Welcome Guest. | Log In | Register | Membership Benefits

All Attacks/Breaches Stories

Orphaned Bots Facing Internet Blackout

    February 22, 2012
DNSChanger botnet takedown poses unique challenges and risks that other botnet overthrows do not

Flash Zero-Day Used In Targeted Email Attacks

    February 16, 2012
Rare universal XSS attack campaign aimed at taking over Webmail accounts

New Waledac Variant Goes Rogue

    February 15, 2012
Disabled spamming botnet creates new variant that steals user credentials

Hactivists Take Down CIA's Website

    February 13, 2012
Hit by apparent DDoS, website has been experiencing intermittent period of inaccessibility since Friday

When And How Attackers Are Owning Businesses

    February 09, 2012
New Truswave SpiderLabs breach report highlights risky passwords, emails, and timing

Smarter, Stealthier, Sneakier Malware

    February 08, 2012
From Stuxnet to Duqu to new incarnations of Zeus, sophisticated attacks are becoming more numerous -- and harder to stop

Law Enforcement Ups Its Game In Cybercrime

    February 07, 2012
New data from Trustwave SpiderLabs shows how law enforcement agencies worldwide are getting better at catching cybercriminals -- but it's still a major chase

Hackers Post Symantec Source Code After Failed Extortion Attempt

    February 07, 2012
Symantec is warning customers to upgrade pcAnywhere and apply available patches to stay safe after source code for the product was posted online

Utilities Facing Brute-Force Attack Threat

    February 06, 2012
SSH attack warning from ICS-CERT just the latest in a series of high-profile vulnerabilities in '1990s-era security' SCADA, critical infrastructure world

More Than Half Of Cyberattacks Come From Asia

    January 31, 2012
DDoS attacks worldwide on the rise, report finds

New Drive-By Spam Infects Those Who Open Email -- No Attachment Needed

    January 28, 2012
Getting infected just got a whole lot easier, researchers say

Security Careers: A Closer Look At Digital Investigations

    January 26, 2012
Security incident response and forensics are, at heart, people problems. Here are some tips for making the most of them

Study: The Aftermath Of A Breach

    January 26, 2012
New Ponemon-Experian study highlights organizations' top priorities following a data breach

Six-Year-Old Breach Comes Back To Haunt Symantec

    January 26, 2012
Security firm warns users to halt use of pcAnywhere until it finishes patching it, but says older Norton products not at risk from previously 'inconclusive' 2006 security incident

Hacktivists Turn To DNS Hijacking

    January 26, 2012
Coach, UFC fallvictim to attacks that redirect their Web traffic

EU's More Stringent Data Privacy Proposal Poses Challenges For Businesses

    January 25, 2012
Proposed changes to data privacy laws in Europe have garnered mixed praise

Are You Contributing To A DDoS Attack? Researcher Says You Might Be

    January 20, 2012
Links distributed by Anonymous and others could make your computer part of the DDoS, Sophos says

'Anonymous' Back With A Vengeance: Downs DoJ, MPAA, RIAA, Universal Music Websites

    January 19, 2012
White House also being targeted as federal anti-piracy moves fuel widespread online attacks

Zappos Dealing With Data Breach

    January 18, 2012
Online shoe and clothing retailer directs customers to reset their passwords via a dedicated password-reset page

Facebook: No Koobface Malware Attacks For Nearly A Year

    January 17, 2012
An aggressive campaign by the social network to kill the pesky malware included taking down its command and control server, and SophosLabs unmasks the alleged gang members

Facebook 'Koobface' Malware Gang Unmasked -- Sophos Releases Exclusive Research

    January 17, 2012
Investigation uncovers identities of the alleged perpetrators

Sykipot Malware Now Steals Smart-Card Credentials

    January 12, 2012
New variant of malware used by advanced persistent threat (APT) actors out of China challenges DoD, other organizations’ two-factor authentication

China Arrests Four In CSDN Data Breach; Related Breaches Proved To Be Hoaxes

    January 12, 2012
More than 6M users affected by hack of China's CSDN; eight people punished for spreading faulty info about related breaches

China Not The U.S.'s Only Cyber-Adversary

    January 11, 2012
Reports of cyberespionage out of India a wake-up call for U.S. businesses, government agencies

U.S. China Commission Emails Hacked

    January 10, 2012
Indian hacker group's alleged hack for India or China?

Prolexic Mitigates Weekend DDoS Attack For Foundation Source

    January 09, 2012
Attack started Friday night, spanned three days, and impacted site functionality

Worm Siphons 45,000 Facebook Accounts

    January 05, 2012
Ramnit financial malware gets social with new variant

New Denial-Of-Service Attack Cripples Web Servers By Reading Slowly

    January 05, 2012
'Slow Read' proof-of-concept and tool released today

Care2 Discloses Breach; Company Has Nearly 18 Million Members

    January 05, 2012
Passwords, account information could be at risk following breach of Care2 customer data

Latest SQL Injection Campaign Infects 1 Million Web Pages

    January 04, 2012
SANS warns of uptick in 'Lilupophilupop' attack, but Cisco says total number of infected URLs may be 'inflated'

Same Toolkit Spawned Stuxnet, Duqu, And Other Campaigns

    January 03, 2012
New Kaspersky Lab research nails down platform used for the targeted attacks, but not all researchers are sold that the exploits are all interrelated

Most Facebook Scams Are Designed To Feed Affiliate Marketing Programs

    December 29, 2011
Fraudulent advertisers are behind majority of Facebook scams and exploits, Commtouch study finds

The 7 Coolest Hacks Of 2011

    December 27, 2011
Evil insulin pumps and laptop batteries, war texting, and a tween hacker captured our imagination -- and our attention

Details Emerge About Sykipot Malware

    December 22, 2011
Clues point to China

U.S. Chamber Of Commerce Hit By Chinese Cyberspies

    December 21, 2011
Targeted attack against the nation's business lobbying organization may have been ongoing for more than a year, according to The Wall Street Journal

Attackers Pose As Police In New Ransomware Campaign

    December 20, 2011
Messages with an official-looking police banner claim discovery of child pornography, other illicit material, and emails with terrorists

Hackers Turn Lady Gaga's Facebook Page Into Bad Romance

    December 19, 2011
Bad guys woo Lady Gaga's Facebook friends with promise of free custom iPads -- and steal their data instead

DDoS Attack On Noticias24.com Is Abandoned After Traffic Is Provisioned Through Prolexic

    December 15, 2011
Website was subjected to a 10-hour DDoS attack launched by extortionists from Russia

Social Media Abuse, Mobile Malware Headline 2011 Top Internet Security Trends

    December 14, 2011
From social media abuse to mobile malware to major busts, past year filled with new twists on old scams

Adobe Zero-Day Attack Part Of Wider Campaign

    December 09, 2011
Symantec research points to well-funded attackers who use so-called Sykipot malware to target defense contractors, telecommunications firms, computer hardware companies, chemical companies, energy companies, and government

Resurgent LulzSec Attacks Government Sites In Portugal

    December 08, 2011
Hacktivist group Lulzsec responds to reports of police brutality in Portugal with attacks on government websites

The Most Notorious Cybercrooks Of 2011 -- And How They Got Caught

    December 07, 2011
A torrent of attacks from groups like Anonymous, LulzSec, Goatse Security and Antisec has made it a busy year for cybercrime investigators

Government Official Predicts Catastrophic U.S. Cyber Attack

    December 07, 2011
Members of the House Intelligence Committee say an attack could be in the near future

New Open-Source Technology Locks Down User's DNS Connection

    December 07, 2011
OpenCrypt secures connection between end users and their DNS service

RSA Shuts Down More Than 500,000 Cyber Attacks Across 185 Countries

    December 06, 2011
RSA FraudAction anti-phishing and anti-Trojan service recently reached a milestone

Healthcare Data In Critical Condition

    December 01, 2011
New study shows data breaches up and costing healthcare industry billions of dollars a year, with employees, mobile devices the weakest links

The Dark Side Of Java

    December 01, 2011
Metasploit adds new module for latest Java attack as the application is rapidly being targeted by cybercriminals

Hacktivists Crack United Nations, Publish User Data

    December 01, 2011
Hacktivist group TeamPoison may have broken into UN Development Program website, reports say

Researcher: DEP Would Have Stopped Exploit Used In RSA Breach

    November 30, 2011
Qualys research says EMC RSA phishing victims likely were running Windows XP

Slide Show: The Year In Data Theft

    November 29, 2011
From healthcare to game companies to trusted third-party security companies, a number of significant breaches were reported in 2011










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)