Best Of Web
Best Of The Web
SYMANTEC
Malicious Mandiant Report In Circulation
Attacker uses Mandiant APT1 report as bait to infect those who want to read it
INFOSECURITY
Sophisticated Banking Threats Branch Out To Other Sectors -- And Get Smarter
Cyberattacks originally targeting the financial services industry are now increasingly directed at other critical sectors of the economy
HELP NET SECURITY
Hidden Security Threats On Enterprise Networks
Check Point uncovers security risks and threats in new report
CNET
Malware Getting Smarter, Says McAfee
Savvier cyberattacks are being directed toward more critical segments of the U.S. economy, security provider says
XINHUA
China Refutes Accusations Of Launching Cyberattacks On U.S.
Chinese government denies allegations that it is behind cyberattacks against U.S. websites
USA TODAY
Thieves, Spies Move To AVTs: Advanced Volatile Threats
Attacks in RAM are advanced, but not always persistent
LAW.COM
Employees May Be A Company's Greatest Cybersecurity Vulnerability
Apple, Facebook, and New York Times hacks have one thing in common: employee failure
FORBES
Developer Site That Was Used To Hack Facebook And Apple Issues Mea Culpa
Both hacks started with the hacking of another site: iPhoneDevSDK.com
KREBS ON SECURITY
Bit9 Breach Began In July 2012
Cyberespionage hackers who broke into security firm Bit9 used custom malware also used last year in highly targeted attacks against U.S. defense contractors
HOMELAND SECURITY NEWSWIRE
U.S. Weighing Retaliatory Measures Against China For Hacking Campaign
The administration has intensified discussions of retaliatory measures the U.S. may take against China
THREAT POST
iOS Developer Site At Core Of Facebook, Apple Watering Hole Attack
The missing link connecting the attacks against Apple, Facebook, and possibly Twitter is a popular iOS mobile developers' forum called iphonedevsdk, which was discovered hosting malware in an apparent watering hole attack
WIRED
Top U.S. Stealth Jet Has To Talk to Allied Planes Over Unsecured Radio
U.S. F-22 fighters and Britain's Typhoon jets have come together for intensive, long-term training in high-tech warfare, but cannot communicate securely due to incompatible systems
HBGARY BLOG
Be Alert, Be Watchful, Be Vigilant
ManTech's Security Operations Center Chief gives tips on how to protect employees from inevitable spearphishing attacks
THREAT POST
Firefox 19 Fixes HTTPS Phishing Issue, Adds Built-In PDF Viewer
The new version of Firefox released today includes fixes for a number of serious security vulnerabilities, as well as a new, built-in PDF viewer
THE HUFFINGTON POST
Hackers Who Attacked Twitter, Facebook, Apple May Have 'Hundreds' More Victims
F-Secure estimates that "hundreds" of app developers at tech startups have been compromised but haven't come forward publicly because their employers can't afford the negative publicity
TECHWORLD
Oxford University Blocks Google Docs As Phishing Attacks Soar
Oxford University is temporarily blocking access to Google Docs after a dramatic increase in phishing attacks trying to harvest academic email credentials using bogus forms hosted on the service
LOS ANGELES TIMES
MTV, BET Pull Hack Stunt In Apparent Bid To Gain Twitter Followers
Sister networks pretended hackers took over their accounts
SYDNEY MORNING HERALD
Unit 61398 -- The Featureless 12-Story Building Which Houses One Of The World's Most Dangerous And Secretive Cyber-Hacking Operations
Nondescript tower identified as nerve center of one of the world’s most dangerous military cyberhacking operations
INFOWORLD
13 Security Myths Debunked
Security pros warn about believing everything you hear about malware, zero-day attacks, compliance, and more
TECHWORLD
Oxford University Blocks Google Docs As Phishing Attacks Soar
University temporarily blocks access to Google Docs as phishers try to harvest academic email credentials
RT
Anonymous Hacked U.S. State Dept., Investment Firm In Homage To Aaron Swartz, Lulzsec
Hacktivist group says it gained access to State Dept. website, captured a database, and published it online
HELP NET SECURITY
The Sophistication Of Risky Apps, Mobile Misbehavior And Spyware
New McAfee report documents sophisticated and complex apps containing multifaceted scams
KREBS ON SECURITY
DDoS Attack On Bank Hid $900,000 Cyberheist
Christmas Eve cyberattack on website distracts bank officials from account takeover
YAHOO NEWS
U.S. Ready To Strike Back On China Cyberattacks
Obama administration ready to spell out trade actions if may take against countries guilty of cyberespionage
TECHWORLD
Targeted APT Attacks Experienced By One In Five Security Professionals
Advanced Persistent Threats (APTs) could be more of a mainstream security problem than previously thought, according to an ISACA survey that found that one in five had suffered such an attack
COMPUTERWORLD
Microsoft Warns Of Looming Retirement For Windows 7 RTM
Customers must upgrade to SP1 to continue to receive security patches after April 9
IFSEC GLOBAL
We're Under Attack By Cybercriminals
Tips from a security site that got DDoS'ed recently, including setting auto-alerts for server downtime, knowing who to contact at your ISP, and backing up your site
THREAT POST
Could Smart-Watches Replace Passwords As Authenticators?
The man who designed Apple’s first human interface published a blog about a possible smart swatch that could be used for authentication
SECURITY LEDGER
Uncle Sam Needs A Plan: GAO Pans Govt. Cybersecurity Efforts In 100 Page Report
A new General Accounting Office report concludes that while the federal government has made progress in securing its systems, it hasn't done much to improve in cyberincident response
COMPUTERWORLD
Lawmakers, Business Execs Defend Privacy In CISPA
Critics say the cyberthreat information-sharing bill still has privacy problems
NAKED SECURITY BLOG
More Mac Malware Attacking Minority Groups In China
New Trojans for the Mac bypass the Mac's admin prompt to stay alive in Macs
SOFTPEDIA
Former FBI Agents, US Senator, UN Official Also Victims Of Bush Family Hacker
More victims of the Bush family email hack include a U.S. Senator, former FBI agents, and a U.N. official
THREAT POST
Flaws In Emergency Alert System Hardware Allow Remote Login, Zombie Alert Insertion
EAS appliances contain a set of easily exploited vulnerabilities, researchers say
FIERCE GOVERNMENT IT
DHS And NIST Sign Cybersecurity Agreement
Major government groups say they'll work together more closely on cybersecurity issues
THE HACKER NEWS
Zeus Banking Trojan Targeting Five Major Banks In Japan
Malware moves from U.S. and Europe to Japan
THE VERGE
iPhone Lockscreen Can Be Bypassed With New iOS 6.1 Trick
Using flaw, attackers can bypass iPhone password lock and access your phone app
REUTERS
Europol Breaks Up Multi-Million Euro Internet Fraud Gang
Network of online fraudsters masquerades as law enforcement agency, collects millions of euros in fake fines
SOFTPEDIA
U.S. Department Of Defense To Award Medal For Cyber Warfare Achievements
Service members will receive recognition even far away from the field of battle, DoD says
ARS TECHNICA
A World Of Hurt After McAfee Mistakenly Revokes Key For Signing Mac Apps
Just allow untrusted certificates, one customer is told
BLOOMBERG BUSINESSWEEK
A Chinese Hacker's Identity Unmasked
Dell Secureworks researcher Joe Stewart offers a look at how he tracked down a malware purveyor
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3562
Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-3561
Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.
CVE-2013-3560
The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-3559
epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (integer overflow, and heap memory corruption or NULL pointer dereference, and application crash) via a malformed packet.
CVE-2013-3558
The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not terminate a bit-field list, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.


