Best Of Web
Best Of The Web
ISC SANS DIARY
Diginotar Looses Their Accreditation For Qualified Certificates
Dutch regulators have revoked DigiNotar���s status as an issuer of "qualified" certificates for digital signatures
AMERICAN BANKER
Financial Institutions, Customers See Drop In Cyber Crime Losses
Financial Services Information Sharing and Analysis Center testimony today before the House Financial Services Committee says losses to financial institutions and their customers due to cybercrime declined over the past 18 months
NAKED SECURITY BLOG
BitTorrent Serves Malware Directly From Website -- No Need For P2P!
A breach of www.bittorrent.com and www.utorrent.com led to the download of fake anti-virus from the sites
NOVA INFOSECPORTAL
The 4 Not So Easy Steps To Removing Malware
Among the steps: copy data to s secure device, wipe the system drive, and reinstall the OS and apps
THREAT POST
Adobe Fixes 13 Critical Flaws In Reader And Acrobat
Adobe patched a total of 13 vulnerabilities in the two applications
THE HACKER NEWS
'#Opiran': New Press Release For 23 September By Anonymous Hackers
Anonymous is promising to come to the aid of Iranian and Syrian citizens in a new movement, #opriran
MAKE USE OF.COM
How To Encrypt Your Gmail And Facebook Messages
Encipher.it bookmarklet lets you encrypt messages before you send them
THREAT POST
Microsoft Releases Five Bulletins For September Patch Tuesday
None of the fixes is rated critical, and Microsoft updated its bulletin for the DigiNotar compromise, revoking trust for more root certificates
SECUROSIS BLOG
Building An SSL Early Warning System
Build a browser feature or plug-in that serves as a sensor to detect mismatched certificates
COMPUTERWORLD
Certificate Hacker Probably Paid By Iran, Say Victimized Firms
Comodo CEO sees strong link between hacker and Iran
GIZMODO
Ten Hackers Who Made History
A look back at some game-changers in the online security arena
BANK INFO SECURITY
Why Consumers Trust Online Banking
In ABA survey, consumers say online banking "just makes life simpler"
COMPUTING.CO.UK
Mobile Malware Increases By 273 Percent
Cross-platform Trojans are the most prevalent exploit, G Data report says
INFOSEC ISLAND
INSA Releases Cyberintelligence Report
Paper aims to spark debate and begin defining concepts behind cyberintelligence
THE REGISTER
State-Sponsored Spies Collaborate With Crimeware Gang
Groups form unholy APT-botnet union
MICROSOFT SECURITY BLOG
More On DigiNotar Certificates, And September Bulletins
Microsoft offers updated certificates that are vetted by third parties
THREAT POST
Did The Sept. 11 Attacks Blind Us To A Digital Pearl Harbor?
Decade-old warnings still ring true, experts say
ARS TECHNICA
DigiNotar Fallout: Adobe To Patch Reader And Acrobat Tomorrow
Adobe is removing a DigiNotar certificate from its trusted list and issuing "critical" security patches to Reader and Acrobat tomorrow
IT WORLD
Linux.com, Linux Foundation Sites Breached
The Linux Foundation's websites are down and being reinstalled in the wake of a breach that was connected to the kernel.org hack
INFOSEC ISLAND BLOG
Stuxnet Could Be Modified To Undermine Nuclear Weapons
A security evangelist for Check Point warned a conference last week that the Stuxnet virus could be adapted to hack systems that control nuclear missile arsenals
GLOBALSIGN
Incident Response
GlobalSign says its website�s server was hacked and has always been kept "isolated" from the rest of its operations
SOURCEFIRE BLOG
Agile Security--For the Real World
Sourcefire today unveils a new holistic and dynamic security strategy that covers the network to the endpoint that it is calling "Agile Security"
PC WORLD
9/11 Anniversary Spurs Hacker Mischief
'The Script Kiddies,' an Anonymous-inspired group of hackers, hacked NBC News' Twitter account last week and posted several messages saying there had been a plane crash after a suspected hijacking
THE NEW YORK TIMES
Hacker Rattles Security Circles
The 'Comodohacker' who also hacked DigiNotar says he acted on his own and isn' worried that his work may have been used to spy on fellow Iranian citizens who are anti-government
THE REGISTER
MS Inadvertently Offers Early Peep At September Patches
Microsoft inadvertently published details on the patches it will be releasing tomorrow, but security experts say it's no big deal
MICROSOFT TECHNET BLOG
Protective Steps For Fraudulent DigiNotar Certificates
Microsoft says to remove the DigiNotar Root from the trusted root store and clear the cache, and that its Windows Update client will only install binary payloads signed by the actual Microsoft root CA certificate, which is issued and secured by Microsoft
FOX NEWS
Breach Leads To Online Data Posting
Stanford University Hospital says a privacy breach led to medical information of 20,000 emergency room patients--including names and diagnostic codes--to be posted online for nearly one year
TECHWORLD
RSA Spearphish Attack May Have Hit US Defense Organizations
The attackers who hacked RSA last March used the same attack code to try to break into several other companies, including two U.S. national security organizations
HEALTH AND HUMAN SERVICES
Annual Report To Congress: Breaches Of Unsecured Health Information
A new HHS report says from September 2009 to 2010, around 7.9 million people in the U.S. were impacted by some 30,800 health data breaches
GOOGLE ONLINE SECURITY BLOG
Gmail Account Security In Iran
Google provides tips for Gmail users in Iran on how to secure their accounts in the wake of the hack of a Dutch certificate authority
THE REGISTER
Ex-Microsoft Accountant Jailed For $1.1m Redmond Theft
A former Microsoft accountant was sentenced to two years in prison and ordered to repay more than $1 million after pleading guilty to theft and money laundering
WIRED
Researchers' Typosquatting Stole 20 GB Of E-Mail From Fortune 500
A pair of researchers set up phony domains posing as legitimate Fortune 500 domains collected up 20 gigabytes of misaddressed e-mail over six months
THE INQUIRER
FBI Anonymous Profiles Leaked
The Anonymous hacktivist group has leaked a document it claims is FBI dossiers on its leaders, including Sabu, Kayla, and Topiary
SOPHOS
Researchers Extend Firesheep To Exploit Google Search Data Leak
Proof-of-concept plugin exploits the use of unencrypted cookies by Google's Web History feature
NETWORK WORLD
Free Security Tool Detects Banking Malware
Finnish penetration testing company says its tool can detect all variants of five major families of malicious software
GOVERNMENT COMPUTER NEWS
Contractors, Mobile Users Pose Threat To Critical Infrastructure
Web-based support forums could be a breeding ground for viruses and spyware, expert says
HELP NET SECURITY
Cybercriminals Impersonating Government Agencies
Government-related scams figure prominently in GFI Software's list of top 10 threats
HOMELAND SECURITY NEWSWIRE
General Dynamics Teams Up With Virginia Tech To Bolster Cybersecurity
Defense contractor will help university with its Security and Software Engineering Research Center
EWEEK
Ten Notorious Hackers Who Went To Work For "The Man"
A look at some bad news hackers who became good news for the feds
PC WORLD
Comodo Says DigitNotar Hack Was State-Sponsored
"They will not stop attacking," executive says
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3927
Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 before 10.0.3.0.4 allows local users to obtain unintended write access to the database by leveraging read access.
CVE-2013-3647
The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL. NOTE: this vulnerability exists because of a CVE-2012-4009 regression.
CVE-2013-3646
The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site. NOTE: this vulnerability exists because of a CVE-2012-4008 regression.
CVE-2013-3644
Unspecified vulnerability in JustSystems Ichitaro 2006 through 2013; Ichitaro Pro through 2; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro Portable with oreplug; Ichitaro Viewer; and Ichitaro JUST School through 2010 allows remote attackers to execute arbitrary code via a crafted document.
CVE-2013-4616 (iphone_os)
The WifiPasswordController generateDefaultPassword method in Preferences in Apple iOS 6 and earlier relies on the UITextChecker suggestWordInLanguage method for selection of Wi-Fi hotspot WPA2 PSK passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack that leverages the insufficient number of possible passphrases.



