Best Of Web
Best Of The Web
TRUSTEER
Mobile Malware: Why Fraudsters Are Two Steps Ahead
Google Android is fraudster�s heaven, researchers sayGoogle Android is fraudster�s heaven, researchers say
MICROSOFT
Microsoft Releases New Threat Data On Rustock
After taking down the spam-carrying botnet, Microsoft offers insight on the infection
NEXTGOV
Former CIA Director: Build A New Internet To Improve Cybersecurity
Hayden advocates construction of a separate, "secure" Internet for critical services
THE STATE
Cybersecurity Experts In Great Demand
Rash of hacks drives need for more staff, services
THREAT POST
UCLA Health Services Pays $865K, Settles HIPAA Violations
Medical institution pays penalty for employees who attempted unauthorized access of celebrity health records
MSNBC
Warning: Traffic Ticket Email Is A Hoax
If you get a speeding ticket via email, don't open it, experts warn
SOFTPEDIA
Zbot Targets Android Users
Malware steals mobile transaction authentication numbers
SECUROSIS
Smart Card Laggards
The U.S. is behind many other countries in deploying smart card technology, but does it really matter?
FORBES
For The Moment, Visa And MasterCard Reopen Payments To WikiLeaks
After stopping donation payments to the controversial group, credit card companies open up again
ESECURITY PLANET
AntiSec Hacker Launches Random Cyber Attacks
'p0keu,' who claims to be connected to the AntiSec movement, has published sensitive data from a seemingly random collection of sites
THE NEW YORK TIMES
Hackers Select A New Target: Other Hackers
A-Team hacking contingent assembled names, aliases, addresses, phone numbers, even details about family members and girlfriends of LulzSec members in order to assist law enforcement
SC MAGAZINE
Colorado Agency Loses Medical Aid Applicants' Data
A disk containing the personal information of 3,590 medical aid applications has gone missing from the Colorado Department of Health Care Policy and Financing
ANONYMOUS
Anonymous Claims Hack Of IRC Federal
Hacktivist group appears to have dumped private emails, databases, and other sensitive information of federal contractor
THREAT POST
FBI: Employee Passed Chicago Mercantile Exchange Secrets To China
An employee of CME Group allegedly stole trade secrets and proprietary source code used to run trading systems for the Chicago Mercantile Exchange, according to a court case, and corresponded via email with an official in China discussing proprietary CME data
CNN
NY Troopers Warn Of E-Mail Hoax Ticket And Computer Virus
E-mail circulating nationally contains an attachment purporting to be a traffic ticket by New York State troopers, but it's malware
INFOSEC ISLAND
Turkish Takedown Thursday: New Anonymous Attack
Anonymous hackers defaced 74 Turkish websites on behalf of AntiSec in "Turkish Takedown Thursday"
BANK INFOSECURITY
Citi Case Exposes Insider Risks
A former Citigroup exec arrested for embezzling more than $19 million from Citi and its customers was a classic case of insider fraud, but it went on for an unusually long time
YOUTUBE
Cambodia Government CERT Website Compromised To Serve Malware
Video shows how site is being used to deliver malicious code
FEDERAL COMPUTER WEEK
DoD Proposes New Cybersecurity Requirements For Contractors
Contractors would have to protect even unclassified data and report breaches
SC MAGAZINE
Hackers Steal 17,000 Accounts, Including U.S. Military
Group opens recruitment drive hacking contest
COMPUTER WEEKLY
Anonymous Attacks Turkish Government Websites In Antisec Campaign Protest
Hacker group demonstrates against Internet filtering in Turkey
COMPUTING.CO.UK
International Cybercrime Fighters Join Forces
Business, government, and law enforcement form new alliance
INFOSEC ISLAND
What To Do When You Get A Data Breach Notification Letter
Don'�t panic, but pay attention, expert says
REUTERS
Government Facilities Targets Of Cyberattacks
Research facilities funded by U.S. government fall victim in string of attacks
NORTH CAROLINA STATE UNIVERSITY
Losing Sleep: New "GoldDream" Malware Targets Android
Malicious code collects data on text messages and phone calls
CREDIT.COM
Morgan Stanley Data Breach Hits Investors
Personal information of 34,000 investment clients of Morgan Stanley Smith Barney has been lost after two unencrypted CD-ROMs containing clients� names, addresses, account and tax identification numbers, income, and some Social Security numbers, went missing
NAKED SECURITY BLOG
Anonymous Responds After Suspected Hacktivists Arrested In Italy And Switzerland
The five people arrested by Italian authorities are not "dangerous hackers," Anonymous says of the apparent bust of the Italian branch of the hacking group
SC MAGAZINE
Cisco Cameras To Monitor China
Cisco will provide network equipment as part of a program in the Chinese city of Chongqing for CCTV cameras to crack down on crime
US-CERT
Internet System Consortium Releases BIND Patches
The Internet System Consortium released updates for BIND to address multiple vulnerabilities, including one that could allow a denial-of-service attack
MASHABLE
Secret Service Investigating Hack Of Fox News Twitter Account
U.S. Secret Service will investigate the recent hacking of the Fox News political Twitter account, which tweeted fake news of an assassination of the President
NAKED SECURITY BLOG
PayPal UK's Twitter Profile Commandeered By Angry Hacker
For nearly two hours, a hacker controlled the Twitter account of online payment broker PayPal UK
SEARCH ENGINE LAND
Google+ Profiles Will Be Public: Google To Terminate All Private Profiles After July 31st
Google says if you have a private profile and don't want it to go public, you can delete your profile--all private profiles will be deleted after July 31
THREAT POST
Google Removes .CO.CC Subdomains Over Phishing, Spam Concerns
Google has taken down sites hosted on .co.cc domains from its search results due to low-quality or spam issues
NAKED SECURITY BLOG
Free Apple iTunes Giftcard Scam Spreads On Facebook
iTunes gift card scam tricks victims into completing a survey, spreads the link to their contacts
ASSOCIATED PRESS
Britain Shocked By Hacking Into Slain Girl's Phone
Murdoch tabloid allegedly hacked into phone mail of abducted teenager and possibly damaged police investigation into her disappearance
COMPUTERWORLD
Hackers Claim Apple Online Data Was Compromised
A list of 27 usernames and encrypted passwords purportedly from a Apple website were posted online, as well as a warning from Anonymous
THE NEXT WEB
Anonymous Suspects Arrested In Italian Police Raids
Italian press are reporting that Italian police conducted 32 dawn raids, including one in the Swiss region of Ticino, and arrested three people including one minor
MIT TECHNOLOGY REVIEW
A Futures Market For Computer Security
Researchers academia, industry, and the U.S. intelligence community are building a pilot "prediction market" for predicting major security events before they occur
ZDNET
Hulu Removes Facebook Connect After Exposing User Data
Hulu integrated Facebook Connect into its service, but disabled it soon after discovering a technical issue that exposed user data
NEW SCIENTIST
Exclusive First Interview With Key LulzSec Hacker
"Sabu" says he is a man who believes in human rights, exposing corruption and that LulzSec�s hack of sony "motivated a giant to upgrade its security"
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



