Best Of Web
Best Of The Web
THE HACKER NEWS
100 Kenya Government Websites Breached By Indonesian Hacker
An Indonesian hacker known as "Direxter" yesterday defaced more than 100 Kenya government websites, including those of the ministries of local government, livestock, environment, fisheries, housing, and industrialization
THE REGISTER
Symantec 'Fesses Up: 'Code Theft Worse Than We Thought'
Symantec now says its network was breached and code for a larger number of products than previously thought was stolen by hackers
HELP NET SECURITY
Hackers Steal $6.7 Million In Bank Cyber Heist
The South African Postbank, which is part of the country's postal service, was hit with a major breach that resulted in a loss of $6.7 million
HEALTHCARE INFO SECURITY
How To Prevent A Data Breach: Attorney Offers Insight For Avoiding Costly Incidents
First step is to learn from others' mistakes, expert says
CNET
Hackers Threaten To Release Symantec Source Code Tuesday
"Yama Tough" says Norton Antivirus code will be exposed, but Symantec says the release poses no threat
REUTERS
U.S. Online Piracy Bill Headed For Major Makeover
Under heavy criticism, SOPA's fast track appears to have been derailed
INFOSEC ISLAND
How To Choose A Security Vendor
Cost issues and free offers can muddy the waters, expert says
GOVERNMENT SECURITY NEWS
DHS Cybersecurity Operations See Leadership Changes
Brown steps down, Streufert appointed as director of CS&C's National Cybersecurity Division
SECURITY NEWS DAILY
Ten Computer Threats You Didn't Know About
A look at some schemes and scams that might have slipped under your radar
FINEXTRA
South Africa's Postbank Loses $3.5 Million To Cybercrime Gang
Cash was looted from ATMs over the New Year holiday
HAARETZ
Cyberattack Against Israeli Websites Used Local Computers, Security Expert Says
Attack took advantage of local bots, Check Point executive says
CNET
Microsoft Security--You've Come A Long Way, Baby
Ten years ago this week, Bill Gates sent the famous memo that changed and improved Microsoft's security woes, with the Trustworthy Computing initiative
ITWORLD
Anonymous Publishes Israeli SCADA Log-In Details
A member of the Anonymous hacktivist collective posted on Pastebin IP-based URLs to Web administrative interfaces that purportedly monitor industrial facilities in Israel
FINEXTRA
PCI Security Standards In The Dock
A restaurant in Utah is challenging the payment card industry's PCI security standards in a lawsuit against their merchant acquirer US Bank in the wake of a customer credit card leak that led to fraudulent transactions
WIRED
Military Networks 'Not Defensible,' Says General Who Defends Them
Gen. Keith Alexander, NSA director and head of the military�s new U.S. Cyber Command, says the ability to protect the Defense Department's information infrastructure is limited
BBC
Why I Left Facebook
Graham Cluley, senior technology consultant at Sophos, says he deleted his Facebook account in the wake of the social network's Timeline rollout -- he worried about its privacy implications as wel as concerns about Facebook's handling of member information
EWEEK
Microsoft Testing Real-Time Botnet Threat Intelligence Data Feed
Microsoft will distribute information collected from several sources on major botnets, including Rustock, Waldec, and Kelihos networks, to foreign governments, law enforcement, Computer Emergency Response Teams, and private corporations via APIs
FORBES
Researcher's Tool Maps Malware In Beautiful 3D Models
A researcher will demo at Shmoocon a new three-dimensional version of a tool he's created called Visualization of Executables for Reversing and Analysis, or VERA, that maps viruses' and worms' code into intuitively visible models
ZDNET ASIA
Fighting Cyber Threats With Malware Not Ideal
Security experts say the practice of creating malware for tit-for-tat cyberdefense is more of an offensive strategy and question the motivations of those who take this tack
THREAT POST
At FBI's Cyber Crime Conference: Chest Thumping And Head Scratching In Equal Measure
Senior law enforcement officials at a conference today hailed their successes in the past year, but others say law enforcement is still behind sophisticated cybercriminals
THE NEW YORK TIMES
Stratfor Relaunches Web Site In Wake Of Attack
Strategic Forecasting Inc (Stratfor) has reactivated its website after a breach that exposed personal information on clients, including Henry Kissinger
THE WALL STREET JOURNAL
Banks Unite To Battle Online Theft
Security officials from Wall Street financial firms such as Morgan Stanley and Goldman Sachs will meet with researchers from the Polytechnic Institute of New York University about creating a center to gather attack data from banks
COMPUTERWORLD
Attack Code Published For Serious ASP.NET DoS Vulnerability
Exploit code for a denial-of-service vulnerability in ASP.NET has been released
THE WASHINGTON POST
Iranian Scientist Involved In Nuclear Program Killed In Tehran Bomb Attack
An Iranian scientist associated with Iran's main nuclear enrichment facility was assassinated when a magnetic bomb attached to his car exploded yesterday
CLIFFVIEW PILOT
Ringleader Admits Role In Identity Theft 'Crime Superstore'
Sang-Hyun "Jimmy" Park, 45, led an effort to steal identities of Asian immigrants who worked in Guam and other American territories
HP BLOG
Psychology Of Information Security -- The God Complex
Security experts should reflect on their "Do as I say, not as I do" security postures -- it's not an easy pattern to break
ICSA LABS
Ramnit's Not Actually a Facebook Worm
ICSA says new Ramnit variant is not Facebook-specific and all about stealing credentials that could be used for online banking
KREBS ON SECURITY
Adobe, Microsoft Issue Critical Security Fixes
If you use Acrobat, Adobe Reader, or Windows, it's time to patch
INFO WORLD
Why Internet Crime Goes Unpunished
Lack of security provides path for high-value, low-risk offenses
INFOSEC ISLAND
Israeli Hackers Counterhack And Steal Saudi Credit Cards
In response to theft of Israeli credit card info, pro-Israeli hackers breach Saudi shopping sites
SECURITY NEWS DAILY
Gangs Are Eavesdropping On Police Radios Via Smartphone Apps
Police scanner apps enable gang members to listen in on secure law enforcement radio transmissions
HELP NET SECURITY
Cyber Crooks Combine New Zeus Variant And DDoS Attacks
"Gameover" purports to be from Federal Reserve Bank, FDIC, or NACHA
DANCHO DANCHEV�S BLOG
Who's Behind The Koobface Botnet?
OSINT analysis exposes botnet masters behind infamous network
PC ADVISOR
Police Arrest ATM Skimmer After $1.5 Million Stolen
Alleged New York "skim king" caught in the act
NETWORK WORLD
Pirate Bay Block Prompts Anonymous To Launch DDoS
Hacktivist group strikes websites of two anti-piracy organizations
HELP NET SECURITY
Stratfor Hack Exposes UK, U.S., And NATO Officials To Danger, Phishing
Attack by Anonymous puts data of high-profile officials in public domain
SECURITY NEWS DAILY
Hackers Get Copy Of Symantec Antivirus Source Code
After initially denying that hackers had anything useful, Symantec now concedes that the source code to an older enterprise software version has been breached
TORRENT FREAK
uTorrent And BitTorrent Surge To 150 Million Users Monthly
Peer-to-peer file sharing site continues to grow by leaps and bounds
HELP NET SECURITY
Five Reasons To Enforce Email Monitoring
Enterprises should look for policy violations, identify heavy users, experts say
THE HACKER NEWS
FBI Arrests Two Suspected Anonymous And LulzSec Hackers
Additional warrants being served in other states, agency says
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



