Quick Hits
-
Pakistan Hit By Targeted Attack Out Of India
May 17, 2013Information-stealing malware campaign spreads via phishing email attachments posing as Indian military secrets
-
Study: Application Vulnerabilities Are No. 1 Threat
May 16, 2013Shortage of training among developers is a key cause of high vulnerability rates, (ISC)2 survey says
-
Internet Crime Cost Consumers More Than A Half-Billion Dollars Last Year
May 15, 2013Number of cases reported by consumers to FBI-partnered Internet Crime Complaint Center increased by nearly 10 percent last year, with scams in auto fraud, FBI impersonation via email, extortion at the top of the list
-
SAFECode Launches Software Security Training Program For Enterprises
May 14, 2013Free curriculum will help businesses build software security training programs in-house, SAFECode says
-
Ten Emerging Threats Your Company May Not Know About
May 13, 2013Some new attacks get a lot of attention. Here's a look at 10 that haven't, but ought to be on your radar
-
Microsoft Issues Emergency Fix For IE Zero-Day
May 09, 2013'Fix it' now available as a temporary defense until actual patch is ready; only IE 8 is affected by flaw
-
Advanced Persistent Threats: The New Reality
May 09, 2013Once rare and sophisticated, the APT is now becoming a common attack. Is your organization ready?
-
Convenience Store Chain Hacked, Customer Payment Data At Risk
May 07, 2013MAPCO Express says the FBI is investigating a breach that exposed customer financial data in its stores
-
Anonymous, LulzSec, OpUSA Plan Broad Attacks On Government Agencies, Banks On Tuesday
May 07, 2013Hacktivist groups plan denial-of-service attacks on banks, government sites
-
Threat Nuevo: Latin America, Caribbean Cybercrime On The Rise
May 03, 2013Cybercriminals in the region have built their own tools and learned from their predecessors in other regions, says Trend Micro report in cooperation with Organization of American States (OAS)
-
Reputation.com Suffers Breach, Changes Customer Passwords
May 02, 2013Some customer information exposed, including salted and hashed passwords from 'a minority' of customers
-
Consumer Reports: 58 Million U.S. PCs Infected With Malware
May 02, 2013Malware cost consumers nearly $4 billion in repairs in 2012, Consumer Reports says
-
Password Reuse Rampant, But Users Value Security, Survey Says
April 30, 2013More people adopt some online—and mobile—security, but still fail in proper follow-through, according to a new study by Varonis
-
LivingSocial Says Cyberattack Puts Data Of 50 Million Customers At Risk
April 29, 2013Shopping and deals site LivingSocial says all customers should change passwords; source of hack undisclosed
-
Managing Mobile Security In Small And Midsize Businesses
April 29, 2013Wireless devices are a boon to SMB productivity -- and a nightmare for security. Here are some tips for securing them
-
Phishers Hack Hosting Providers To Launch Mass Attacks
April 25, 2013Nearly half of all phishing attacks in the second half of last year came via hacked hosting providers, according to new data from the Anti-Phishing Working Group (APWG)
-
How Cybercriminals Attack The Cloud
April 25, 2013What attacks are most likely against cloud computing environments? Here's a look -- and some advice
-
Many Hacked Businesses Remain Unprepared For The Next Breach
April 24, 2013New Ponemon report finds three-fourths of hacked organizations either have had or expect to have a breach that loses them customers and business partners
-
Report: DDoS Attacks Getting Bigger, Faster Than Ever
April 22, 2013DDoS attacks of more than 10 Gbps now happen several times a day across the globe, study says
-
Botnets Come Out Of Hiding For Boston Bombing Spam
April 19, 2013Kelihos, Cutwail botnets jump into action to deliver spam emails disguised as news from bombings
-
Consumers Want Biometrics, Survey Finds
April 18, 2013New Ponemon Institute study shows disillusionment and problems with passwords in online transactions
-
'Magic' Malware Uses Custom Protocol And A 'Magic Code' Handshake
April 17, 2013Researchers spot a nearly year-long attack campaign that employs some special tricks
-
Web Hosting Provider Breached Via Adobe ColdFusion Vulnerabilities
April 16, 2013Linode says attackers accessed one of its Web servers, some source code, and database
-
Mobile Malware Up 163 Percent In 2012, Study Says
April 15, 2013App repackaging, malicious mobile URLs and "smishing" are top delivery techniques for malicious mobile code
-
Open Group Publishes Security Standard For Technology Supply Chain
April 15, 2013New O-TTPS standard is designed to improve security of commercial off-the-shelf IT products
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- How Hackers Fool Your Employees: People are your most vulnerable endpoint. Make sure your security strategy addresses that fact.
- Not All Or Nothing: Effective security doesn't mean stopping all attackers.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3342 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.
CVE-2013-3341 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3340.
CVE-2013-3340 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, and CVE-2013-3341.
CVE-2013-3339 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3340, and CVE-2013-3341.
CVE-2013-3338 (acrobat_reader)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.



