Best Of Web
Best Of The Web
ASSOCIATED PRESS
AP Exclusive: CIA Following Twitter, Facebook
The CIA follows up to 5 million tweets a day, and also scans Facebook, Internet chat rooms and other open communications
GOVERNMENT COMPUTER NEWS
After Phishing Crackdown, Cyberattackers Switch To Other Weapons
Takedown of botnets and spamming tools forces bad guys to move in new directions
HELP NET SECURITY
Unique Malware URLs Increased 89 Percent
Most-impersonated organizations include the FDIC, the IRS, and the Federal Reserve, IID report says
INFOSECURITY
PwC Director Says Cybersecurity Is In Free-Fall
Business leaders are ignoring the risks of cybertechnology, Beer says
NETWORK WORLD
Ongoing Drive-By Download Campaign Hijacked MIT Server
Server was used to launch attacks against other websites, researchers say
ZDNET
EU And U.S. In First Joint Cybersecurity Stress-Test Exercise
Goal is to strengthen security of international critical infrastructure
WASHINGTON POST
U.S. Cyberespionage Report Names China And Russia As Main Culprits
U.S. officials break with policy, name names in ongoing cyberconflict
BBC
Would Police Use Malware To Catch Cybercriminals?
Ex-hackers help law enforcement to build new strategies for surveillance
BANK SYSTEMS & TECHNOLOGY
Cyberattacks More Frequent And Harder To Detect
Advanced persistent threats (APTs) target banks in particular, Ernst & Young study says
WIRED
WikiLeaks Founder Loses Appeal In Extradition Hearing
WikiLeaks founder Julian Assange will return to Sweden to face sex-crime allegations there
NAKED SECURITY BLOG
Busted! Ukrainian Cybercrime Duo Who Ripped Off $4.5 Million Sent To Prison In UK
Yuriy Konovalenko, 29, and Yevhen Kulibaba, 33, were sentenced after their alleged role in an operation that used malware to steal online banking credentials from unsuspecting victims and siphoning money from them
NETWORK WORLD
'Advanced Persistent Threat' Concerns Boosting Security Budgets
Thirty-two percent of security pros surveyed say APT problem will increase security spending 6 to 10 percent, and 11 percent said spending would jump more than 10 percent
THE REGISTER
Army Of 'Socialbots' Steal Gigabytes Of Facebook User Data
Scripts programmed to mimic people stole 250 GB worth of personal information from Facebook users in two months, researchers said in an academic report to be presented next month
CNET
Apple Reportedly Fires Employee For Negative Facebook Post
Apple reportedly fired an Apple store employee over saying something negative about the company on his private Facebook page
NEW ZEALAND HERALD
'Hackerazzi' Accused Pleads Not Guilty
Christopher Chaney, 35, of Florida has pleaded not guilty to hacking into the emails of Scarlett Johansson, Christina Aguilera, Mila Kunis, and other celebrities
SOFTPEDIA
Anonymous Mexico Denies Attack On Drug Cartel
Mexican faction of the hacktivist group denies being behind or involved with video threatening the Zetas criminal organization
CSO ONLINE
Facebook Denies Vulnerability, Then Quietly Fixes it
Facebook appears to have repaired a vulnerability that could allow someone to send another person a malicious file after saying it was not a weakness
ZDNET
Windows Kernel 'Zero-Day' Found In Duqu Attack
One version of the attack was triggered by a rigged Microsoft Word document, researchers say
THREAT POST
Android Reverse Engineering Toolset Debuts
ARE toolset is implemented as a virtual machine and can break down Android malware
EWEEK
New Mac Malware Part Trojan, Data Stealer, Spyware, BitCoin Miner
Malicious code steals user credentials and computer processing power
NETWORK WORLD
Should You Share Breach Information?
It's time for government to take the guesswork out of the equation
FEDERAL REGISTER
NIST Seeks Comments On Smart Grid Interoperability, Security Standards
Comment period on new guidelines ends in 23 days
NEW ZEALAND HERALD
'Hackerazzi' Accused Pleads Not Guilty
Florida man is on bail after being accused of hacking into emails of multiple celebrities
ALJAZEERA
Assange Loses Appeal Against Extradition
London court rules that WikiLeaks founder should be sent to Sweden to face questioning
INFOSEC RESOURCES
The Pandora's Box Of Cyberwarfare
A look at what could happen if nation-states declare war online
INFOSEC ISLAND
Hacktivist 'The Jester' Draws Crowd At Hacker Halted
The Jester (th3j35t3r) participated in an IRC chat during a session at the Hacker Halted Conference in Miami last week amid rumors he would be one of the presenters
THE GUARDIAN
Met Police Using Surveillance System To Monitor Mobile Phones
British police are using technology that poses as a mobile phone network for surveillance purposes
DANCHO DANCHEV BLOG
Exposing The Market For Stolen Credit Cards Data
Most carding sites are hosted in the Ukraine and the Netherlands, and stolen credit cards are up for sale in a DIY-type market
REUTERS
India Shuts Server Linked To Duqu Computer Virus
Indian authorities seized computer equipment from Mumbai-based Web Werks as part of an investigation into the Duqu malware threat
WIRED
Anonymous Threatens Mexico's Murderous Drug Lords
Anonymous video warns that if the Zetas don't release one of the group's members, the group will reveal the photos, names, and addresses of Zetas-affiliated cops and taxi drivers
COMPUTERWORLD
China A Minimal Cyber Security Threat: Paper
Experts says China's offensive cyber-warfare capabilities are "fairly rudimentary"
THREAT POST
Microsoft Research Proposes E-Voting Attack Mitigation
A countermeasure to the "trash attack" adds a cryptographic hash to the receipts received by voters
BRAD SMITH DONATION PAGE
Voluntary Donations To Help "TheNurse"
Security expert Brad Smith, a.k.a. theNurse, suffered a massive stroke last week during Hacker Halted in Miami, and friends in the industry are asking for donations for pocket expenses for him and his wife during his hospital stay
NAKED SECURITY BLOG
600,000+ Compromised Account Logins Every Day On Facebook, Official Figures Reveal
New official statistics from Facebook reveal that 0.06 percent of the more than billion logins each day are compromised
HUFFINGTON POST
Verizon Privacy Changes: Verizon Now Monitors And Shares Your Web Surfing Information
Verizon says it will use information gathered from its mobile users on the websites they visit, the apps they use, and their location to make mobile ads 'more relevant' to them
MICROSOFT
Microsoft Reaches Settlement With Piatti, dotFREE Group In Kelihos Case
Lawsuit against alleged botnet operators is dismissed in legal agreement
KREBS ON SECURITY
Chasing APT: Persistence Pays Off
Infection found by third-party firm turns out to be legitimate
BLOOMBERG
China Suspected In U.S. Satellite Hacking Attacks
Chinese military interfered with two U.S. satellites in 2007 and 2008, Congressional commission says
EWEEK
Oracle Fixed 57 Bugs In October's Critical Patch Update
Oracle issued 23 patches to remedy 57 security vulnerabilities, including four bugs in its database software and 20 bugs in its Oracle Sun products
REUTERS
Hackers Threaten Fox News Over Occupy Wall Street Coverage
'Anonymous' says it will shut down the Fox News website on Nov. 5
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-1612
Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.1.3, and Symantec Endpoint Protection Center (SPC) Small Business Edition 12.0.x, allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2013-2866
The Flash plug-in in Google Chrome before 27.0.1453.116 does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.
CVE-2013-2969
Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters.
CVE-2013-2968
An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to cause a denial of service via a large file that lacks end-of-line characters.
CVE-2013-4622 (droid_incredible)
The 3G Mobile Hotspot feature on the HTC Droid Incredible has a default WPA2 PSK passphrase of 1234567890, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.



