Best Of Web
Best Of The Web
NATIONAL JOURNAL
House Leaders Want Info About Epsilon Data Breach
Lawmakers looking into mammoth leak
MICROSOFT
Microsoft To Issue 17 Security Bulletins In Big Patch Tuesday
Nine patches are considered critical, software giant says
HELP NET SECURITY
Smartphone Users Feel More Secure Than PC Users
Many smartphone users think browsing is safer on their phones than on the Web, Kaspersky study says
ABC NEWS AUSTRALIA
Hackers Steal Dell Customer Information
Customers of Dell Australia are among those affected by Epsilon breach
COMPUTERWORLD
Five Cloud Security Trends For 2011
Mobile technology leads the list, experts say
THE DROID GUY
Verizon Joins The Likes Of Best Buy And Others In Epsilon Data Breach
Service provider is the latest to acknowledge potential damage from email data compromise
NETWORK WORLD
RSA Detailing SecurID Hack To Customers Sworn To Secrecy
RSA has started providing more detail about the mid-March attack on its SecurID token-based authentication system, but to get a fuller story you have to be an RSA customer willing to sign an NDA
THE REGISTER
Google Chrome To Warn Of Malicious Windows Executables
Google will extend its blacklist of malicious websites to include those that use deceptive claims to push malicious Windows programs
CBS NEWS
Secret Service Investigates Epsilon Data Breach
CBS News has confirmed that the U.S. Secret Service is investigating the case, and the public can notify the Secret Service of phishing scams by emailing phishing-report@us.cert.gov
VERACODE ZERO DAY LABS BLOG
Mobile Apps Invading Your Privacy
As more free apps attempt to monetize their offerings, more of this information will be sent to marketing and advertising data aggregation companies
HP BLOG
The Hard Truth About Mobile Application Security -- Separating Hype From Reality
Apps are one thing, but the bigger
problem is the back-end systems that power mobile apps
CNET
Comodo Hack May Reshape Browser Security
Major browser vendors are assessing how they handle Web authentication after last month's breach that allowed a hacker to impersonate sites including Google.com, Yahoo.com, and Skype.com
BANK INFOSECURITY
Heartland Breach: Legal Update
A U.S. District Court in Texas has dismissed civil suits against Heartland Bank and KeyBank for their involvement in the 2009 Heartland Payments Systems breach
THE COURANT
Hospital Records Breach Involves 93,500 Patients
MidState Medical Center Offering says an employee used a personal hard drive to take home patient data and was later dismissed -- the drive has not yet been located
CNET
Surge In Malware Marks Start Of Year
First quarter shows new wave of malicious code, as well as many attacks, Panda says
SOPHOS
Fired Gucci Employee Charged With Hacking Into Network
Former network engineer charged with breaking into network, shutting down servers and deleting data
COMPUTERWORLD
Frank Hayes: It�s Not Funny When Security Becomes A Joke
New sitcom spoofs penetration testers, but is IT security the one with pie on its face?
SECURITYWEEK
Insider Attacks: Identify The Anomaly
A third of security professionals say insider attacks are more expensive than external attacks
OFFICE OF INADEQUATE SECURITY
And The Hits Just Keep Coming For Epsilon--50 Companies And Counting
More companies say they are affected by breach
NETCRAFT
Compromised GlobalTrust Database Is Published Online
Disclosure may be related to recent Comodo hack
MINNEAPOLIS BUSINESS JOURNAL
From The Grave, Ulysses Telemedia Lets Secrets Slip
Defunct company left personal data in file cabinets
THE REGISTER
Anonymous Hacks Global PS3 Sites
PlayStation sites rendered unavailable by DDoS attack
THE REGISTER
Pandora Subpoenaed Over Privacy Of IPhone, Android Apps
Online radio provider Pandora has been subpoenaed by a federal grand jury to provide documents related to the privacy of smartphone apps it offers for Apple's iPhone and Google's Android operating system.
THREAT POST
Children, The New Hot Commodity In The Business Of Identity Theft?
Carnegie Mellon University�s Cylab found that as many as 10 percent of kids were victims of identity theft before they are old enough to own a credit card or buy a drink
WIRED
Army: Manning Snuck 'Data-Mining' Software Onto Secret Network
Bradley Manning installed and used unauthorized ?data-mining software? on his SIPRnet workstation during the period he allegedly siphoned hundreds of thousands of documents off that classified network, the Army said
M86 SECURITY LABS BLOG
Facebook Scam Spreading: 'Hey, I Just Made A Photoshop Of You, Check It Out?'
A new scam spreading via Facebook Chat messages begins spamming your Facebook friends/family members with the same message
H ONLINE
Proposals For The Future of Certificates
Certificate authority Comodo at the Internet Engineering Task Force (IETF) in Prague presented a mechanism for limiting the unauathorized issuing of certificates
THE EXAMINER
Anonymous Attacks Sony: Operation PayBack Continues
Anonymous has gone after Sony due to legal actions taken by the media firm against George �Geohot� Hotz, who was able to jailbreak the Sony PlayStation 3
NAKED SECURITY BLOG
Millions Of Facebook Users Invited To Scam Events, As Spammers Exploit Social Network
Bogus Facebook events are the newest way for scammers to generate income from online survey scams
TREND MICRO BLOG
ZeuS Source Code Already in the Wild
While the Zeus Trojan source code is available in the wild but via a password-protected .RAR file, Trend Micro expects that file soon to be cracked and the malware to get into the hands of the wrong people
WEBSENSE BLOGS
Update On Lizamoon Mass-Injection And Q&A
The LizaMoon mass-injection campaign is still ongoing, and more than 500,000 URLs have a script link to lizamoon.com, according to Google Search results, and pushes rogue AV software
EWEEK
IEEE Reports Breach Of 800 Engineers' Credit Card Data
Some 800 members of the IEEE had their credit card numbers stolen from a database storing conference registration information
COMPUTERWORLD
What A Cyberwar With China Might Look Like
New U.S. Air Force report describes a detailed scenario of how cyberwar could unfold, and how it will be an "always-on engagement"
M86 LABS BLOG
Your Music Order--A Loaded PDF
New spam campaign poses as a music or cell phone "Order" with an attached and infected PDF file
WIRED
NSA To Investigate NASDAQ Hack
The National Security Agency is helping investigate recent hack attacks against the company that runs the NASDAQ stock market, according to Bloomberg News
THE REGISTER
Stock-Trading Teen Hacker Jailed Again Over 2nd Scam
A man who was jailed in 2003 at age 19 for a stock-trading hack has been sent to jail again for a different crime, this time trying to swindle money from a currency exchange
THREAT POST
Security Stories We Wish Had Been April Fool's Jokes
Hackable pacemakers, hackable cars, Stuxnet, Comodo, and hackable ATMs all made the A-list of real attacks
COMPUTERWORLD
Cybercrime Second Biggest Risk To Airlines
Information sharing could help draw attention to attacks, says local expert
HELP NET SECURITY
Half Of U.S. Taxpayers Are Unaware About Identity Theft Risks
Tax-related identity theft is still unknown to many consumers, PrivacyGuard says
NATIONAL DEFENSE MAGAZINE
FBI To Conduct Joint Cyber Investigations With China
Agency will work cooperatively with Chinese authorities to investigate alleged attacks by Chinese hackers
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 104 | 105 | 106 | 107 | 108 | 109 | 110 | 111 | 112 | 113 | 114 | 115 | 116 | 117 | 118 | 119 | 120 | 121 | 122 | 123 | 124 | 125 | 126 | 127 | 128 | 129 | 130 | 131 | 132 | 133 | 134 | 135 | 136 | 137 | 138 | 139 | 140 | 141 | 142 | 143 | 144 | 145 | 146 | 147 | 148 | 149 | 150 | 151 | 152 | 153 | 154 | 155 | 156 | 157 | 158 | 159 | 160 | 161 | 162 | 163 | 164 | 165 | 166 | 167 | 168 | 169 | 170 | 171 | 172 | 173 | 174 | 175 | 176 | 177 | 178 | 179 | 180 | 181 | 182 | 183 | 184 | 185 | 186 | 187 | 188 | 189 | 190 | 191 | 192 | 193 | 194 | 195 | 196 | 197 | 198 | 199 | 200 | 201 | 202 | 203 | 204 | 205 | 206 | 207 | 208 | 209 | 210 | 211 | 212 | 213 | 214 | 215 | 216
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



