Best Of Web
Best Of The Web
THE INQUIRER
Microsoft Admits That Windows Phone 7 Collects Location Data
Microsoft collects data such as the MAC address of the device, the signal strength, the radio type, and latitude, longitude, direction, and speed
NEW YORK TIMES BLOG
Holding Companies Accountable For Privacy Breaches
There seems to be no real repercussions for companies who suffer breaches that expose their customers' personal information
SYMANTEC BLOG
Cyber Crooks All SeTo Crash The British Royal Wedding
The British Royal Wedding is being used in spam campaigns and to push rogue antivirus software through black hat search engine optimization techniques
INFOSECURITY
VISA: Payment Card Industry Needs To Work Smarter, Not Harder , To Increase Security
Visa's chief enterprise risk officer commended the industry's efforts to reduce electronic payment fraud, but says "smarter" technologies and risk assessments are needed to keep up with cybercrime
SC MAGAZINE
Infosecurity Europe: Rogue Wireless Network Snares More Than 300 Visitors In Four Hours
More than 300 users joined a rogue wireless network at the Infosecurity Europe exhibition in a live experiment by CryptoCard
DEADSPIN
Yankees Accidentally Leak Personal Info Of 20,000 Season Ticket Holders
The New York Yankees accidentally sent a spreadsheet file containing information on more than 20,000 season ticket accounts--including account numbers, names, addresses, phone numbers, and email addresses--to thousands of current clients
CLOUD SECURITY BLOG
GoGrid Security Breach
An unauthorized third party may have viewed user account information, including payment card data, for GoGrid
COMPUTERWORLD
Feds To Remotely Uninstall Coreflood Bot From Some PCs
Over the next four weeks, federal authorities will remotely uninstall the Coreflood botnet Trojan from some infected Windows PCs
SUCURI NET BLOG
WordPress 3.1.2 Released, With Security Fixes
New version of version of WordPress fixes flaw where contributor-level users were allowed to publish posts
KREBS ON SECURITY
SpyEye Targets Opera, Google Chrome Users
Latest version of the SpyEye Trojan includes features designed to steal sensitive data from Windows users running Chrome and Opera Web browsers
THE REGISTER
Love Bug Malware-Inspired Film Gets Big Screen Premiere
A film inspired by the infamous Love Bug worm premieres this week, telling the story of the I love you/LoveLetter virus that spread in May 2000: an "action-packed romantic drama is based on the destructive 'I Love You' computer virus"
THREAT POST
Glass Dragon: China's Cyber Offense Obscures Woeful Defense
Security researcher says Chinese government unprepared to fend of cyberattacks on its own infrastructure, based on research he has conducted
PC MAGAZINE
Most Mobile Apps Lack Privacy Policies: Study
A study by TRUSTe and Harris Interactive found just 19 percent of the top 340 free applications contain a link to a privacy policy
EWEEK
Oak Ridge Still Not Back Online
Ten days after the Oak Ridge National Laboratory�s IT department shut down Internet access after a successful spear phishing attack, the laboratory remains disconnected
COMPUTERWORLD
Security Experts Can't Verify Iran's Claims Of New Worm
No proof of another Stuxnet without a sample of the malware, Symantec says
CONTAGIO
Targeted Email Senders By Country/Source
Study shows China is source of more spear phishing attacks than any other country
ABC SAN FRANCISCO
Janet Napolitano Visits UC Berkeley, Talks Cybersecurity
Speech is part security update, part recruiting session
CLICKZ
Email Marketers Urged To Shore Up Security
Online Trust Alliance says more should be done to protect customer data
YONHAP NEWS AGENCY
Prosecutors Probe N. Korea's Alleged Role Behind Cyberattack On Nonghyup
Authorities suspect North Korean involvement in disruption of South Korean farm cooperative�s banking system
SC MAGAZINE
What If It Wasn't About The Phish?
Epsilon breach may have been more useful as a means of correlating customer data for marketing, expert says
TECHNOLOGIZER
Sony Disables PlayStation Network After Security Breach
Gamers going through withdrawal as company undertakes forensic investigation of external hack
TEAM SHATTER
Is Oracle Misleading Its Database Customers With CPUs?
Researchers suggest that Critical Patch Updates may underrate the severity of some threats
MEHR NEWS
Iran Target Of New Cyberattack
Iranian government says country is focus of new computer worm called Stars
CYBER ARMS
Chinese Hackers Spear Phishing For U.S. Military Secrets
Attacks traced back to military sources
ABC NEWS
Cybersecurity System Mimics Human Immune Response
DHS white paper envisions healthy ecosystem of computers that would work together to fight threats
THREAT POST
The Banker Trojan Epidemic
A look at the trend and what can be done to mitigate it
SC MAGAZINE
Hacker Pleads After Being Busted With 675,000 Stolen Cards
Much of the card data was obtained by hacking business networks, authorities say
STATESMAN
Comptroller Data Lapse Racks Up More Than $1.8 Million In Costs
Texas breach already is costing the state dearly, report says
BANK INFO SECURITY
Phishing: Email Needs Authentication
Expert says targeted attacks are becoming more widespread
GUARDIAN
Guantanamo Leaks Lift Lid On World�s Most Controversial Prison
More than 750 files are leaked to news media
PC MAGAZINE
$36M Stolen Credit Card Hacker Pleads Guilty
Rogelio Hackett, Jr. pleaded guilty to charges related to a nine-year-long computer hacking operation that generated millions in fraudulent credit card charges�he was found to have more than 675,000 stolen credit card numbers
ALL SPAMMED UP
Mega-D Mastermind Facing Nearly 20 Years In Prison
The Russian spammer who allegedly is the mastermind behind the massive Mega-D botnet is facing 17 years in prison and a $250,000 fine
NEWSFACTOR
EC2 Outage Takes Out Multiple Sites, Including Foursquare
Foursquare and other websites were knocked off due to problems at Amazon's Elastic Compute Cloud data center--the outage is likely to add to the debate about reliability and security of cloud-based computing
TECHEYE
U.S. Army Picks Android
Mitre is developing a prototype device based on Android called the Joint Battle Command-Platform to help reduce the amount of heavy gear soldiers must carry around
THREAT POST
Adobe Releases Patch for Flash Zero Day Hole in Reader, Acrobat
Adobe issued patches for its Reader and Acrobat products to plug a hole in the Flash Player that was first reported in March and is being used in attacks
THE NEW YORK TIMES
Researchers Prove They Can Hack Into Cars' Electronics
UC San Diego and University of Washington researchers say hackers can easily gain remote access to and take over the vehicle's basic functions, including control of its engine
COMPUTERWORLD
Epsilon Pledges To Build 'Fort Knox' Around Breached System
The CEO of Epsilon�s parent company said the firm will build an industry-leading security system in response to a March 30 breach that spilled e-mail addresses and names of customers
MILITARY.COM
Report: U.S. Nuke Lab Needs More Cyber Controls
Lawrence Livermore National Laboratory failed to set up adequate cyber security controls for classified information, including details about the nation's nuclear stockpile, according to a federal report
ALEX LEVINSON BLOG
3 Major Issues with the Latest iPhone Tracking �Discovery�
Apple is not harvesting this data, the hidden file is not new or secret, and this �discovery� was published months ago
DATABREACHES.NET
IEEE Members Notified Of Second Breach In As Many Months
In the wake of a breach of more than 800 members� names and credit card numbers, IEEE members with Term Life insurance underwritten by New York Life Insurance have been told that a mailing error exposed other members� names and numbers
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
- HP Newsletter with Gartner Research: Maximizing Your Infrastructure through Virtualization
- Understanding Holistic Database Security 8 Steps to Successfully Securing Enterprise Data Sources
- A How-To Guide on Using Cloud Services for Security-Rich Data Backup
- Holistic Risk Management: Perspectives from IT Professionals
- Aligning IT with strategic business goals: A proactive approach to managing IT risk to your business
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2012-4697
TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to obtain administrative access via an FTP session.
CVE-2011-4520
Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
CVE-2011-4519
Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
CVE-2011-4518
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2012-6563
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.


