Best Of Web
Best Of The Web
THE REGISTER
Brits Guard Facebook Passwords More Than Work Logins
A third of users have shared their work logins, but only 20 percent say they share Facebook credentials
CNET
Tech Firms Agree To Privacy Protections For Mobile Apps
Apple, Google, Microsoft and others agree to inform users of data usage policies before they download apps
WIRED
Ruling Stands: Defendant Must Decrypt Laptop
Woman who faces years in prison says decryption would violate her Fifth Amendment rights; appeals court says defendant must be acquitted or convicted before appeal can take place
SECURITY NEWS DAILY
Hidden Security Worms May Loom In Apple�s Future
Rapid growth of platform could lead to increased targeting by hackers, experts say
INFO SECUIRITY
Firms Move Ahead With Mobility, Despite Security Concerns
More than 41 percent of IT professionals in Symantec study say they are worried about security risks posed by mobility programs
INFOSEC ISLAND
DHS's Mark Weatherford On The Cybersecurity Act Of 2012
Deputy undersecretary for cybersecurity publicly endorses proposed legislation
COMPUTERWORLD
Google, Microsoft Butt Heads Over IE Privacy Skirting
Google countered Microsoft's assertion that the search engine giant is skirting Internet Explorer's privacy protections
GARTNER BLOG
Proposing An International Cyberweapons Control Protocol
Gartner analyst says protocols for cyberweapons weapons control and law enforcement are linked and lauds Eugene Kaspersky�s views on cyberwar
SECURELIST
DDoS Attacks In H2 2011
Kaspersky Lab says the longest DDoS attack in the second half of last year was against a travel website and lasted 80 days, 19 hours, 13 minutes, and five seconds
RAPID 7 COMMUNITY
Metasploit 4.2 Released: IPv6, VMware, And Tons Of Modules
New version of popular hacking tool supports opening command sessions and shells on IPv6 networks and existing payloads in Metasploit now also support IPv6
BANK INFOSECURITY
Tips To Fight Debit Fraud
New American Bankers Association report finds that POS signature suffer more losses than PIN-debit and ATM, which are a bit safer with their PINs, and debit card losses are now more than paper check fraud
HELP NET SECURITY
Users Don't Bother Changing Default Passwords
Most people rarely change default, automatically generated and assigned passwords, and only about 25 percent change their passwords regularly
ZDNET
Microsoft Quietly Extends Consumer Support For Windows 7, Vista
Microsoft this month changed its support policy for consumer versions of Windows � now Vista and Windows 7 will get a full 10 years of support
MOBILE COMMERCE PRESS
Visa Criticizes Lackluster Security Measures For PayPal�s New Mobile Payment Platform
Visa is warning anyone that chooses to use PayPal�s platform to guard their PINs so their financial information isn�t stolen
CNET
Scared Of Anonymous? NSA Chief Says You Should Be
Hacktivist group is growing more powerful, official says
IT NETWORKS
Hacker Jailed For Infiltrating Facebook Servers From His Parents� House Last Year
Hacker who �tested� secure areas of Yahoo gets eight months for doing the same to Facebook
GOVERNMENT COMPUTER NEWS
The Riskiest Cities For Cybercrime: Where Does Yours Rank?
Nation�s capital takes top spot in Symantec report
bit9
State-Sponsored Threats: Q&A With Richard Clarke
Former White House cybersecurity adviser offers insight on foreign governments� initiatives
FEDERAL NEWS RADIO
DHS Defends Social Media Monitoring Program
Congress takes closer look at privacy aspects in Homeland Security program
CYBER NEWS
Anonymous Hackers Promise 'Something Big' Is Coming
Hacktivist group says a massive announcement will take place later this week
IT NETWORKS
Hackers Can Follow You Via Your Cell Phone
With cheap equipment, hackers can easily locate where you and your phone are, University of Minnesota study says
MARKETWATCH
New Survey Highlights Security Risks Facing Health IT And Security Professionals
Rapid adoption of mobile technologies brings new challenges to health care settings
THE GASTON GAZETTE
IRS: Beware Of Dirty Dozen Tax Scams
The Internal Revenue Service has issued its annual "Dirty Dozen" tax scams list to warn taxpayers about scams and threats including identity theft and return preparer fraud
THE WASHINGTON POST
Google Pulls Cookies That Tracked Users Through Safari
Google has removed special code it had reportedly attached to users' cookies when they ran Apple Safari browser that allows advertisers and Google to bypass Safari's ability to block third-party cookies
THREAT POST
Google Password Generator In The Works
Google is building a tool to help users generate strong passwords for websites as an interim solution until the OpenID standard becomes widely deployed
ARS TECHNICA
Is Megaupload "A Lot Less Guilty Than You Think?"
Legal experts say Megaupload is likely in serious legal trouble, but Jennifer Granick, a Bay Area attorney blogging for Stanford's Center for Internet and Society, raises the distinction between civil and criminal law in the case
HELP NET SECURITY
Thwarting Attacks With Genetically-Inspired Computer Configuration Systems
Automated security technology would be capable of learning from experience
TRUSTEER
Merchant Of Fraud Returns -- Shylock Polymorphic Financial Malware Infections On The Rise
Each new build of this polymorphic malware contains excerpts from Shakespeare's The Merchant of Venice
THREAT POST
What You Need To Know About The RSA Key Research
RSA algorithm is not broken, analysis says
FORBES
Anonymous Plans To Take Down The Internet? We're Being Trolled
Hacktivists' plan to take down the Web�s core address book could be a hoax, expert says
SANS INSTITUTE
SANS Launches Eighth Annual Log And Event Management Survey
Study aims to collect data on how enterprises collect and use log and event data
SOFTPEDIA
Stratfor Faces Lawsuit For Failing To Secure Customer Data
Lawsuit demands more than $50 million
ARBOR NETWORKS
DDoS Attacks In Russia Added To Protests
Political protests include cybersecurity exploits
ALERTSEC XPRESS
University Of North Carolina At Charlotte Is Latest Victim Of Data Breach
Authorities scrambling to figure out how much data has been compromised
THREAT POST
Bloody Valentine For Critical Infrastructure: EtherNet Exploit Could Crash Devices
A new batch of PLC exploits was released by researchers that includes one exploiting a bug in the implementation of the EtherNet/IP (Internet Protocol) used in many IP-enabled PLCs
THE HACKER NEWS
Anonymous Hackers Target Nasdaq Website
A DDoS attack against websites for Nasdaq and BATS temporarily caused disruptions to the those sites -- Nasdaq says no information was stolen and trading was not affected
REUTERS
Philips Investigates Possible Cyber Security Breach
Philips Electronics shut down one of its servers yesterday due to a possible attack under investigation there
ZDNET BLOG
Have You Uninstalled Java Yet? Here Are 14 New Reasons...
Oracle's new patch release included 14 new vulnerabilities in Java SE, some that let hackers remotely install malware on machines without authenticating to them
INFOWORLD
Mozilla Will Ask All Certificate Authorities To Revoke SSL-Spying Certificates
Mozilla will request that certificate authorities revoke certs that could be used by companies to inspect SSL traffic for domain names they don't control in response to Trustwave revealing that it had done so
REUTERS
Experts Say Iran Has 'Neutralized' Stuxnet Virus
Iranian engineers have cleaned up and neutralized Stuxnet from their countrys nuclear systems, European and U.S. officials and private experts say
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
- Remote Data Replication: Combat Disasters And Optimize Business Operations
- Riverbed vs Silver Peak: WAN Optimization Vendors Put to the Test
- Storage Infrastructure as a Service The Best of Cloud and On-premises Storage
- Putting Metaswitch's SBC Software to the Test
- When It Makes Sense to Move to Desktop Virtualization: Seven Key Indicators
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-4612 (redcap)
Multiple cross-site scripting (XSS) vulnerabilities in REDCap before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving different modules.
CVE-2013-4611 (redcap)
Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Online Designer page or (2) the Manage Survey Participants page.
CVE-2013-4610 (redcap)
Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact and remote attack vectors.
CVE-2013-4609 (redcap)
REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.
CVE-2013-4608 (redcap)
Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View & Descriptive Stats page.



