Best Of Web
Best Of The Web
BANK INFO SECURITY
Business Case For ID Theft Recovery
More banks need to step up efforts to assist victims, expert says
THE REGISTER
Phishers Net Norwegian Secrets
Oil, gas, and defense data stolen from computers in Norway in country's largest-ever data espionage case
INFOSEC ISLAND
Three Words To Describe Enterprise Security
Security professionals express frustration with funding, technology
MSNBC
U.S. Reserves Right To Meet Cyberattack With Military Force
Pentagon says military is sharpening its ability to track down the source of any attack
THE AGE
USB Keys Are Unexploded Security Bombs In Companies
Flash drives are tremendous tools, but with handy portability comes security risk, experts say
DAILY MAIL
Real-Life Star Wars: U.S. Claims Chinese Military Was Behind Hackers Who Seized Control Of Two U.S. Satellites
Environment-monitoring satellites were "interfered with" four or more times in 2007 and 2008, officials say
HUFFINGTON POST
2012 Cybersecurity Warnings: Online Identity More Valuable Than Credit Cards
Your social media profile could be more valuable than your credit card to cyberthieves, study says
HELP NET SECURITY
Hiding Messages In VoIP Packets
Researchers demonstrate simple way of hiding information within VoIP packets exchanged during a phone conversation
CBR
Half Of SMBs Don't Consider Themselves Targets Of Cyberattacks: Symantec
Study also shows that SMBs accounted for 40 percent of targeted attacks in 2010, compared to 28 percent targeted toward large enterprises
THREAT POST
Google Fixes High-Risk Flaw In Chrome
Flaw in V8 JavaScript engine could cause a memory corruption condition, researcher says
ZDNET
South Korea To Block Port 25 As Anti-Spam Countermeasure
In an attempt to stem the flow of spam, South Korea is considering a nationwide block of port 25--but experts say this won�t work
IT PRO PORTAL
Hackers Adapt Siri To Run On Any Smartphone Device
The big new feature of the iPhone 4S is the voice-activated search tool called Siri, and now hackers have made it possible to run Siri on any phone
THREAT POST
Android Malware, Up 472 Percent, Seeing Fastest Growth Ever
In October, Android malware jumped to a 110 percent increase over September, and a 171 percent increase from July of this year
THREAT POST
Researchers 'Convinced' Duqu Written By Same Group As Stuxnet
Kaspersky Lab researchers say the writers of Duqu are tied to the development of the Stuxnet worm
CNET
Google, Facebook, Zynga Oppose New SOPA Copyright Bill
Web companies sent a letter to members of the U.S. Senate and House of Representatives calling the Stop Online Piracy Act "a serious risk to our industry's continued track record of innovation and job creation, as well as to our nation's cybersecurity"
TECHWORLD
Iran Secrecy To Blame For Duqu Infections, Claims Researcher
Antivirus researcher says Iran's policy of not sharing malware samples delayed the detection of Duqu
CSO ONLINE
Unemployed Romanian Hacker Accused Of Breaking Into NASA
Robert Butyka, 26, was arrested on Tuesday in Western Romania for allegedly hacking multiple NASA servers and incurring $500,000 in damages to NASA systems
NETCRAFT
Sustained DDoS Attack Against 4chan
4chan has been under siege from a sustained DDoS attack using UDP packets to flood port 80
SECURITY NEWS DAILY
Cyberwar Most Likely To Take Place Among Smaller Powers, Experts Say
Smaller countries and groups that have no diplomatic channels are more likely to launch online attacks than superpowers
WALL STREET JOURNAL
U.S., China Confer On Internet Privacy Concerns
To succeed in cloud services environments, China will have to prove its security mettle, U.S. officials say
TALKING POINTS MEMO
Bank of America's Google Plus Page Appears "Brandjacked"
Page created on BofA's behalf actually contains negative material about the bank
HELP NET SECURITY
Expect An Escalation In Targeted Attacks
Stolen digital certificates and zero-day attacks will characterize new wave of exploits targeting specific organizations, M86 Security says
SECURITY NEWS DAILY
French Nuclear Energy Firm Fined $2M For Hacking Greenpeace
EDF illegally broke into environmental group's systems to find out its plans for blocking construction of new nuclear plants
G+
Standards Authors Seek Input On Cloud Security Specifications
Cloud Security Alliance, other groups request ideas on new developments in cloud security standards
THREAT POST
Apple Fixes Man-In-The-Middle Bug In iTunes
Vulnerability could give users a fake app that looks like iTunes
TECH REPUBLIC
Exploring Underweb Forums: How Cybercriminals Communicate
A look at the rules and practices behind cybercrime forums
ANDROID AUTHORITY
Most Free Anti-Malware Apps For Android Nearly Useless
AV-TEST study found out only one of the seven free anti-malware apps for Android that the company tested offers acceptable safety and protection
PC WORLD
French Energy Firm Sent Trojans To Spy On Greenpeace
Nuclear security executive at France�s EDF was sent to jail and his company fined after he was found guilty of of spying on Greenpeace using Trojan malware
THREAT POST
TDSS Rootkit And Dnschanger: An Unholy Alliance
Dell's Secureworks researchres have seen between 600,000 and 1 million unique IP addresses infected with the DNSchanger Trojan in recent weeks, with TDSS downloading and installing it
CIO
F-Secure Finds Malware Signed With Stolen Digital Certificate
Researchers discovered a software sample that carried a valid code-signing certificate from a Malaysian government institution
SC MAGAZINE
Occupy St. Louis Sympathizer Hacks Mayor's Website
A hacker infiltrated the website of the St. Louis mayor, defacing it and exposing contact information and emails
THE WASHINGTON POST
Contractors Wary Of New DoD Rule On Unclassified Data
Proposed Defense Department rule would make contractors employ either a "basic" or "enhanced" level of protection to unclassified information
ZDNET
RSA: Hack Was Like 'A Spy Novel'
SecurID "information in and of itself couldn't have been used in an attack," RSA CEO says
CYBERSECURE GEEK
DARPA Increase Budget To Improve Internet Security
The Defense Advanced Research Projects Agency (DARPA) is looking for an $88 million 2012 budget increase for cyber-research
WIRED
Judge Rules Feds Can Have WikiLeaks Associates' Twitter Data
A federal judge said the Justice Department is allowed to access records of the Twitter accounts used by three current and former WikiLeaks associate including Jacob Appelbaum
ITAC BLOG
Better Business Bureau Warns Of Scams Targeting Veterans
Beware of scammers and identity thieves preying on U.S. soldiers on Veterans Day
MICROSOFT TECHNET BLOG
Fraudulent Digital Certificates Could Allow Spoofing
Microsoft is providing an update for Windows that revokes the trust in CA DigiCert Sdn. Bhd.
BBC
Facebook 'To Seek Consent For Privacy Changes'
Facebook reportedly will ask users to opt into any new changes in in how it uses their personal information
SECURELIST BLOG
Hackers Hit Steam Gaming Service In Latest Data Breach
A separate set of attack files was made for each victim, according to new research by Kaspersky Lab, and each set of files used a separate control server
INFOSEC ISLAND
Top Five Security Settings For Apple iPhones And iPads
Passcodes, erase data, find my iPhone/iPad, backup encryption, and updating iOS are all key security features
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



