Best Of Web
Best Of The Web
AOL DEFENSE
Military Debates Who Should Pull The Trigger For A Cyberattack
Offense might be the best defense, military experts say
THE REGISTER
How Zombie LulzSec Exposed Privates' Love Lives with PHP Hack
Single soldiers' site swallowed surprise load
FINEXTRA
U.S. Banks Roll Out P2P Payments Platform
Bank of America, Wells Fargo go live with clearXchange person-to-person payments platform
COMPUTERWORLD
Confidential Data: Delete It Or Eat It
Hoarding sensitive information is easy and inexpensive, but as the collected data grows, so do the risks
FORBES
Researchers Say They Snuck Malware App Past Google's 'Bouncer' Android Market Scanner
Trustwave researchers say they plan to demonstrate proof of concept at Black Hat conference in July
CSO
European Firms Allow BYOD Despite Security Concerns
Apple is the personal mobile device of choice, followed by Samsung
INFOSEC ISLAND
IT Security: Preventing Insider Threats
A "logic bomb" isn't really logical -- it's a virus normally planted by an insider
COMPUTERWORLD
Pwnium Hacking Contest Winners Exploited 16 Chrome Zero-Days
Google yesterday revealed that 'Pinkie Pie' used six unknown flaws and Sergey Glazunov, 10, to hack Chrome in March during the company's Pwnium hacking contest
CNET
FBI Quietly Forms Secretive Net-Surveillance Unit
The Domestic Communications Assistance Center will develop new electronic surveillance technologies, including intercepting Internet, wireless, and VoIP communications
WIRED
NSA Teams Up With Colleges To Train Students For Secret Cyber-Ops Jobs
The National Security Agency is partnering with Dakota State University, Naval Postgraduate School, Northeastern University, and University of Tulsa, to train students in cyberoperations for intelligence, military, and law enforcement jobs -- work that will remain secret to all but a select group of students and faculty who pass clearance requirements, according to Reuters
APPLE INSIDER
IBM Bans Apple's Siri From Its Internal Networks For Security
IBM has barred Apple's Siri and Dictation features for iOS because Apple converts them to text and gathers them
TORRENT FREAK
Megaupload's Kim Dotcom Refuses To Give Up Passwords
Megaupload founder Kim Dotcom wants access to 135 computers and hard drives that were seized from his home in January and refuses to provide his passwords to encrypted data stored on them until he gets them back
HEALTHCARE INFOSECURITY
20 Million Affected By Health Breaches
The U.S. government's count of individuals affected by major healthcare information breaches since September 2009 has now exceeded 20 million and 435 incidents
NAKED SECURITY BLOG
Bredolab: Jail For Man Who Masterminded Botnet Of 30 Million Computers
Georg Avanesov, who made $125,000 a month from the massive Bredolab botnet and lived a lavish lifestyle, was sentenced to four years in jail in Armenia
THREAT POST
Common Firewall Feature Enables TCP Hijacking Attacks
University of Michigan researchers found that a feature common among many firewalls and networking equipment could be used to abused to hijack Web sessions on mobile and desktop devices
QUALYS
Ten Ways To Speed Up Your Patching
Identifying unknown assets, avoiding downtime are two keys
KREBS ON SECURITY
Google To Warn 500,000+ Of DNS Changer Infections
Thousands of systems still infected despite threat of quarantine
SC MAGAZINE
Cybercrime Ringleader Sentenced To Five Years In Prison
Leader of group targeted by FBI's "Operation Phish Phry" is convicted of all charges
HELP NET SECURITY
Trojan Stealing Money In German Online Banking Scam
Tatanga Trojan conducts elaborate man-in-the-browser attack, Trusteer researchers say
SECURITY WEEK
NCC Group Launches DDoS Attack Simulation Service
Service emulates popular attack in a secure, controlled environment
LAW.COM
Corporate Boards Still In The Dark About Cybersecurity
Energy and utility companies fare worst in study of security governance
SECURITY WEEK
Anonymous Hacks U.S. Bureau Of Justice Statistics Server
Nearly 2 Gbps of data is compressed into a single file and uploaded to Pirate Bay
WEBROOT
Spamvertised Bogus Online Casino-Themed Emails Serving Adware
Emails ultimately redirect users to bogus casino site, where systems are infected
PC WORLD
Wikipedia Warns Users About Malware Injecting Ads Into Its Pages
Wikipedia says if you see advertisements on its site for for-profit organizations, you've likely been hit with a browser malware infection
THREAT POST
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
Northrop Grumman is hiring software engineers to help it carry out "offensive cyberspace operations," according to a recent job posting, but a company spokesperson would not elaborate on just what that job would entail
THE NEXT WEB
Google Chrome Overtakes Internet Explorer As The Web's Most Used Browser
Chrome has now surpassed Microsoft�s Internet Explorer (IE) as the most-used browser, new data from StatCounter has found
CSO ONLINE
IT Students Aim For The Security Services
IT students in the UKK say they would like to work for The Secret Intelligence Service (MI6), Security Service (MI5), and GCHQ (Government Communications Headquarters), as well as Apple, Google, Microsoft, IBM, and Intel
THE REGISTER
Anonymous Takes Out Indian CERT As Attacks Continue
The hacktivist collective went after the Indian government again by knocking offline its national CERT and the Indian president's website
SECURITY WEEK
Chicago Police And NATO Websites Hit By DDoS Attacks
AntiS3curityOPS targeted the Chicago Police Department for its actions against protestors, and NATO suffered a DDoS on Sunday by another Anon-related group
NAKED SECURITY BLOG
Selena Gomez's Facebook Account Hacker Jailed For One Year
A 21-year-old British man has been sentenced to one year in prison after saying he hacked into the Facebook account of Justin Bieber's girlfriend, Selena Gomez, and accessed private messages
GOV INFOSECURITY
Who Is Michael Daniel?
The new White House cybersecurity coordinator, a former intelligence branch chief, is expected to reshape the cyberczar role with his policy, budget experience
CNET
FBI 'Looking At' Law That Makes Websites Wiretap Ready, Director Says
Agency needs to be able to 'capture communications' of people under surveillance, Mueller says
DEFENSE NEWS
China Continues Its Focus On Cyber: Report
China continues to develop offensive cyberwarfare capabilities that could disrupt global computer network, Defense Department says
SOPHOS
Call Of Duty Trojan Horse Creator Ends Up In Jail After Drunken College Raid
British man who spread spyware Trojan disguised as video game update gets 18 months in jail
ZDNET
The Pirate Bay Returns, Anonymous Hater Takes Credit For DDoS
Anonymous traitor who goes by name of AnonNyre claims responsibility for attack
CYBER WAR ZONE
Saudi Arabian Hackers Attack Iranian Oil Companies
Several state-backed Iranian oil firms targeted by group from Saudi Arabia
CIFAS
Staff Fraud Report Reveals Complex Set Of Dangers
U.K.'s Fraud Prevention Service reports that insider frauds are up nearly 15 percent
THREAT POST
Trojan Mimics Chrome Installer To Steal Banking Information
Malware impersonating a Google Chrome installer is actually stealing data
KREBS ON SECURITY
Facebook Takes Aim At Cross-Browser 'LilyJade' Worm
Social networking worm spreads via an app built to run as a plug-in across multiple browsers and operating systems
SCHNEIER ON SECURITY
Security Vulnerabilities In Airport Full-Body Scanners
The DHS Office of Inspector General has found "vulnerabilities in the screening process" at U.S. airports using full body scanners, a classified internal Department of Homeland Security report says
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-2969
Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters.
CVE-2013-2968
An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to cause a denial of service via a large file that lacks end-of-line characters.
CVE-2013-4622
The 3G Mobile Hotspot feature on the HTC Droid Incredible has a default WPA2 PSK passphrase of 1234567890, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.
CVE-2013-0484
The server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented API call that triggers the transmission of unexpected data.
CVE-2013-3744
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.



