Best Of Web
Best Of The Web
TREND MICRO BLOG
Targeted Attacks on Popular Webmail Services Signal Future Attacks
Trend Micro looks at parallels between recent Gmail attack and attacks over the past few months on Hotmail and Yahoo Mail
LIFEHACKER
Faceniff Is The Firesheep For Android, Hijacks Facebook Sessions With One Tap
New Android app lets smartphone users hijack Facebook accounts of users on an open WiFi network -- it works like Firesheep
SPAMFIGHTER
Phony VirusTotal Website Pushes Malicious Software: Kaspersky
Kaspersky Lab researchers say a legitimate-looking but phony VirusTotal website is spreading malware
THE TELEGRAPH
MI6 Attacks Al-Qaeda In 'Operation Cupcake'
British intelligence hacked into an al-Qaeda online magazine and replaced bomb-making instructions with a recipe for cupcakes
FEDERAL TIMES
FBI Reviewing Hacking Of Google Accounts
The FBI is investigating the attack on Gmail that targeted hundreds of Google email accounts, including those belonging to senior government officials and military personnel
INFORMATION WEEK
Google Sued For SMS Spamming
Google and its recent acquisition Slide are being sued for allegedly spamming users with SMS messages, while in a separate lawsuit Twilio and GroupMe are facing similar allegations
TECHNOLOGY REVIEW
Breached Companies Say They Did All They Could
Executives from Sony and Epsilon told a U.S. congressional committee that a uniform federal law governing disclosure would improve breach response times, and they also also defended their current security and response times
THREAT POST
TDSS Rootkit Gets Its Own Self-Replicating Loader
The TDSS rootkit now has a worm-like, self-propagating loader that can install new copies of the rootkit on PCs, set up its own DHCP server on a network ,and force machines to connect to a malicious DNS server
SECURITY WEEK
Building A Bridge For Information Sharing: An Industry Perspective
A look at how law enforcement and other entities can share information about cybercrime
SECURITY WEEK
Are Regulations Falling Behind On Web Security?
Compliance isn't what it used to be, expert says
REUTERS
Cybersecurity Becoming U.S. Diplomatic Priority
Washington looks to build relationships to tackle information theft
HOST EXPLOIT
Internet Fraud Surge Hits Russians
Internet fraud has nearly doubled since the beginning of the year, Russian officials say
WASHINGTON POST
List Of Cyberweapons Developed By Pentagon To Streamline Computer Warfare
Scope of attacks defined as global, regional, or local
TELEGRAPH
The Cyberwarriors Are Preparing For Battle
A new form of war is looming, expert says
FINANCIAL TIMES
Summit Has Few Answers On Hacking Crisis
Top officials from major countries exchange statistics, but no real proposals
CSO ONLINE
Microsoft Prepares To Out Rustock Operators
PBS site defaced; passwords and other sensitive information stolen
CNET
One Out Of Eight People Now Use Chrome
New data shows that one out of eight people on the Internet use Chrome now, an increase from 11.9 percent in April to 12.5 percent in May
US-CERT
Imperva SecureSphere Management GUI Contains An XSS Vulnerability
A vulnerability has been discovered in the Imperva SecureSphere management graphical user interface, which could allow persistent cross-site scripting attacks
THE REGISTER
Unpatched IE Bug Exposes Sensitive Facebook Creds
New attack remotely steals digital credentials used to access user accounts on Facebook and other websites by exploiting a flaw in Microsoft's Internet Explorer browser
THE WASHINGTON POST
Federal Government Loosens Its Grip On The Blackberry
Vivek Kundra says federal workers should be allowed to use whatever mobile device they want -- with strict security settings
CNET
Pew Study Finds More People Using Twitter
Pew Internet found that 13 percent of adults online use Twitter -- up from 8 percent in November
REUTERS
North Korea Hacker Threat Grows As Cyber Unit Grows: Defector
North Korea is recruiting computer-savvy students at universities to send overseas for training as part of a plan to expand its cyber warfare unit, a defector says
HUFFINGTON POST
Facebook Malware Attack: Fake Strauss-Kahn Video Infects Mac And PC Users
New attack infects both Mac and PC users with malware, using the lure of a video about IMF boss Dominique Strauss-Kahn
THE HILL
White House Defends Cybersecurity Plan
New White House legislation criticized by U.S. Chamber of Commerce, but Obama administration says the proposal strengthens security, preserves privacy and civil liberties protections, and fosters continued economic growth
GOVERNMENT INFO SECURITY
Public Health Serves As Cybersecurity Model
Governments could take the same approach to IT security as they do to secondhand smoke, Microsoft's Charney says
CNET
Sony: PlayStation Store Back This Week
Following massive hack, remainder of PlayStation services to be restored by end of week
THE REGISTER
Hackers Pwn PBS In Revenge For WikiLeaks Documentary
PBS site defaced; passwords and other sensitive information stolen
WALL STREET JOURNAL
Cyber Combat: Act Of War
Pentagon officials say that some acts of computer sabotage could elicit a military response with traditional weapons
CRN
Call For Banks To Blacklist Spammers
Banks and techies could work together, experts say
WALL STREET JOURNAL
Iran Vows To Unplug Internet
Country plans to build network that operates separately, officials say
BANK INFO SECURITY
FFIEC Guidance: Focus On Awareness
Fraud awareness is most critical of five components, guidance says
IT WORLD
Bad Software Analysis Causes Release Of 450 Dangerous California Inmates
Bug in software causes some dangerous offenders to be released in effort to stop overcrowding
NETWORK WORLD
RSA Tokens May Be Behind Major Network Security Problems At Lockheed Martin
Use of company network has been disrupted, reports say
WALL STREET JOURNAL
Cybersecurity Plan Faulted
U.S. Chamber of Commerce calls plan "regulatory overreach"
MICROSOFT
SmartScreen Application Reputation In IE9
Application reputation helps protect users from social engineering attacks
ARS TECHNICA
Senior Defense Official Hedges On U.S. Involvement In Stuxnet
Deputy Defense Secretary William Lynn declines to answer questions on U.S.'s Stuxnet role
COMPUTERWORLD
Update: Honda Canada Breach Exposed Data On 280,000 Individuals
Company says ID theft unlikely because of the limited nature of the compromised data
FINEXTRA
Former Diebold Technician Charged With Stealing $200,000 From Bank Of America ATMs
Technician charged with replacing cash with counterfeit notes
GAMEPRO
Codemasters Hit By Hackers
U.K. publisher is latest gaming company to be hit with server attack
PC WORLD
New Sony Hack Nabs User Data Of 2,000 Customers
Sony Ericsson's Canadian website is target of latest hack
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



