Quick Hits
-
Security Pros Fail In Business Lingo
May 23, 2013Survey shows communication breakdown between IT security staffers and business execs
-
Twitter Adds SMS As Second Factor Of Authentication
May 23, 2013Phone will be second means of verifying user identity, Twitter says
-
The Eight Most Common Causes Of Data Breaches
May 22, 2013Why do bad breaches happen to good companies? Here's a look at the most frequent causes
-
IDs Of 22 Million At Risk Following Breach At Yahoo Japan
May 21, 2013Yahoo Japan officials say they "can't deny the possibility" of epic data breach
-
Strategies For Improving Web Application Security
May 20, 2013Web apps are essential to your business -- and easy targets for hackers. Here are some tips for keeping them secure
-
Pakistan Hit By Targeted Attack Out Of India
May 17, 2013Information-stealing malware campaign spreads via phishing email attachments posing as Indian military secrets
-
Study: Application Vulnerabilities Are No. 1 Threat
May 16, 2013Shortage of training among developers is a key cause of high vulnerability rates, (ISC)2 survey says
-
Internet Crime Cost Consumers More Than A Half-Billion Dollars Last Year
May 15, 2013Number of cases reported by consumers to FBI-partnered Internet Crime Complaint Center increased by nearly 10 percent last year, with scams in auto fraud, FBI impersonation via email, extortion at the top of the list
-
SAFECode Launches Software Security Training Program For Enterprises
May 14, 2013Free curriculum will help businesses build software security training programs in-house, SAFECode says
-
Ten Emerging Threats Your Company May Not Know About
May 13, 2013Some new attacks get a lot of attention. Here's a look at 10 that haven't, but ought to be on your radar
-
Microsoft Issues Emergency Fix For IE Zero-Day
May 09, 2013'Fix it' now available as a temporary defense until actual patch is ready; only IE 8 is affected by flaw
-
Advanced Persistent Threats: The New Reality
May 09, 2013Once rare and sophisticated, the APT is now becoming a common attack. Is your organization ready?
-
Convenience Store Chain Hacked, Customer Payment Data At Risk
May 07, 2013MAPCO Express says the FBI is investigating a breach that exposed customer financial data in its stores
-
Anonymous, LulzSec, OpUSA Plan Broad Attacks On Government Agencies, Banks On Tuesday
May 07, 2013Hacktivist groups plan denial-of-service attacks on banks, government sites
-
Threat Nuevo: Latin America, Caribbean Cybercrime On The Rise
May 03, 2013Cybercriminals in the region have built their own tools and learned from their predecessors in other regions, says Trend Micro report in cooperation with Organization of American States (OAS)
-
Reputation.com Suffers Breach, Changes Customer Passwords
May 02, 2013Some customer information exposed, including salted and hashed passwords from 'a minority' of customers
-
Consumer Reports: 58 Million U.S. PCs Infected With Malware
May 02, 2013Malware cost consumers nearly $4 billion in repairs in 2012, Consumer Reports says
-
Password Reuse Rampant, But Users Value Security, Survey Says
April 30, 2013More people adopt some online—and mobile—security, but still fail in proper follow-through, according to a new study by Varonis
-
LivingSocial Says Cyberattack Puts Data Of 50 Million Customers At Risk
April 29, 2013Shopping and deals site LivingSocial says all customers should change passwords; source of hack undisclosed
-
Managing Mobile Security In Small And Midsize Businesses
April 29, 2013Wireless devices are a boon to SMB productivity -- and a nightmare for security. Here are some tips for securing them
-
Phishers Hack Hosting Providers To Launch Mass Attacks
April 25, 2013Nearly half of all phishing attacks in the second half of last year came via hacked hosting providers, according to new data from the Anti-Phishing Working Group (APWG)
-
How Cybercriminals Attack The Cloud
April 25, 2013What attacks are most likely against cloud computing environments? Here's a look -- and some advice
-
Many Hacked Businesses Remain Unprepared For The Next Breach
April 24, 2013New Ponemon report finds three-fourths of hacked organizations either have had or expect to have a breach that loses them customers and business partners
-
Report: DDoS Attacks Getting Bigger, Faster Than Ever
April 22, 2013DDoS attacks of more than 10 Gbps now happen several times a day across the globe, study says
-
Botnets Come Out Of Hiding For Boston Bombing Spam
April 19, 2013Kelihos, Cutwail botnets jump into action to deliver spam emails disguised as news from bombings
Free Research and Reports
Whitepapers
- HP Newsletter with Gartner Research: Maximizing Your Infrastructure through Virtualization
- Understanding Holistic Database Security 8 Steps to Successfully Securing Enterprise Data Sources
- A How-To Guide on Using Cloud Services for Security-Rich Data Backup
- Holistic Risk Management: Perspectives from IT Professionals
- Aligning IT with strategic business goals: A proactive approach to managing IT risk to your business
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- The Future Of Web Authentication: Password technology is out of steam. We need safer ways to prove who's who online.
- Rethink ID Management: If the technology continues to improve, it might soon be OK for all of us to be one person on the Web.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2012-4697
TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to obtain administrative access via an FTP session.
CVE-2011-4520
Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
CVE-2011-4519
Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
CVE-2011-4518
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2012-6563
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.


