Best Of Web
Best Of The Web
THREAT POST
Poison Ivy Variant Changes Benign Code To Malicious After Download
Microsoft researchers have found that bits of code that separately are not malicious but then turn into malicious code when the hit the targeted machine
NAKED SECURITY BLOG
Canadian Resident Sentenced To Death For Writing A Computer Program
Computer programmer Saeed Malekpour, whose photography program was unknowingly used to upload pornography to the Internet, was sentenced to death in Iran where he was arrested while visiting his dying father
US-CERT
Denial-of-Service Malware Campaign
US-CERT issued a warning about Anonymous-led distributed denial-of-service attacks against federal agencies and private sector organizations
POPULAR MECHANICS
Digital Spies: The Alarming Rise Of Electronic Espionage
Foreign agents are stealing stealth technology, hacking heads of state, and sabotaging American companies
HELP NET SECURITY
Hacker Allegedly Leaks 100,000 Facebook Account Credentials Of Arab Users
Israeli hacker posts four installments of Facebook credentials, claims to have 30 million email accounts of Arabs
THE REGISTER
Anonymous Explodes MegaUpload Clone "Scam"
AnonyUpload has nothing to do with us, hacktivist group says
REUTERS
Analysis: New EU Data Laws Command The Tide But Not The Cost
New legislation designed to give customers ownership of their own data and harmonize laws in EU's 27 countries
MARKET WATCH
One In Five Americans Affected By Online Stalking Or Aggressive Outreach Incidents
Nearly two-thirds believe that local police don�t have the ability to deal with cybercrime
HELP NET SECURITY
Researchers Discover Network Of 7,000 Typo Squatting Domains
Network is being used by scammers to drive traffic to their sites
SECURITY NEWS DAILY
Oops! Online Protesters Attack The Wrong SOPA
Scottish Organic Producers Association suffers misguided attacks from militant, but not-too-swift anti-SOPA protesters
CRM BUYER
Guardians Of The Grid: Agencies Unite To Bulk Up Utility Cybersecurity
White House, two federal departments, and electric power industry begin joint effort
THE WASHINGTON POST
Does The Megaupload Takedown Prove That SOPA Is Unnecessary?
The logic behind Congress' much-maligned online-piracy bills was that more weapons were needed to go after copyright infringers overseas. But last week, the U.S. government took down Megaupload, one of the biggest file-sharing sites abroad. A look at whether that implies the new laws are not necessary
CNET
New EU Data Protection Rules Due This Week
Companies will be required to disclose security breaches within 24 hours of their occurrence under European Union proposals being made this week to strengthen data protection rules.
KREBS ON SECURITY
'Citadel' Trojan Touts Trouble-Ticket System
Developers of a new ZeuS Trojan variant are marketing their malware as a social network where customers file bug reports, provide feedback for new and upcoming features, and track trouble tickets for the malware -- another software-as-a-service for malware
WIRED
Warrants Needed For GPS Monitoring, Supreme Court Rules
U.S. Supreme Court ruled unanimously today that authorities must have a probable-cause warrant from a judge to apply a GPS device to a vehicle and monitor its movements
THREAT POST
DreamHost Warns Of Attack, Forces Customer Password Changes
Hosting provider DreamHost says it "detected some unauthorized activity within one of" its databases, so is having all customers change their FTP and shell account passwords
NAKED SECURITY BLOG
Free Amazon.com Gift Card Promotion Is A Facebook Scam
Victims who follow the lure are sent to another Web page that encourages them to sign up for a premium rate mobile phone service -- the scammers also earn affiliate cash by driving traffic to the sites
CNET
FileSonic Disables File Sharing In Wake Of MegaUpload Arrests
File-sharing service FileSonic disabled its sharing function in the wake of the MegaUpload takedown, saying its service can "only be used to upload and retrieve files you have uploaded personally"
ZDNET
Australian Control Systems Exposed Online
Some Australian businesses have left their building management systems exposed to the Internet, potentially leaking sensitive information as well as mundane things, such as the temperature in their office
GOV INFOSECURITY
Decade-Long Virus Infection Discovered
The City College of San Francisco has discovered Trojans and other malware that stole banking information and other information from possibly tens of thousands of students, faculty, and administrators since 1999
WIRED
Hoping To Teach A Lesson, Researchers Release Exploits For Critical Infrastructure Software
A group of researchers has discovered serious security vulnerabilities in General Electric, Rockwell Automation, Schneider Modicon, Koyo Electronics, and Schweitzer Engineering Laboratories PLCs used in critical infrastructure and manufacturing facilities
THE REGISTER
Spam-Squirting Hole Found In Mcafee Antivirus Kit
McAfee says it will fix a vulnerability in its hosted anti-malware service that turns systems that run the product into possible spam-relay nodes
IC3
Fraud Alert Involving E-mail Intrusions To Facilitate Wire Transfers Overseas
The FBI is warning that cybercriminals are using legit e-mail accounts of U.S. individuals to request and authorize overseas wire transactions in a multi-milliondollar scheme -- using money mules in the U.S. and Australia via a romance scam where they are asked to further transfer the funds to Malaysia
REUTERS
Congress Puts Anti-Piracy Bills On Ice
Senate Democratic leader Harry Reid postponed a showdown vote in his chamber on the Protect Intellectual Property Act, and Lamar Smith, the Republican chairman of the House of Representatives Judiciary Committee will delay action on the Stop Online Piracy Act (SOPA) until a compromise can be found
SC MAGAZINE
Tweeters Reveal Personal Details Including Email Addresses
period by business leaders, journalists, and celebrities, who are putting themselves at risk of phishing and other attacks, according to Websense Security Labs
NAKED SECURITY BLOG
Romanian NASA Hacker Gets Suspended Three-Year Sentence
The Romanian man who admitted to hacking into NASA servers has received a three-year suspended prison sentence, and his lawyers have challenged NASA's damage claims of $580,000
THE TELEGRAPH
Kim Dotcom: The Millionaire Playboy Behind Megaupload
Kim Schmitz, the file-sharing website's founder, is accused of heading a $175 million conspiracy of criminal copyright infringement, money laundering, and racketeering � and he has been in trouble with the law before for hacking and theft of trade secrets
BANK INFO SECURITY
Decade-Long Virus Infection Discovered
City College of San Francisco vows updated security in wake of breach that may have affected tens of thousands
CNET
DoJ, FBI, Entertainment Industry Sites Attacked After Piracy Arrests
Anonymous claims credit for shutdown of U.S. Department of Justice, FBI, and Motion Picture Associates sites
THREAT POST
Stuxnet Expert: Analysis Shows Design Flaw, Not Vulnerability, Sank Siemens
Analysis proves that Iran's nuclear program was the target, expert says
BLOOMBERG
Chertoff Urges Swift Action By Senate On Cybersecurity Measures
Former DHS secretary urges Senate leaders to pass legislation to protect hospitals, power plants, and other critical infrastructure
REUTERS CANADA
Virus Infections Stop After Suspects Named
Working with security researchers, Facebook releases the names of five suspected ringleaders
ISOZIAL
Hackers Exploit McAfee Security Bug
Vulnerability in McAfee SaaS Web protection add-on coula allow hackers to turn McAfee customers' PCs into bots
ZERO PAID
How To Find Out If Your Gmail Account Has Been Hacked
Several handy tips for discovering if your Gmail account has been compromised by hackers
APPLE INSIDER
Mac Platform Faced 58 Malware Threats From Q2 To Q4 2011 -- Report
Security research firm says Mac still experiences a fraction of the threats faced by Microsoft Windows
FEDERAL TIMES
NSA Crafting Cyber Guidelines
The National Security Agency is developing cybersecurity guidelines for its own use that could also be adopted by other agencies or contractors, according to sources close to the project; the NSA, meanwhile, will neither confirm nor deny the project
FORBES
Why Sharing Passwords With Your Girlfriend/Boyfriend Is A Spectacularly Bad Idea
Pew found that 1 in 3 teens share passwords with a friend, boyfriend, or girlfriend: a bad idea for privacy, sabotage, and other reasons
PC WORLD
Russian Father And Son Face Charges In U.S.
Vladimir Zdorovenin, 54, of Moscow, and his son, Kirill, have been charged with alleged conspiracy, mail fraud, wire fraud, computer fraud, aggravated identity theft, and securities fraud in a scam that used malware to steal credit card numbers, identities, and financial accounts
NAKED SECURITY BLOG
How To Get Around The Wikipedia Blackout
To reach the popular site during the SOPA/PIPA online protest blackout, run the Firefox NoScript add-on, according to SophosLabs
TREND MICRO
The Koobface Saga
The disclosure of the Koobface gang investigation was unveiled prematurely, according to Trend Micro, which held closely details of its own investigation into the Russian gang behind it
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



