable because that data is stored in Apple's data centers
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3562
Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-3561
Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.
CVE-2013-3560
The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-3559
epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (integer overflow, and heap memory corruption or NULL pointer dereference, and application crash) via a malformed packet.
CVE-2013-3558
The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not terminate a bit-field list, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.


