Best Of Web
Best Of The Web
VERACODE
Which Of The 10 Big Breaches In 2011 Were Application Security Related?
A look back shows that many of the industry's biggest compromises are related to software vulnerabilities
ZDNET
Cybersecurity: Are Stricter Regulations The Answer?
Will new SEC rules make a difference? One expert weighs in
CSO ONLINE
Cerf: Internet Governance Critical Issue
Vint Cerf says Internet governance is one of the most important issues in technology
THE REGISTER
Anti-Kremlin Websites Complain Of DDoS Attacks
Websites questioning the fairness of the Russian parliamentary election were hit by denial of service attacks
THE REGISTER
Mexico Shuts Down Drug Gang's Antennas, Radios
Mexican officials say as Zetas used encrypted mobile network to track the military as well as run operations
HEALTHCARE INFOSECURITY
Congress Probes TRICARE Breach
Five members of Congress are asking TRICARE, the military health program, about a recent breach that affected 4.9 million people
THREAT POST
Researchers Say Carrier IQ Not Logging Texts or Emails, But Has Some Worrisome Capabilities
It can't record SMS messages, phone calls, or keystrokes, but there's still a possibility for abuse by carriers, third parties who can access the data, and hackers
WIRED
HP Hit With Lawsuit Over Flaming-Printer Hack
David Goldblatt, the lead plaintiff, says HP should have warned customers about the flaws ahead of time about a flaw that would allow an attacker to set a printer on fire by taxing its fuser
HELP NET SECURITY
Microsoft Spam-Detecting Algorithm Helps With HIV Research
Similarities in the way spammers shift their strategies to avoid filters and in the way that the HIV virus mutates has led Microsoft to offer some of its technology to help HIV researchers
SOFTPEDIA
Amazon Expiration Emails Lead to Phishing
Phony email says Amazon account about to expire and to be deactivated, but downloading the attachment leads to malware
BUSINESS JOURNALS
Man Who Used Romance In Bank ID Theft Scheme In Philadelphia Sentenced
Miguel Bell, 36, struck romantic relationships with bank employees and an insurance company employee, for example, as part of his identity theft scheme that attempted to steal more than $2 million from victims
M86 LABS
Cutwail Spam Campaigns Lure Users To Blackhole Exploit Kit
The Cutwail botnet is sending malicious spam campaigns posing as airline ticket orders, Automated Clearing House (ACH), Facebook notifications, and scanned documents
INFOSECISLAND
Researcher Traces Stuxnet Duqu Timeline Back To 2006
Cyber warfare expert and researcher John Bumgarner says the viruses had been active for much longer than previously suspected
THE REGISTER
Yahoo! 0-day! Exploit! Hijacks! Status! Updates!
An unpatched bug in Yahoo! Messenger lets attackers hijack a user's status message
INFOSECISLAND
What Facebook's FTC Settlement MeansFor Businesses
Facebook must now get users' permission before it changes how their personal information is shared
CNET
What Does Carrier IQ Do On My Phone -- And Should I Care?
Mobile security researchers say the risk posed by Carrier IQ's software has been overblown
THREAT POST
Google Expands Safe Browsing Alerts To Include Malware Distribution Sites
The company is now giving operators information on dedicated domains that are being used for malware hosting and distribution
V3
Security Spending To Reach $60bn In 2011 As Firms Prepare For Attacks
PwC says security spending will grow at an annual rate of 10 percent over the next three to five years
THE REGISTER
Duqu Attackers: Master Coders, Linux Rookies
Amateur goofs doom global wipe of command and control servers
GIZMODO
Anonymous And Team Poison Join Forces For OpRobinHood To Target Banks And Give To Charities
Plan is to swipe money from stolen credit cards and bank information and give it to charity, reports say
SYDNEY MORNING HERALD
Cybersecurity Bill Advances In The U.S.
Sharing of security data could move forward, thanks to new legislation
ADOBE
Adobe Releases Security Patch For Flex SDK
Update corrects cross-site scripting vulnerabilities
WIRED
Comedy Of Errors Led To False
After many sensational reports, "America?s Stuxnet" turns out to be a red herring
THREAT POST
Two Million Requests From Infected Systems In Week After Ghost Click Takedown
Systems were infected with DNS Changer malware set up by authorities
SOFTPEDIA
FBI: Three U.S. Cities Breached Via SCADA Systems
Critical systems in three unnamed cities were breached and at risk, official says
INDUSTRIAL SAFETY AND SECURITY SOURCE
Putting BEAST Into Context
Level of risk is not as severe as first thought, researchers say
TECH NEWS WORLD
White House, Congress Renew Cybersecurity Push
Congress and the White House are moving forward on efforts to pass national cybersecurity legislation
CNET
Google, Microsoft, Yahoo, AOL Join Agari Anti-Phishing Service
An anti-phishing startup has teamed with major Web-based e-mail providers to stop phishing email from hitting inboxes
THE REGISTER
Anonymous Launches OpRobinHood Against Banks
Hactivists plan to use stolen credit details to donate to charities and others, supposedly at the expense of banks
SF GATE
Hackers Getting Hacked By Security Firms
Whispers of security organizations going further and trying to physically damage or destroy the computer systems of their attackers
KREBS ON SECURITY
DDoS Attacks Spell 'Gameover' For Banks, Victims In Cyber Heists
Cybercriminals are using DDoS attacks against banks and customers as a distraction for more damaging attacks using a Zeus variant called "Gameover"
WIRED
Researcher's Video Shows Secret Software On Millions Of Phones Logging Everything
An Android developer has posted a video of how the Carrier IQ software is secretly installed on millions of mobile phones and reports on what they do with their phones
GOV INFOSECURITY
FBI Gets $18 Million To Bolster Cybersecurity Training
Newly signed legislation will create new jobs in order to help FBI�s anti-cybercrime efforts
INFORMATION AGE
Hackers Accessed City Infrastructure Via SCADA -- FBI
A deputy assistant director of the FBI's Cyber Division says hackers recently accessed the infrastructure of three cities through SCADA systems
ARS TECHNICA
New Jersey DMV Workers Accused Of Selling Identities For $200 A Pop
Insiders at tax office, realty company also accused of using their jobs to sell identities
MSNBC
Millions Of Printers Open To Devastating Hack Attack, Researchers Say
Columbia University researchers lay claim to a whole new class of security flaws
THE REGISTER
Google Researchers Propose Fix For Ailing SSL System
Changes are designed to fix a structural flaw that allows some 600 bodies to issue digital certificates without permission of the domain name holder
GOVERNMENT INFO SECURITY
FBI Gets $18 Million To Bolster Cybersecurity Training
Law creates 42 infosec positions, including 14 special agents
HELP NET SECURITY
Top Ten Cybersecurity Trends For Financial Services In 2012
Increased threats to senior executives, growth of organized crime are at top of list
THE TELEGRAPH
Staff To Be Banned From Sending Emails
Citing drain on productivity, one of Europe's largest IT services firms decides to scrap internal email
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
- Three Principles to Improve Data Security and Compliance
- Aligning IT with strategic business goals: A proactive approach to managing IT risk to your business
- Connecting the Dots: Are You Seeing the Complete Big Data Picture?
- How crowdsourced testing has changed the game for innovative software companies
- Ensuring Your Apps Work in the Real World
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3562
Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-3561
Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.
CVE-2013-3560
The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-3559
epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (integer overflow, and heap memory corruption or NULL pointer dereference, and application crash) via a malformed packet.
CVE-2013-3558
The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not terminate a bit-field list, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.


