Welcome Guest. | Log In| Register | Membership Benefits

All attacks

Product Watch: New Tool Automatically Examines Suspicious Code In Memory

    February 8, 2010
HBGary Responder Professional 2.0 analyzed malware behavior in the Operation Aurora in five minutes

Twitter Gives Details On Phishing Attack

    February 4, 2010
Social networking firm outlines exploit that forced many users to reset their passwords

Hospitality Industry Hit Hardest By Hacks

    February 4, 2010
Trustwave report on data breach investigations shows hotels were breached more than financial institutions last year, and nearly all attacks were after payment-card data

Botnet Floods Major Websites With Fake SSL Connections

    February 1, 2010
DDoS-like traffic surge against CIA, Chase, Google Chrome, FBI, and others has researchers puzzled by Pushdo botnet's plans

49 Congressional Websites Hacked By Brazilian 'Red Eye Crew'

    January 29, 2010
Defacement worries legislators, who have been hit previously

Speaker Pelosi And Boehner Send Letter To CAO On Protecting House Web Sites From Being Hacked

    January 29, 2010
Legislators request 'immediate and comprehensive assessment of how hackers were able to deface the websites of nearly fifty House Members and Committees'

Global Critical Infrastructure Networks Regularly Under Attack

    January 28, 2010
New report from the Center for Strategic and International Studies finds it's not a matter of when energy, telecom, and other networks will be attacked -- but how often

Anatomy Of A Targeted, Persistent Attack

    January 27, 2010
New report provides an inside look at real attacks that infiltrated, camped out, and stole intellectual property and proprietary information -- and their links to China

Cost Of Data Breaches Increased In 2009, Study Says

    January 26, 2010
Ponemon Institute research says malicious attacks are the most costly breaches

Report: More Than 560,000 Websites Infected In Q4

    January 26, 2010
Web attacks get stealthier and more efficient; 5.5 million Web pages discovered to be infected

Flaws In The 'Aurora' Attacks

    January 25, 2010
Security experts say targeted attacks could have been much worse, point out strategic errors made by the attackers

New Details On Targeted Attacks On Google, Others, Trickle Out

    January 21, 2010
Meanwhile, Microsoft releases emergency patch for IE exploit used in the attacks

Google Hack Code Released, Metasploit Exploit Now Available

    January 16, 2010
Researchers now say there's no evidence infected PDFs were used in the targeted attacks originating from China on Google and other companies, but investigations continue

Attackers Employed IE Zero-Day Against Google, Others

    January 14, 2010
Microsoft issues workaround for the attack; McAfee christens the Chinese hacks 'Aurora'

More Victims Of Chinese Hacking Attacks Come Forward

    January 14, 2010
Law firm that filed suit against China for intellectual property theft and a Web hosting service report attacks; news site hit by a DDoS out of China

Spear-Phishing Attacks Out Of China Targeted Source Code, Intellectual Property

    January 13, 2010
Attackers used intelligence, custom malware to access Google, Adobe, and other U.S. companies' systems

ITRC Report: Malicious Attacks Are Now More Frequent Than Human Error

    January 13, 2010
In 2009 breach report, ITRC finds that bad guys account for more leaks than dumb mistakes

Philippines Investigates Hacks Of Multiple Government Sites

    January 11, 2010
Political motives suspected in defacement of high-profile sites

Heartland To Pay Up To $60 Million In Breach Settlement With Visa

    January 8, 2010
A year after the big breach, Heartland is still paying for hack

Industry Group Plans Cyber Attack Simulation

    January 7, 2010
The Financial Services Information Sharing and Analysis Center will test participants' emergency response, notification, and communication procedures

Hackers Replace European Union President With Mr. Bean

    January 6, 2010
Cross-site scripting attack puts photo of British comedian in place of Spanish prime minister

New PDF Exploit May Be First Of Many In The New Year, Experts Say

    January 5, 2010
Adobe will be a chief target for hackers and cybercriminals in 2010, researchers predict

Gonzalez Pleads Guilty To Hack Of Heartland, Hannaford, 7-Eleven

    December 30, 2009
Guilty plea reveals Target was also victim of massive hacking ring

DDoS Attack Briefly Interrupts Online Holiday Shopping

    December 28, 2009
Attack On UltraDNS was detected 'within minutes,' and shoppers were back online in an hour

Facebook Hit By Clickjacking Attack

    December 23, 2009
Social network targeted by emerging brand of attack that's hard to kill

Intel Website Hacked With SQL Injection

    December 23, 2009
Hacker reveals major hole that exposes personal passport information on channel partner events Website

The 9 Coolest Hacks Of 2009

    December 23, 2009
Digital faces, missile defenses, iPod Touches, and even texting teens all were the subject of extreme hacks

Report: FBI Probes Citigroup Breach

    December 22, 2009
Federal officials say they are investigating loss of tens of millions of dollars; Citigroup says there was no breach or loss

How The Koobface Worm Gang Makes Money

    December 21, 2009
Trend Micro report looks at the true motivation behind the widespread malware-laden botnet

Attack Of The RAM Scrapers

    December 18, 2009
Beware of malware aimed at grabbing valuable data from volatile memory in point-of-sale systems

Twitter Hit By DNS Hijacking Attack

    December 18, 2009
Twitter site redirected to 'Iranian Cyber Army' Website for about an hour last night

Social Networking Developer Site Database Hacked In SQL Injection Attack

    December 15, 2009
32 million accounts exposed, Webmail accounts could be at risk as well

MessageLabs '09 Report: Botnets Bounce Back With Sharpened Survival Skills

    December 11, 2009
The bad guys sharpened their skills, rather than just relying on large spam runs and malware attacks

Some 132K Websites Hit By New SQL Injection Attack

    December 10, 2009
ScanSafe reports widespread attack that continues to grow

New Verizon Business Report Outlines 15 Most Common Attacks

    December 9, 2009
Keylogging and spyware are among the most commonly found exploits in breached companies, report says

Metasploit Gets New Vulnerabilty Scanning Features

    December 1, 2009
Rapid7 takes first step in integrating penetration testing tool with its NeXpose vulnerability scanner, rolls out new free version of NeXpose

Hacker Arrested For Stealing Virtual Assets In Online Game

    December 1, 2009
Man allegedly broke into almost 300 RuneScape accounts, police say

Heap Spraying: Attackers' Latest Weapon Of Choice

    November 30, 2009
Difficult to detect reliably, heap spraying was behind an exploit of IE and Adobe Reader

Perimeter E-Security: Top Ten Biggest Security Breaches And Blunders of 2009

    November 30, 2009
A common thread between all of these incidents: They could have been avoided

New Exploit Masquerades As Flash Player Upgrade

    November 25, 2009
Phishing campaign has hit more than 3.5 million mailboxes, researchers say

Three Indicted For Comcast Site Hack

    November 20, 2009
'Kryogeniks' gang redirected traffic to its own Web page in 2008

FBI Warns Of Spear Phishing Attacks On U.S. Law Firms and Public Relations Firms

    November 18, 2009
Socially engineered e-mail designed to compromise a network by bypassing technological network defenses and exploiting the person at the keyboard

Big-Name Vendors Team On Disaster Preparedness, Recovery

    November 17, 2009
IT can play a major role in boosting the effectiveness of response efforts, say alliance sponsors that include Microsoft, Google, Yahoo

D.A. Davidson Breach Case Nears Resolution

    November 16, 2009
Judge approves settlement of lawsuit; three Latvian suspects extradited

Conn. AG Investigates Blue Cross Blue Shield Data Breach

    November 16, 2009
BC/BS and its related companies Anthem and Empire failed to inform health care providers until late last month, says Connecticut Attorney General Richard Blumenthal

iPhone Targeted Yet Again

    November 11, 2009
New hacking tool steals personal data off 'jailbroken' iPhones via a wireless network

Alleged $9 Million Hacking Ring Exposed

    November 11, 2009
Group broke into credit card systems at RBS Worldpay, DoJ says

MassMutual Warns Of Data Breach

    November 10, 2009
Database may have been compromised via third party vendor

Product Watch: Verizon Launches Data Discovery, Identification, And Security Classification Service

    November 9, 2009
New service reflects shift to 'data-centric' view of security, Verizon says

Gumblar Botnet Resurges

    November 6, 2009
Reactivation of Gumblar.cn domain could have ripple effect, researchers say








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:suse linux
Published:2010-01-22
Severity:High
Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Vulnerability:bind
Published:2010-01-22
Severity:Medium
Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)