Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10


Around The Web

NETWORK WORLD
Inspector General Criticizes Cybersecurity Efforts
US-CERT doesn't have authority to make federal agencies comply with its recommendations and is nor properly prepared and staffed to protect U.S. infrastructure from attack, IG says

THE DAILY PRESS
Virginia Beach Reports School Database Compromised
Officials at Ocean Lakes High School said a high school student was able to access names, addresses and Social Security number of students at 22 schools

REUTERS
Q+A with Oracle CEO Larry Ellison
Ellison says his long-term goal for Oracle is to focus on IBM as a competitor -- he wants to next beat Big Blue in high-end servers

FREE REPUBLIC
Was Gary Mckinnon The Victim Of A Russian Hacking Plot?
One rumor circulating security and law enforcement agencies is thatRussian intelligence was running a covert program to lure young people with Aspergers syndrome into hacking U.S. government systems

NEW YORK TIMES BLOG
How to Quickly Find Out if Your Identity Is Stolen
A free way to determine whether you've been victimized by identity fraud is to check the www.MyIDScore.com site

INFORMATIONWEEK
NoSQL Alternative
A new genera ion of low-cost, high-performance database software is rapidly emerging to challenge SQL's dominance in distributed processing and data apps

ZDNET
Hacker 'Deletion Frenzy' Almost Foils AFP
Australian Federal Police (AFP) operation to rescue a hacked database of 60,000 domain names' usernames and passwords and 13,000 credit card numbers was nearly derailed when the hackers were tipped off and started deleting evidence

ZDNET
Bank Settles Wire Transfer Security Suit Against Customer
PlainsCapital Bank has settled a lawsuit it bought against one of its own business customers after cybercriminals stole over $800,000 from the company's account.

NETWORK WORLD
Our Growing Security Quagmire
Proliferation of connected computing devices such as iPhone, Droid, iPad; evolution of the smart grid; and automotive computing now make technology a threat to not just our money, but our daily lives

UPI
Obama Urged To Fast-Track Cybersecurity Policy
The Obama administration is under increasing pressure to fast-track cybersecurity policies announced a year ago as threats intensify

SQL MAGAZINE
A New Law Could Change the Way You Build Database Applications
Massachusetts?? new data security law that will have a profound on the way organizations develop data-centric applications

BUSINESS WEEK
Judge Denies Bail For Ex-Trader Accused Of Code Theft
A federal judge in New York has denied bail to a former trader at Societe Generale who was arrested earlier this week for allegedly stealing proprietary computer code used in a high-speed trading system

NBC 29
VA Beach Workers Fired For Improper Data Access
At least eight Virginia Beach, Virginia, city employees have been fired or disciplined in the past year for improperly accessing confidential data about former employees, family members, and clients

CXO TODAY
Data Security: The Threat From Within
A typically overlooked security threat is data at rest, as well as not knowing the multiple locations data is stored within an organization

CBS NEWS
Mexico Tries to Tackle "Virtual Kidnapping"
Mandatory cell phone database to thwart extortionists is under fire ?? it requires that all Mexicans register their cell phones with a database

HOST EXPLOIT
FBI Struggles to Pull Criminal Data from Digital Devices
FBI forensic examiner says it??s difficult for law enforcement agencies to access forensic data from smartphones and game consoles

IOL SOUTH AFRICA
Data Headache For Home Affairs
The Department of Home Affairs is investigating whether private security companies are violating national security for profit by demanding ID numbers and fingerprints for access to exclusive residential estates

H ONLINE
Symantec: 1,100 NHS Infected Desktops
Over 1,000 desktops in the UK National Health Service are infected with the emerging Qakbot botnet

COMPUTERWORLD UK
Zurich Promises Encryption Following Massive Data Loss
Insurance giant exposed personal data of more than 641,000 customers when unencrypted backup tape was lost

HOSTEXPLOIT NEWS
Data Breach Impacts Fifth Third Cardholders
Some Fifth Third Bank customers are getting new debit cards after a data breach at a third party payments firm that may have compromised their account numbers


Best Of Web Archive:
Most Recent | 1| 2| 3| 4| 5| 6| 7| 8| 9| 10








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)