Welcome Guest. | Log In| Register | Membership Benefits

All attacks

'Operation Aurora' Changing The Role Of The CISO

    March 16, 2010
Targeted attacks out of China against Google and other U.S. firms have forced some chief information security officers to reach out to their counterparts in other organizations and share attack, forensics information

New Twitter Feature Looks For Malicious URLs

    March 10, 2010
Meanwhile, one in eight Twitter accounts is either malicious, suspicious, or suspended, according to a new report from Barracuda Networks

Top Google Search Items Under Siege

    March 10, 2010
Nearly 300 top search terms hit by 6,600 malicious URLs in past seven days

Voluntary Breach Disclosure Rare But Valuable

    March 9, 2010
Most organizations won't go public about an attack unless they have to, but security experts say there are ways to collaborate without being stigmatized

New IE Zero-Day Flaw Being Used In Targeted Attacks

    March 9, 2010
Microsoft issues special Internet Explorer 6 and 7 security advisory along with Patch Tuesday patches

Botnets Serving Project Aurora Likely Built By "Amateurs," Researcher Says

    March 9, 2010
Rumors of sophistication in China's botnet attacks were exaggerated, Damballa expert says

Verizon Offers Up Its Data Breach Framework

    March 1, 2010
Free Verizon Incident-Sharing (VerIS) provides a standard way to collect and anonymously share security incident data and analysis

Criminals Hide Payment-Card Skimmers Inside Gas Station Pumps

    February 22, 2010
Wave of recent bank-card skimming incidents demonstrate how sophisticated the scam has become

FTC Probe Uncovers Widespread Data Breaches Via P2P Networks

    February 22, 2010
Close to 100 organizations have been notified that personal data has been shared

Thousands Of Organizations Worldwide Hit By Widespread Malware Attack

    February 18, 2010
Botnet bearing the Zeus Trojan infected 75,000 systems worldwide in 2,500 enterprises, government agencies

Czech Researchers Say 'Chuck Norris' Kicks Bots

    February 18, 2010
Emerging botnet could redirect users to data-stealing sites, researchers say

'Aurora' Attacks Still Under Way, Investigators Closing In On Malware Creators

    February 10, 2010
Researchers find 'markers' associated with authors of Aurora malware used in attacks against Google, others

Healthcare Data Exposed In California Security Breach

    February 10, 2010
Social Security numbers appeared on labels used in mass mailing from government healthcare organization

Product Watch: New Tool Automatically Examines Suspicious Code In Memory

    February 8, 2010
HBGary Responder Professional 2.0 analyzed malware behavior in the Operation Aurora in five minutes

Twitter Gives Details On Phishing Attack

    February 4, 2010
Social networking firm outlines exploit that forced many users to reset their passwords

Hospitality Industry Hit Hardest By Hacks

    February 4, 2010
Trustwave report on data breach investigations shows hotels were breached more than financial institutions last year, and nearly all attacks were after payment-card data

Botnet Floods Major Websites With Fake SSL Connections

    February 1, 2010
DDoS-like traffic surge against CIA, Chase, Google Chrome, FBI, and others has researchers puzzled by Pushdo botnet's plans

49 Congressional Websites Hacked By Brazilian 'Red Eye Crew'

    January 29, 2010
Defacement worries legislators, who have been hit previously

Speaker Pelosi And Boehner Send Letter To CAO On Protecting House Web Sites From Being Hacked

    January 29, 2010
Legislators request 'immediate and comprehensive assessment of how hackers were able to deface the websites of nearly fifty House Members and Committees'

Global Critical Infrastructure Networks Regularly Under Attack

    January 28, 2010
New report from the Center for Strategic and International Studies finds it's not a matter of when energy, telecom, and other networks will be attacked -- but how often

Anatomy Of A Targeted, Persistent Attack

    January 27, 2010
New report provides an inside look at real attacks that infiltrated, camped out, and stole intellectual property and proprietary information -- and their links to China

Cost Of Data Breaches Increased In 2009, Study Says

    January 26, 2010
Ponemon Institute research says malicious attacks are the most costly breaches

Report: More Than 560,000 Websites Infected In Q4

    January 26, 2010
Web attacks get stealthier and more efficient; 5.5 million Web pages discovered to be infected

Flaws In The 'Aurora' Attacks

    January 25, 2010
Security experts say targeted attacks could have been much worse, point out strategic errors made by the attackers

New Details On Targeted Attacks On Google, Others, Trickle Out

    January 21, 2010
Meanwhile, Microsoft releases emergency patch for IE exploit used in the attacks

Google Hack Code Released, Metasploit Exploit Now Available

    January 16, 2010
Researchers now say there's no evidence infected PDFs were used in the targeted attacks originating from China on Google and other companies, but investigations continue

Attackers Employed IE Zero-Day Against Google, Others

    January 14, 2010
Microsoft issues workaround for the attack; McAfee christens the Chinese hacks 'Aurora'

More Victims Of Chinese Hacking Attacks Come Forward

    January 14, 2010
Law firm that filed suit against China for intellectual property theft and a Web hosting service report attacks; news site hit by a DDoS out of China

Spear-Phishing Attacks Out Of China Targeted Source Code, Intellectual Property

    January 13, 2010
Attackers used intelligence, custom malware to access Google, Adobe, and other U.S. companies' systems

ITRC Report: Malicious Attacks Are Now More Frequent Than Human Error

    January 13, 2010
In 2009 breach report, ITRC finds that bad guys account for more leaks than dumb mistakes

Philippines Investigates Hacks Of Multiple Government Sites

    January 11, 2010
Political motives suspected in defacement of high-profile sites

Heartland To Pay Up To $60 Million In Breach Settlement With Visa

    January 8, 2010
A year after the big breach, Heartland is still paying for hack

Industry Group Plans Cyber Attack Simulation

    January 7, 2010
The Financial Services Information Sharing and Analysis Center will test participants' emergency response, notification, and communication procedures

Hackers Replace European Union President With Mr. Bean

    January 6, 2010
Cross-site scripting attack puts photo of British comedian in place of Spanish prime minister

New PDF Exploit May Be First Of Many In The New Year, Experts Say

    January 5, 2010
Adobe will be a chief target for hackers and cybercriminals in 2010, researchers predict

Gonzalez Pleads Guilty To Hack Of Heartland, Hannaford, 7-Eleven

    December 30, 2009
Guilty plea reveals Target was also victim of massive hacking ring

DDoS Attack Briefly Interrupts Online Holiday Shopping

    December 28, 2009
Attack On UltraDNS was detected 'within minutes,' and shoppers were back online in an hour

Facebook Hit By Clickjacking Attack

    December 23, 2009
Social network targeted by emerging brand of attack that's hard to kill

Intel Website Hacked With SQL Injection

    December 23, 2009
Hacker reveals major hole that exposes personal passport information on channel partner events Website

The 9 Coolest Hacks Of 2009

    December 23, 2009
Digital faces, missile defenses, iPod Touches, and even texting teens all were the subject of extreme hacks

Report: FBI Probes Citigroup Breach

    December 22, 2009
Federal officials say they are investigating loss of tens of millions of dollars; Citigroup says there was no breach or loss

How The Koobface Worm Gang Makes Money

    December 21, 2009
Trend Micro report looks at the true motivation behind the widespread malware-laden botnet

Attack Of The RAM Scrapers

    December 18, 2009
Beware of malware aimed at grabbing valuable data from volatile memory in point-of-sale systems

Twitter Hit By DNS Hijacking Attack

    December 18, 2009
Twitter site redirected to 'Iranian Cyber Army' Website for about an hour last night

Social Networking Developer Site Database Hacked In SQL Injection Attack

    December 15, 2009
32 million accounts exposed, Webmail accounts could be at risk as well

MessageLabs '09 Report: Botnets Bounce Back With Sharpened Survival Skills

    December 11, 2009
The bad guys sharpened their skills, rather than just relying on large spam runs and malware attacks

Some 132K Websites Hit By New SQL Injection Attack

    December 10, 2009
ScanSafe reports widespread attack that continues to grow

New Verizon Business Report Outlines 15 Most Common Attacks

    December 9, 2009
Keylogging and spyware are among the most commonly found exploits in breached companies, report says

Metasploit Gets New Vulnerabilty Scanning Features

    December 1, 2009
Rapid7 takes first step in integrating penetration testing tool with its NeXpose vulnerability scanner, rolls out new free version of NeXpose

Hacker Arrested For Stealing Virtual Assets In Online Game

    December 1, 2009
Man allegedly broke into almost 300 RuneScape accounts, police say








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:legato networker, informix dynamic server
Published:2010-03-05
Severity:High
Description:Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allow remote attackers to execute arbitrary code via a crafted parameter size.
Vulnerability:legato networker, informix dynamic server
Published:2010-03-05
Severity:High
Description:Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.
Vulnerability:http server
Published:2010-03-05
Severity:Medium
Description:The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
Vulnerability:kvm
Published:2010-03-05
Severity:Medium
Description:The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not properly restrict writing of segment selectors to segment registers, which might allow guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, and replacing an instruction in between emulator entry and instruction fetch.
Vulnerability:unified communications manager
Published:2010-03-05
Severity:High
Description:Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapabilitiesRes message with an invalid MaxCap field, aka Bug ID CSCtc38985.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)