Quick Hits
-
NTT To Acquire Solutionary, Add Cloud Security Services
June 18, 2013Pure-play managed security services provider Solutionary will become part of NTT's cloud portfolio
-
Medical Devices Subject To Cyberattack, FDA Warns
June 17, 2013Food and Drug Administration issues alert on vulnerabilities in medical devices
-
Iranians Targeted In Massive Phishing Campaign
June 13, 2013Google spotted targeted attacks out of Iran against tens of thousands of Iranians in the run-up to the country's presidential election on Friday
-
10 Ways Small Businesses Can Save Money On Security
June 13, 2013Small and midsize businesses have limited IT resources. Here are some ways they can stretch their security dollars
-
Microsoft: SMB Cloud Security, Privacy Concerns A Matter Of Perception
June 11, 2013Survey finds some SMBs afraid of going to the cloud for security reasons -- and other SMBs loving the cloud for security reasons
-
(ISC)2 Launches Certification Program For Cyber Forensics Experts
June 11, 2013New Certified Cyber Forensics Professional (CCFP) will help train security pros to handle breaches, testify in court
-
Study: Rogue Employees Are Top Concern For Security Pros
June 10, 2013Insider threat tops list of worries for security pros; malware, unauthorized software also cause concern
-
Google Ups Bug Bounty Awards
June 07, 2013Researchers now can get up to $7,500 per vulnerability they discover in Google applications
-
Building And Enforcing An Endpoint Security Strategy
June 06, 2013Endpoint technologies, defenses, and threats are changing rapidly. Here are some tips for keeping up
-
No Java Patch For You: 93 Percent Of Users Run Older Versions Of The App
June 04, 2013Many end users stuck with older Java to run certain apps, Websense finds
-
Fidelis Expands Into Malware Detection And Analysis
June 03, 2013New appliance for the Fortune 1000, SMB space
-
Strengthening Enterprise Defenses With Threat Intelligence
June 03, 2013By integrating security monitoring with threat intelligence, organizations can build a smarter defense
-
Startup To Offer 'Human' Authentication
May 30, 2013Identify Security Software Inc. will launch next week and preview new technology that eschews passwords and biometrics
-
Recent Data Breaches: A Look Back
May 30, 2013Hactivists, cybercriminals take center stage in latest spate of data breaches
-
Chinese Cyberspies Access U.S. Military Weapons System Designs
May 29, 2013Confidential report to DoD officials reveals breadth -- and reality -- of Chinese cyberespionage operations against U.S. military interests
-
What Every Database Administrator Should Know About Security
May 28, 2013Database administrators and security people are often at odds with each other. Here are some ways they can get together
-
Security Pros Fail In Business Lingo
May 23, 2013Survey shows communication breakdown between IT security staffers and business execs
-
Twitter Adds SMS As Second Factor Of Authentication
May 23, 2013Phone will be second means of verifying user identity, Twitter says
-
The Eight Most Common Causes Of Data Breaches
May 22, 2013Why do bad breaches happen to good companies? Here's a look at the most frequent causes
-
IDs Of 22 Million At Risk Following Breach At Yahoo Japan
May 21, 2013Yahoo Japan officials say they "can't deny the possibility" of epic data breach
-
Strategies For Improving Web Application Security
May 20, 2013Web apps are essential to your business -- and easy targets for hackers. Here are some tips for keeping them secure
-
Pakistan Hit By Targeted Attack Out Of India
May 17, 2013Information-stealing malware campaign spreads via phishing email attachments posing as Indian military secrets
-
Study: Application Vulnerabilities Are No. 1 Threat
May 16, 2013Shortage of training among developers is a key cause of high vulnerability rates, (ISC)2 survey says
-
Internet Crime Cost Consumers More Than A Half-Billion Dollars Last Year
May 15, 2013Number of cases reported by consumers to FBI-partnered Internet Crime Complaint Center increased by nearly 10 percent last year, with scams in auto fraud, FBI impersonation via email, extortion at the top of the list
-
SAFECode Launches Software Security Training Program For Enterprises
May 14, 2013Free curriculum will help businesses build software security training programs in-house, SAFECode says
Free Research and Reports
Whitepapers
Upcoming Events
Dark Reading Digital Magazine
In This Issue
- Endpoint Security: End user security requires layers of tools and training as employees use more devices and apps.
- Security Isn't A Piece Of Cake: It's time we rethink the conventional wisdom about security layering.
- BYOD Is Here To Stay: Trying to keep employees' devices off the network is futile.
Tech Insight
Bugs
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability Database
CVE-2013-3744
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.
CVE-2013-3743
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 45 and earlier and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.
CVE-2013-2473
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2472.
CVE-2013-2472
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2473.
CVE-2013-2471
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2472, and CVE-2013-2473.



