NEWS FEEDS CONSOLE (v2)

BBC News Technology
Smartphone keys get quantum trick
dot.Rory
Shuttle makes final night flight
China shuts down hacking website
Computing Ace
Robo-soldiers
IT glitch causes more tax errors
Endeavour prepares for second go
Spaceman
Spaceman
Pirate bill could 'breach rights'
dot.Rory
Personal politics
Cambridge to study computer games
Site 'crowdsources' climate data
Wired Magazine
First Chevrolet Volt Rolls Off the Line Nov. 1
Artist Creates Paintings From Floppy Disks
Farewell to Sci-Fi Writer William Tenn
Electric Cars, and Chargers, Poised to Flood Israel
Boeing's Biggest Bird Leaves the Nest
Google Making Gmail Into a Communications Hub
Jurors Told to Stop Tweeting
JooJoo Tablet Faces Uphill Battle Against iPad
Audio: DIY Recordings of Awakening Sun
Feb. 9, 1969:Boeing 747 Makes First Flight
Storyboard: Chris Anderson on Long Tail of Stuff
Stormy Weather Cannot Defeat Re-Engineered Umbrella
Video Gallery: Lightning Reveals Its Power in Slow Motion
Macworld Expo 2010 Caters to Apple Fans — Without Apple
Feb. 9, 1870: Feds Get on Top of the Weather
Net-Security Vulnerabilities
Sun Java System Application Server HTTP TRACE Information Disclosure
Hybserv2 ":help" Command Denial of Service
C++ Sockets Library HTTP Headers Remote Denial of Service
Citrix XenServer Authentication Bypass
XAMPP Multiple Cross-Site Scripting Vulnerabilities
jVideoDirect Component for Joomla! "v" Parameter SQL Injection
Joomla! "com_dms" Component "category_id&qu ot; Parameter SQL Injection
Joomla! JE Quiz Component "eid" Parameter SQL Injection
Joomla! "com_ccnewslett er" Component Directory Traversal
MoinMoin Unspecified Security
Tor Directory Authorities Directory Queries Remote Information Disclosure
Apple Safari Style Sheet Redirection Information Disclosure
Google Chrome prior to 4.0.249.78 Multiple Security Vulnerabilities
PunBB "viewtopic.php& quot; Cross-Site Scripting
Joomla! "com_book" Component "cid[]" Parameter SQL Injection
eWeek Security
China Closes Hacker Training School, Arrests 3
Researchers Present Web Application Attack Targeting Database Connection
Report: Google to Partner with NSA for Cyber-Security
Microsoft Plans Massive Patch Tuesday Security Update
Google, China and the Anatomy of the Aurora Attack
Microsoft Warns of IE Security Vulnerability
Older IE Versions Maintain Sizable Market Share Despite Security Concerns
Twitter Details Phishing Attacks Behind Password Reset
PGP to Acquire TC TrustCenter for Cloud-Based Identity Management
Researchers Uncover Security Vulnerabilities in Femtocell Technology
Facebook Privacy, Security Fears Grow with Social Network Risks
Adobe Flash Security on Menu at Black Hat
Apple iPhone App Security in Spotlight at Black Hat
Critical Infrastructure Security a Mixed Bag, Report Finds
Symantec's Consumer Business Led Way in Q3
Computer Crime Research Center
2010 CyberSecurity Watch Survey
Young lawmaker says cybercrime bill 'too vague'
CSI Computer Crime and Security Survey Shows Poor Security Awareness Training in Public and ...
Suffolk County Computer Crimes Initiative Awarded Funds In Omnibus Appropriation Bill
Computer crime: Protecting your privacy
Child porn sentence for ex-Bartlett parks official
Decatur police arrest man on child pornography charges
5,400 people were nabbed in China for online porn in 2009
iNetSec 2010 Open Research Problems in Network Security
Avoid Post-Thanksgiving Internet Scams
Millions of computers are filled with fake security software
Critical bug in SMB . Vista 2008 and RC of Windows 7 affected
Where in the World do Viruses Come From?
The 3rd International conference on IPRs, Personal Data Protection and National Security
Largest case of computer crime and identity theft ever prosecuted
The Register
Sun's cloud and gaming execs leave Oracle
Microsoft kills FAST's Linux and Unix search biz
Microsoft tests show no Win 7 battery flaw
Oracle issues emergency security patch for WebLogic
SourceForge reverses ban on US foes
Intel 'Tukwila' born after long and painful labor
Conficker outbreak infects Leeds hospital servers
Adobe apologizes for festering Flash crash bug
Ex-Intel exec pleads guilty to insider trading
El Reg reader assembles own iPad
LG eyes golden age of telly with retro CRT set
Phoenix recovers barbecued data in Europe
Cheeky French hackers hijack Tata website
iPhone OS 3.1.3 unlock app posted
Dell snaps up crashed Exanet
Net-Security News
NEW URL FOR HNS RSS FEED: http://feeds.feedbur ner.com/HelpNetSecur ity
NEW URL FOR HNS RSS FEED: http://feeds.feedbur ner.com/HelpNetSecur ity
NEW URL FOR HNS RSS FEED: http://feeds.feedbur ner.com/HelpNetSecur ity
Off the wire: Microsoft seeks patent for office 'spy' software
Security World: Wireless security lacking at a large convention
Off the wire: Setup and benchmark encrypted partitions in Ubuntu
Security World: Information Security Forum: It is time to take information classification seriously
Security World: USB encryption product news #1: KeyPoint Solo Vault
Security World: USB encryption product news #2: SafeHouse 3.0
Security World: 5 VoIP threat predictions for 2008
Off the wire: Annvix: A stable, secure, no-frills server distro
Virus Center: Don't fall in love with the Storm worm
Off the wire: Swedish prosecutors dump 4,000 legal docs on The Pirate Bay
Off the wire: Student points out 2nd security flaw on TSA Web site
Off the wire: MediaDefender hacker speaks out
Net-Security Advisories
SUSE Security Announcement - Linux kernel (SUSE-SA:2010:010)
Mandriva Linux Security Update Advisory - kernel (MDVSA-2010:034)
Mandriva Linux Security Update Advisory - mmc-agent (MDVA-2010:050)
Mandriva Linux Security Update Advisory - microcode_ctl (MDVA-2010:052)
Mandriva Linux Security Update Advisory - mmc-web-base (MDVA-2010:051)
Mandriva Linux Security Update Advisory - mmc-wizard (MDVA-2010:053)
Ubuntu Security Notice - linux, linux-source-2.6.15 vulnerabilities (USN-894-1)
SUSE Security Announcement - Linux kernel (SUSE-SA:2010:009)
Mandriva Linux Security Update Advisory - squid (MDVSA-2010:033)
Debian Security Advisory - New trac-git package fixes regression (DSA-1990-2)
Debian Security Advisory - New squid/squid3 packages fix denial of service (DSA 1991-1)
Mandriva Linux Security Update Advisory - rootcerts (MDVSA-2010:032)
Debian Security Advisory - New chrony packages fix denial of service (DSA 1992-1)
Mandriva Linux Security Update Advisory - wireshark (MDVSA-2010:031)
Debian Security Advisory - New trac-git packages fix code execution (DSA-1990-1)
Linux Exposed
Formatstrings and OpenBSD
Analyzing Malicious SSH Login Attempts
Enhance Security with Port Knocking
Preventing Accidental Denial of Service
Torrents and SSH Tunnels
Ilegal SEO techniques
Cracking WPA and WPA2 passwords
Windows Hacking and Windows Security Site
Inspecting HTTP
Hosted Exchange and Hosted Sharepoint
phpBB Forum Password Reset Hack
Internet Privacy and you
Mail Bombing : Theoretical Denial of Service Attack
Case of a wireless hack
The Apache HTTP Server
Info World Security
Fake security software scammers jump on Conficker
China denies cyberespionage charges
Gartner: IT spending drop-off worse than after dot-com bust
Conficker activation passes quietly, but threat isn't over
Forrester now says '09 U.S. IT spend to drop 3.1 percent
Conficker may be more widespread than previously thought
Bill would give feds role in private sector cybersecurity
IBM continues push for Sun, but will the deal kill Solaris?
Hackers seize on 0-day flaw in Microsoft's PowerPoint
IBM sees Conficker hitting 4 percent of PCs
Microsoft looks to secure Web content
New worm feeds on latest Microsoft bug
Top 10: Microsoft's bug, Greenspan speaks, Android launches
RFID passport cards vulnerable to snooping
Attack code for critical Microsoft bug surfaces
Hack In The Box
Hackers training website shut down by China government
95% of user-generated content was malicious in 2H 2009
IT Outsourcing: Why It Pays to Appraise Your Contract
Inside CloudLinux's New Linux-Based Cloud OS
Germany to purchase stolen Swiss bank data for $3.5 million
How O2 secured its network for the iPhone
Critical infrastructure under constant cyberattack
£150m sting to infect computers with porn
Open source means freedom from 'anti-features'
YouTube confirms IPv6 support
How to Jailbreak iPhone 3.1.3 IPSW with PwnageTool 3.1.5
Former Intel Exec Pleads Guilty in Galleon Insider Case
AMD Reveals Fusion CPU+GPU, To Challege Intel in Laptops
Microsoft's Windows 7 chief: It's not us; it's your batteries
Google warns Chinese copycat Web site
CERT
TA10-021A: Microsoft Internet Explorer Vulnerabilities
TA10-013A: Adobe Reader and Acrobat Vulnerabilities
TA10-012B: Microsoft Windows EOT Font and Adobe Flash Player 6 Vulnerabilities
TA10-012A: Oracle Updates for Multiple Vulnerabilities
TA09-343A: Adobe Flash Vulnerabilities Affect Flash Player and Adobe AIR
TA09-342A: Microsoft Updates for Multiple Vulnerabilities
TA09-314A: Microsoft Updates for Multiple Vulnerabilities
TA09-294A: Oracle Updates for Multiple Vulnerabilities
TA09-286B: Adobe Reader and Acrobat Vulnerabilities
TA09-286A: Microsoft Updates for Multiple Vulnerabilities
TA09-251A: Microsoft Updates for Multiple Vulnerabilities
TA09-223A: Microsoft Updates for Multiple Vulnerabilities
TA09-218A: Apple Updates for Multiple Vulnerabilities
TA09-209A: Microsoft Windows, Internet Explorer, and Active Template Library (ATL) Vulnerabilities
TA09-204A: Adobe Flash Vulnerability Affects Flash Player and Other Adobe Products
Computer World Security
Adobe apologizes for 16-month-old Flash bug
Poughkeepsie, N.Y., slams bank for $378,000 online theft
Malwarebytes' Anti-Malware Free
Why CSOs Should Care About ShmooCon
An open letter to my public transit company
PC Maintenance: What Tasks When?
China shuts hacker training site, arrests three
The top 5 mistakes of privacy awareness programs
Security Manager's Journal: Latest malware is a call to action
Sharp, Samsung settle all outstanding LCD patent cases
ShmooCon: Inside FarmVille's sinister underbelly
ShmooCon: Your iPhone's dirty little security secret
Symantec hit with class-action lawsuit over auto-renewals
With bug public, Oracle rushes out WebLogic fix
Oracle patches flaw, Asustek to take on iPad
Sophos - Graham Cluley
Bill Cosby has NOT died, but rumours fuel hacker scareware attack
Can Gordon Brown's smile infect your computer with a virus?
Mozilla admits Firefox add-ons contained Trojan code
Microsoft warns of Internet Explorer vulnerability
How to choose a strong password
The Automation Labs Facebook security scare
The world's top 10 dirtiest web-hosting countries
Woman charged £1400 for stolen mobile phone
Petition calls for Internet Explorer 6 to be dropped by British Government
Conficker virus outbreak at Greater Manchester Police
Sophos Security Threat Report 2010
Revealed: Which social networks pose the biggest risk?
Wikileaks closes down.. for now
Sophos wins VB100 award for SUSE Linux protection
Twitter list spam
FireEye Lab
Who is Exploiting the Adobe Flash 0-day? - Part 2
Killing the beast...Part 3
A leap into the unknown - Part 1
Gumblar... Not Gumby!
A little more on Donbot...
Killing the beast...Part 4 (Ozdok)
Smashing the Mega-d/Ozdok botnet in 24 hours
Checking In With The Ozdok Sinkhole
PDF Obfuscation using getAnnots()
Infiltrating Pushdo -- Part 1
Infiltrating Pushdo -- Part 1
PDF Obfuscation using getAnnots()
Checking In With The Ozdok Sinkhole
Bad Actors Part 7 - 3fn (Or: Cutwail - How to do it right)
Heap Spraying with Actionscript
Linux Security
Review: Mod-Security 2.5 by Magnus Mischel
Review: Googling Security: How Much Does Google Know About You
A Secure Nagios Server
Never Installed a Firewall on Ubuntu? Try Firestarter
Review: Hacking Exposed Linux, Third Edition
Security Features of Firefox 3.0
Review: The Book of Wireless
Review: Googling Security: How Much Does Google Know About You
A Secure Nagios Server
Never Installed a Firewall on Ubuntu? Try Firestarter
Review: Hacking Exposed Linux, Third Edition
Security Features of Firefox 3.0
Review: The Book of Wireless
April 2008 Open Source Tool of the Month: sudo
Open Source Tool of March: ZoneMinder
NetSec Blog
FBI launches cybersecurity project - from Keith
Wonderful bedtime stories - The Metasploit (wiki) ...
Pretty good ideas:The 10 Commandments for New Lin...
"Safe Bedside Table"
Speaking of Bad Guys
Nothing new here - Monster.com hacked, 1.6 million...
Storm Worm Strikes Back
Delete This! - A series of legal events means that...
U.S. legal time changing to UTC
Source Code Subpoena Request as Legal Defense Tact...
Design flaw in AS3 socket handling allows port pro...
Sprint to offer WiMAX-enabled Nokia N800 in 2008
Helix 1.9a Released
Will security firms detect police spyware?
Fall Classes Start August 23rd ITN260 Network Se...
joatBlog
Comment system is down
vmfs-fuse
ESXi 3.5 and 3c905c
Graphics added for ESXi install
Installing ESXi 4.0 on a HP e9170c
Still here...
Java and 64-bit Linux
A whole lot of virtual
Toggling lights and clocks
My poor cheesecake
Oh just shut up!
Fun
ESXi and Virtualbox II
ESXi and Virtualbox
TBs and Identica verb for Ubiquity
ZDNet US Security
Oracle releases emergency patch
China breaks up Black Hawk hacking ring
ISM3 brings greater standardization to security measurement across enterprise IT
Oracle rushes out patch for gaping server hole
Mozilla Firefox hit by malware add-ons
Firefox add-on contained toxic Trojan code
MS Patch Tuesday heads-up: 13 bulletins, 26 vulnerabilities
Let compliance lead the way in preventing healthcare data breaches
U.S. House passes cybersecurity research bill
Does Blippy really pose a security risk?
Yikes! Is Google really tapping the NSA for network security help?
IBM to design cloud computing network for Air Force
BriefingsDirect analysts discuss ramifications of Google-China dust-up over corporate cyber attacks
Microsoft warns of new IE data-leakage vulnerability
Climate scientist and his East Anglia university in deeper trouble
ZDNet UK Security
Mobile M2M connections set to rocket
India to create 8m outsourcing jobs in next decade
Mobile tech gets cautious praise from aid groups
Wi-Fi operator launches automatic sign-on tool
Microsoft platform tops Web 2.0 developer survey
Verizon funds undersea internet cable network
Vodafone lands multinational iPhone deal
India mulls tax-break extension for outsourcers
Microsoft resumes XP SP3, Vista SP1 updates
McAfee strikes Yahoo search deal
Sun previews JavaFX for rich web applications
Microsoft and Yahoo: The next step
Sun shows off JavaFX platform
Auction site QXL going, going, gone
Sun demos JavaFX apps
Politechbot
Who'd make the most technology-friendly president? Discuss.
Judge rules defendant can't be forced to divulge PGP passphrase
David Burt and his Filtering Facts Web site are back
ITU botnet paper published in draft form, comments requested
FTC Internet advertising summit in Washington this week
Hamline University student suspended after pro-gun rights email
MIT student picking up friend at airport nearly shot, charged with "infernal machine" crime
Colorado sheriff creates roadblock so private firm can demand DNA blood samples
Paul Levy: Politicians, infomercial kings try to stifle anonymous Internet speech
Federal police will gain access to military spy satellites
Congress at its finest: P2P networks as "national security threat"
Sen. John Kerry wants to outlaw "transmitting" dog fighting images
Whoops! Nevada governor accidentally posts Outlook password
FBI remotely installs spyware to trace bomb threat
Will security firms detect police spyware? A survey of 13 of them
Slashdot
Virtualizing a Supercomputer
Oracle Drops Sun's Commitment To Accessibility
IBM Releases Power7 Processor
Mozilla Puts Tiger Out To Pasture
A Reflection On Sun Executive Payouts For Failure
Verizon Blocking 4chan
New Material Transforms Car Bodies Into Batteries
Google Shooting For Smartphone Universal Translator
Virus-Detecting "Lab On a Chip" Developed At BYU
Study Says OOXML Unsuitable For Norwegian Government
Mozilla Puts Tiger Out to Pasture
Zero-Day Vulnerabilities On the Market
Nexus One First Phone Linus Torvalds "Doesn't Hate"
SourceForge Removes Blanket Blocking
What Are the Best Valentine's Day Stunts?
Government Computer News
Google-NSA partnership should be more public, less private
Security Jam wants bread-and-butter proposals
IBM 'jam' technology goes global
Microsoft warns of IE bug on Windows XP
Microsoft's Tuesday patch will be a Windows wash
Dell strikes alliance to simplify network security
Google pulls support for Internet Explorer 6
Engineer shows how to crack a 'secure' TPM chip
Spyrus to offer 'secure' portable Windows OS
Cyber threat growing at unprecedented rate, intell chief says
Virtual border fence would lose under budget
Faster networks, closer inspection fend off agile threats
Intrusion protection systems: Buyer beware
A new wrinkle in Nigerian e-mail scams
Evolving guidelines seek to harmonize IT security for government systems
InfoSec News
Fugitive VoIP hacker admits 10 million minute spree
Secunia Weekly Summary - Issue: 2010-05
GAO Report: NASA Still Facing Weaknesses In IT Security
CSIIRW Sixth Cyber Security and Information Intelligence Research Workshop
Biggest hacker training site shut down
Why CSOs Should Care About ShmooCon
IDF considers using BlackBerry
BlackBerry has spyware risk too, researcher says
Swiss Banks Achilles Heel Is Workers Selling Data
ITL BULLETIN FOR JANUARY 2010
PACAF stands up Information Protection Directorate
Phishing Scam Cripples European Emissions Trading
Hackers Try to Steal $150,000 from United Way
Black Hat: Microsoft Enhances SDL Offerings
Report Details Hacks Targeting Google, Others
CNet
iPad pricing: How low can you go, Apple?
Did this Metro PCS ad make the tech world cringe?
Google launches Nexus One phone support
CNET News Daily Podcast: Blackberry hacked, 4chan blocked, iPad unwanted
Microsoft denies Windows 7 battery problem
Stay home, let Texas Robot attend that meeting
Next-generation 747 takes first air (photos)
Former Intel exec pleads guilty in Galleon case
Boeing's next-gen 747 takes first flight
TweetDeck gets a few tweaks
University worker accused of extorting student file sharers
Silicon: It's good for you, especially in beer
Twins learn of teen brother's death on Facebook
Bids are in for AOL's sale of ICQ--it's down to 'UN' of 4 buyers
Nook back on sale
InfoSec Officer
You're Certified! Wait, Maybe Not...
Lessons From A Stolen iPhone
Department of Defense Scholarship + Internship + Job!
2010: Security On A Diet
Uncle Sam Needs Security Pros NOW!
Should You Be Nervous To Fly?
Failure Is A Winning Situation
Playing With The Windows Process Tree
Case of the Tenacious Timelord: Part V
Bigger Than A Breadbox?
Forensic Investigators Should Take An Oath
It's Time For Bloggers To Fess Up!
Case of the Tenacious Timelord: Part IV
Case of the Tenacious Timelord: Part III
PSA: What Does The Internet Know About You?
Rootsecure.net
The Register: Sweden to prosecute alleged Cisco, NASA hacker
Net Security: Zero-day vulnerabilities on the market
The Register: Google doppelganger casts riddle over interwebs
H Security: Infected add-ons found on Mozilla download site
H Security: Vulnerability in Samba provides access to files
Wired: 21st-Century Shooters Are No Country for Old Men
Computer World: ShmooCon - Inside FarmVille's sinister underbelly
Network World: ShmooCon - P2P Snoopers Know What's In Your Wallet
CSO: Why CSOs Should Care About ShmooCon "CSO Senior Editor Bill Brenner on why high-level security execs should pay more attention to a hacker fest like ShmooCon"
Slashdot: Paypal Reverses Payments Made To Indians
Reuters: China shuts down largest hacker training website "China has closed what it claims to be the largest hacker training website in the country and arrested three of its members"
Bugspy - "crawls the web in search of the latest bug reports in open source software"
arstechnica: Security flaw puts iPhone users at risk of phishing attacks
c|net: Authors Guild - We don't want to be the RIAA "The Authors Guild agreed to a controversial settlement with Google because it feared repeating the mistakes that the music industry has made in dealing with digital works, it said Friday"
c|net: FBI wants records kept of Web sites visited "The FBI is pressing Internet service providers to record which Web sites customers visit and retain those logs for two years"
Security Focus
News: CIA, PayPal under bizarre SSL assault
News: Most consumers reuse banking passwords
Brief: Google offers bounty on browser bugs
Brief: Cyberattacks from U.S. "greatest concern"
Brief: MS readies patch, as fraudsters target IE flaw
Brief: Attack on IE 0-day refined by researchers
Brief: IE flaw gave attackers entry, says McAfee
Brief: Law firm suing China suffers attack
Brief: Microsoft, Oracle, Adobe issue patches
Brief: Google, Adobe attacked through China
Brief: Cyber exercise to target financial firms
Brief: NIST investigates secure USB flaws
News: Malicious traffic can crash routers, Juniper warns
Brief: Adobe revamps Reader, Acrobat updater
Brief: China sued over Green Dam code
Security Focus BugTraq
Bugtraq: [security bulletin] HPSBMA02487 SSRT100024 rev.1 - HP Operations Agent Running on Solaris 10, Remote Unauthorized Access
Bugtraq: [ MDVSA-2010:034 ] kernel
Bugtraq: RE: Samba Remote Zero-Day Exploit
Bugtraq: [security bulletin] HPSBUX02503 SSRT100019 rev.1 - HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other
Vuln: Oracle 11gR2 Remote Command Execution Vulnerability
Bugtraq: [Suspected Spam]Vulnerability in Tagcloud for DataLife Engine
Bugtraq: mongoose Space Character Remote File Disclosure Vulnerability
Bugtraq: [DSECRG-09-065] TVUPlayer PlayerOcx.ocx ActiveX - Insecure method
Bugtraq: CORELAN-10-010 - GeFest Web HomeServer v1.0 Remote Directory Traversal Vulnerability
Vuln: OCS Inventory NG Cross Site Scripting and SQL Injection Vulnerabilities
Vuln: OpenBB Multiple SQL Injection Vulnerabilities
Vuln: Joomla! 'com_photoblog' Component 'blog' Parameter SQL Injection Vulnerability
Vuln: Apple Safari Remote Denial Of Service Vulnerability
Vuln: Chrony 1.23 and Prior Multiple Remote Denial of Service Vulnerabilities
Vuln: Samba Symlink Directory Traversal Vulnerability
Full Disclosure @Insecure.org
Re: about jit and dep+aslr
Re: about jit and dep+aslr
Re: about jit and dep+aslr
Re: about jit and dep+aslr
Re: about jit and dep+aslr
[ MDVSA-2010:034 ] kernel
Vulnerability in Tagcloud for DataLife Engine
The true power of cache
Re: Samba Remote Zero-Day Exploit
CORELAN-10-010 - GeFest Web HomeServer v1.0 Remote Directory Traversal Vulnerability
[Hacking Event] Night Da Hack 2010 : Call For Proposals
JDownloader Remote Code Execution
XSS vulnerability in NEW orkut.
Re: about jit and dep+aslr
Re: anybody know good service for cracking
SecurityTracker Vulnerabilities
HP OpenView Operations Agent Blank 'opc_op' Password Lets Remote Users Access the System
Linux Kernel Flaw in do_pages_move() Lets Local Users Obtain Kernel Memory and Deny Service
Trend Micro OfficeScan URL Filtering Buffer Overflow May Let Remote Users Execute Arbitrary Code
F5 BIG-IP TCP Processing Flaw Lets Remote Users Deny Service
LANDesk Management Gateway Input Validation Flaw Permits Cross-Site Request Forgery and Command Injection AttacksAttacks
IBM WebSphere Application Server Single Signon "Requires SSL" Option May Not Be Honored
IMail Server Password Encryption Algorithm Lets Local Decrypt Passwords
F5 FirePass TCP Processing Flaw Lets Remote Users Deny Service
OpenSolaris Flaw in kclient and smbadm When Joining a Windows Domain Has Unspecified Impact
Samba Symlink Logic Error Lets Remote Users Access Arbitrary Files
Samba 'mount.cifs' Race Condition Lets Local Users Gain Elevated Privileges
Fetchmail Heap Overflow When Displaying SSL Certificates in Verbose Mode May Let Remote Users Execute Arbitrary Code
Novell NetStorage Unspecified Flaw Lets Remote Users Execute Arbitrary Code
HP System Management Homepage Input Validation Hole Permits Cross-Site Scripting Attacks
Microsoft Internet Explorer Discloses Known Files to Remote Users
Dana Epp's Weblog
Reflecting on our Windows 7 birthday party
Time to party! Windows 7 is here!
RunAs Radio podcasts you might want to listen to
Coding Tip: Why you should always use well known SIDs over usernames for security groups
Major Windows 7 gotcha you should know about that may block you from upgrading
Microsoft SDL bans mempcy()... next it will be zeros!!!!
Using TS RemoteApp as an attack vector
Is Twittering safe?
Come have Coffee and Code in Vancouver with me and Microsoft tomorrow
Choosing the right offset backup provider
Using Information Cards when using Microsoft services
Using Information Cards when using Microsoft services
HP proves they can design disaster-proof environments
Crack that encryption! (or his head)
Is UAC really broken in Windows 7? More importantly, does it make us less secure?
Cryptome
White House Security Corrective Actions
White House Security Review
Obama Yawns Lax Security
USA Indicts Cannon and Drotleff of Blackwater-XE
USA vs Umar Farouk Abdulmutallab
Islam4UK Files
Obama Orders Med Countermeasures for Bio Attack
USA vs Umar Farouk Abdulmutallab
EO 13526 Classified NatSec Information
Mailing Replica or Inert Explosive Devices
Holy Land Hells Angels Remain US Threat
Microsoft Bamboozles Network Solutions
Official Parking Placards Pose Threat
Martin Hellman on NSA and Joseph Meyer Letter
Tapping Computers by David Kahn
Silicon Security
ID cards: Seven years of missed deadlines and U-turns
Leaked report reveals billions in budget cuts for public sector IT
Photos: When hackers get together to do the world a favour
Why you must rein in your power users
Is losing a mobile device really such a big deal?
Trojan bank fraud gang sentenced
UK ID cards rollout hit by delay as launch date revealed
£500,000 fine coming for businesses that lose data?
Naked CIO: Is IT responsible for workers' output and errors?
Bletchley Park's World War Two codebreakers in their own words
Phishers set their sights on corporate accounts
'You're responsible for your own wi-fi security' say ISPs
'UK must up privacy safeguards following Phorm'
Hackers breach Guardian Jobs site
Video: 60-Second Pitch: End-point security
Netcraft
Most Reliable Hosting Company Sites in January 2010
January 2010 Web Server Survey
National Rail website affected by snow
Most Reliable Hosting Company Sites in December 2009
December 2009 Web Server Survey
Most Reliable Hosting Company Sites in November 2009
24 of the 100 top HTTPS sites now safe from TLS renegotiation attacks
November 2009 Web Server Survey
Most Reliable Hosting Company Sites in October 2009
Koala loses a little karma with Ubuntu.com
White House goes Open Source
GeoCities Closure sees Surge in Phishing
October 2009 Web Server Survey
Most Reliable Hosting Company Sites in September 2009
September 2009 Web Server Survey
Reuters - Tech/Internet
China plans online gambling crackdown
Iran's resistance keeps up cat-and-mouse web game
Disney, Google eye stake in China bus media firm
Internet prompts the publishing itch in over-60s
Barnes & Noble's Nook e-reader to hit stores
Amazon reshelves Macmillan titles but not e-books
NetEase suspends new user registration for hit game
China shuts down largest hacker training website
Amazon reshelves Macmillan titles but not e-books
"Demon Sheep" haunts Senate race in California
Facebook removes Microsoft banner ads from site
Publishers, Amazon in flux in e-book pricing fray
YouTube's Eun latest Google exec to join AOL
Justice Dept says Google books deal troubled
Macmillan still talking with Amazon, deal may come
InfoSec Writers
The Phishing Guide
Anatomy of an XSS Attack
Failed: Information Security and Data Protection in a Consumer Digital World
A Closer Look at Ethical Hacking and Hackers
Shedding Light on Quantum Cryptography
Securing a Virtual Environment
Investigating the SANS/CWE Top 25 Most Dangerous Programming Errors List
Hacking Tools & Techniques and How to Protect Your Network from Them
Computer Forensics: Breaking Down the 1’s and 0’s of Cyber Activity for Potential Evidence
Steps Involved in Exploiting a Buffer Overflow Vulnerability using a SEH Handler
Exploring Below the Surface of the GIFAR Iceberg
Anatomy of an XSS Attack
Failed: Information Security and Data Protection in a Consumer Digital World
A Closer Look at Ethical Hacking and Hackers
A Successful CIO: More Leadership, Less Technical Jargon
OSVD
This feed is no more! Please see osvdb.org for more info.
This feed is no more! Please see osvdb.org for more info.
Wireshark Checkpoint FW-1 Dissector Format String Flaw - Mon, 17 Jul 2006 10:03:49 EDT
VLC Media Player Ogg/Theora File Handling Plugin Format String - Wed, 20 Jun 2007 13:19:03 EDT
Wireshark MOUNT Dissector Memory Exhaustion DoS - Mon, 17 Jul 2006 10:03:49 EDT
Wireshark MQ Dissector Format String Flaw - Mon, 17 Jul 2006 10:03:49 EDT
Wireshark XML Dissector Format String Flaw - Mon, 17 Jul 2006 10:03:49 EDT
Wireshark NCP Dissector Unspecified Off-by-one - Mon, 17 Jul 2006 10:03:49 EDT
Wireshark NMAS Dissector Unspecified Off-by-one - Mon, 17 Jul 2006 10:03:49 EDT
Wireshark NDPS Dissector Unspecified Off-by-one - Mon, 17 Jul 2006 10:03:49 EDT
Wireshark NTP Dissector Format String Overflow - Mon, 17 Jul 2006 10:03:49 EDT
Wireshark SSH Dissector Infinite Loop DoS - Mon, 17 Jul 2006 10:03:49 EDT
WordPress BlixKrieg Theme s Variable XSS - Wed, 18 Jul 2007 17:21:44 EDT
WordPress Blixed Theme index.php s Variable XSS - Wed, 18 Jul 2007 17:07:12 EDT
Mbedthis AppWeb URL Protocol Format String - Sun, 29 Apr 2007 12:33:43 EDT
Microsoft Security
MS10-002 - Critical: Cumulative Security Update for Internet Explorer (978207)
MS10-001 - Critical: Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (972270)
MS09-069 - Important: Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)
MS09-070 - Important: Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726)
MS09-071 - Critical: Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)
MS09-072 - Critical: Cumulative Security Update for Internet Explorer (976325)
MS09-073 - Important: Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)
MS09-074 - Critical: Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183)
MS09-063 - Critical: Vulnerability in Web Services on Devices API Could Allow Remote Code Execution (973565)
MS09-064 - Critical: Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)
MS09-065 - Critical: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947)
MS09-066 - Important: Vulnerability in Active Directory Could Allow Denial of Service (973309)
MS09-067 - Important: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)
MS09-068 - Important: Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307)
MS09-050 - Critical: Vulnerabilities in SMBv2 Could Allow Remote Code Execution (975517)
CNet Security
Verizon temporarily blocks some 4chan sites
China breaks up Black Hawk hacking ring
Security software maker Vitamin D exits beta
Verizon blocked some 4chan sites
PCI compliance: What it is and why it matters (Q&A)
BlackBerry has spyware risk too, researcher says
New UI, features highlight McAfee 2010 suites
Mozilla yanks infected add-ons, warns users
BlackBerry has spyware risk too, researcher says
Mozilla yanks infected add-ons, warns users
Caught on tape: Pastry thief and a bad dog walker
Microsoft to patch 26 holes in Windows, Office
DOJ not pleased with latest Google Book agreement
Report: Google, NSA talk defense partnership
Billions to be spent on smart-grid cybersecurity
F-Secure Weblog
Black Hawk Down
Gmail Phish
worldrofwarcraft.com
Watch out for flower-show.org
Microsoft Updates and Vulnerabilities
New Facebook Home Page, Important New Privacy Setting
Using Google Images to Investigate Fraud
An Apple a Day
Texaco offers you a job for £8500 a month
Twittering Widgets
Is the lack of iPad Flash support for security?
Loose Tweets Sink Fleets
Facebook Mischief
Twitter as a Professional Tool
Alarm in show_ads.js
Schneier on Security
The Limits of Visual Inspection
More Details on the Chinese Attack Against Google
New Attack on Threefish
Friday Squid Blogging: Squid Cookie
Scaring the Senate Intelligence Committee
10 Cartoons about Airport Security
World's Largest Data Collector Teams Up With Word's Largest Data Collector
Security and Function Creep
Anonymity and the Internet
Online Credit/Debit Card Security Failure
More Movie Plot Terrorist Threats
Friday Squid Blogging: Harrowgate's 1886 Giant Squid
Deconfliction
Tracking your Browser Without Cookies
World Privacy Day and the Madrid Privacy Declaration
Kasperky Lab Weblog
On the way to better testing
Patch now: MS10-002
Search poisoning, again
Patch Tuesday - Jan 2010
Open season on tax-payers
Cybercriminals go shopping
Trojan.Sejweek: a new variant
All about Brittany on Twitter
Crime time
mwcollectd released
The 12 scams of Christmas
Facebook: money mule or credit card
Last minute shopping - keep safe!
Trojan-SMS.WinCE.Sej week
Where will real-time search take us?
Network World Fusion
An open letter to my public transit company
Malwarebytes' Anti-Malware Free
Banning illegal file-sharers could breach human rights
More evidence of value of security certification
More evidence of value of security certification
China closes hacker training site, arrests three members
ShmooCon: Inside FarmVille's Sinister Underbelly
ShmooCon: Your iPhone's Dirty Little Security Secret
ShmooCon: P2P Snoopers Know What's In Your Wallet
Symantec hit with class-action lawsuit over auto-renewals
Searches for news trends lead to malware
Friday Quiz: Google Versus Everybody
Is Chinese PC Hardware Safe and Secure?
You don't know tech: The InfoWorld news quiz
Malicious Firefox Add-ons Installed Trojans
SANS
When is a 0day not a 0day? Samba symlink bad default config, (Tue, Feb 9th)
Oracle has an unscheduled security alert and patch for CVE-2010-0073. The issue affects WebLogic Server and is remotely exploitable. Details and patch are here http://www.oracle.co m/technology/deploy/ security/alerts/aler t-cve-2010-0073.html , (Tue, Feb 9th)
When is a 0day not a 0day? Fake OpenSSh exploit, again. , (Mon, Feb 8th)
Mandiant Mtrends Report, (Sun, Feb 7th)
LANDesk Management Gateway Vulnerability, (Sat, Feb 6th)
WordPress iframe injection?, (Fri, Feb 5th)
Memory Analysis - time to move beyond XP, (Fri, Feb 5th)
New version of Andreas Schuster's Evtx Parser released http://computer.fore nsikblog.de/en/2010/ 02/evtx_parser_1_0_2 .html, (Sat, Feb 6th)
Oracle WebLogic Server Security Alert, (Sat, Feb 6th)
tweaked ISC layout. Please submit screen shot and browser details if things don't look right., (Sat, Feb 6th)
More MiFi Fun. Consistent Authentication Matters! http://appsecstreetf ighter.com, (Fri, Feb 5th)
Microsoft Patch Tuesday Pre-Release, (Thu, Feb 4th)
Dealing with User 2.0, (Thu, Feb 4th)
Information Disclosure Vulnerability in Internet Explorer, (Wed, Feb 3rd)
Anatomy of a Form Spam Campaign (in progress against isc.sans.org right now) https://blogs.sans.o rg/appsecstreetfight er/, (Wed, Feb 3rd)
2600
Off The Hook show for February 3, 2010
Off The Wall show for February 2, 2010
Off The Hook show for January 27, 2010
Off The Wall show for January 26, 2010
CALL FOR SPEAKERS FOR THE NEXT HOPE
THE NEXT HOPE PREREGISTRATION NOW OPEN
Off The Hook show for January 20, 2010
Off The Wall show for January 19, 2010
Off The Hook show for January 13, 2010
Off The Wall show for January 12, 2010
WINTER ISSUE OF 2600 RELEASED
Off The Hook show for January 6, 2010
Off The Wall show for January 5, 2010
Off The Hook show for December 30, 2009
Off The Wall show for December 29, 2009
CNet Security Blog
CNET News Daily Podcast: Blackberry hacked, 4chan blocked, iPad unwanted
Microsoft denies Windows 7 battery problem
Stay home, let Texas Robot attend that meeting
Next-generation 747 takes first air (photos)
Former Intel exec pleads guilty in Galleon case
Boeing's next-gen 747 takes first flight
TweetDeck gets a few tweaks
University worker accused of extorting student file sharers
Silicon: It's good for you, especially in beer
Twins learn of teen brother's death on Facebook
Bids are in for AOL's sale of ICQ--it's down to 'UN' of 4 buyers
Nook back on sale
Israeli gas stations to swap Better Place car batteries
The application is the new the operating system
Bungie plans 'one last hoorah' for Halo 2
SecuriTeam
Files2Links F2L-3000 SQL Injection Vulnerability
Publique! CMS and SQL Injection Vulnerabilities
LedgerSMB Multiple Vulnerabilities
Browser Fuzzer
HP-UX Running Apache Data Injection and DoS Vulnerability
Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability
Trango Broadband Wireless Rogue SU Authentication Bug
MIT krb5 KDC denial of service in cross-realm referral processing
Exposing HMS HICP Protocol and Intellicom NetBiterConfig.exe Remote Buffer Overflow
AproxEngine Multiple Vulnerabilities
FSpy - Linux Filesystem Activity Monitoring
QuickHeal Antivirus 2010 Local Privilege Escalation
VideoCache vccleaner Root Vulnerability
Family Connections Multiple Remote Vulnerabilities
HP-UX Running OpenSSL Unauthorized Data Injection and Denial of Service
Security Docs
SQL Injection Attack and Defense
Encryption Formula: In the True Light of Science
Writing syslog messages to MySQL
Configuration of IPS to improve Incident Response Time
Foundations of Cryptography
SQL Injection Attack and Defense
Encryption Formula: In the True Light of Science
Writing syslog messages to MySQL
Configuration of IPS to improve Incident Response Time
Foundations of Cryptography
SQL Injection Attack and Defense
Encryption Formula: In the True Light of Science
Writing syslog messages to MySQL
Configuration of IPS to improve Incident Response Time
Foundations of Cryptography
ZDNet - Security
China breaks up Black Hawk hacking ring
Security software maker Vitamin D exits beta
Verizon temporarily blocks some 4chan sites
PCI compliance: What it is and why it matters (Q&A)
New UI, features highlight McAfee 2010 suites
BlackBerry has spyware risk too, researcher says
Caught on tape: Pastry thief and a bad dog walker
Mozilla yanks infected add-ons, warns users
Billions to be spent on smart-grid cybersecurity
Air Force taps IBM for secure cloud
U.S. House passes cybersecurity research bill
Microsoft to patch 26 holes in Windows, Office
Report: Google, NSA talk defense partnership
Microsoft investigates new Internet Explorer flaw
Government warns of looming cyberthreats
Security Fix
Farewell 2009, and The Washington Post
Twitter.com hijacked by 'Iranian cyber army'
Hackers exploit Adobe Reader flaw via comic strip syndicate
Group IDs hotbeds of Conficker worm outbreaks
Hackers target unpatched Adobe Reader, Acrobat flaw
Check your Facebook 'privacy' settings now
Paper-based data breaches on the rise
Critical updates for Adobe Flash, Microsoft Windows
Security Fix author named 'cybercrime hero'
La. firm sues Capital One after losing thousands in online bank fraud
Phishers angling for Web site administrators
Apple issues security updates for Mac OS X
Bit.ly to scour shortened links for badness
Nastygram: CDC 'swine flu' vaccine scam
DC businessman loses thousands after clicking on wrong e-mail
eEye Advisories
Multiple Vulnerabilities In .FLAC File Format and Various Media Applications
CA BrightStor ARCserve Backup Server Arbitrary Pointer Dereference
VGX.DLL Compressed Content Heap Overflow Vulnerability
Windows Metafile AttemptWrite Heap Overflow
eEye Retina Wireless Scanner .RWS File Processing Memory Corruption
Multiple Vulnerabilities in CA ARCserve for Laptops and Desktops
BitDefender Online Scanner 8 Double Decode Heap Overflow
Multiple Vulnerabilities In .FLAC File Format and Various Media Applications
CA BrightStor ARCserve Backup Server Arbitrary Pointer Dereference
VGX.DLL Compressed Content Heap Overflow Vulnerability
Windows Metafile AttemptWrite Heap Overflow
Multiple Vulnerabilities in CA ARCserve for Laptops and Desktops
BitDefender Online Scanner 8 Double Decode Heap Overflow
Multiple Vulnerabilities In .FLAC File Format and Various Media Applications
CA BrightStor ARCserve Backup Server Arbitrary Pointer Dereference
iDefense Vulnerabilities
Real Networks RealPlayer Compressed GIF Handling Integer Overflow
RealNetworks RealPlayer CMediumBlockAllocato r Integer Overflow Vulnerability
RealNetworks RealPlayer 11 HTTP Chunked Encoding Integer Overflow Vulnerability
Adobe Reader and Acrobat JpxDecode Memory Corruption Vulnerability
Microsoft Windows Indeo32 Codec Parsing Heap Corruption Vulnerability
Microsoft WordPad Word97 Converter Integer Overflow Vulnerability
Microsoft Internet Explorer HTML Layout Engine Uninitialized Memory Vulnerability
Microsoft Excel FEATHEADER Record Memory Corruption Vulnerability
Microsoft Word FIB Processing Stack Buffer Overflow Vulnerability
Mozilla Firefox GIF Color Map Parsing Buffer Overflow Vulnerability
Microsoft Office Drawing Format Shape Properties Memory Corruption Vulnerability
Adobe Acrobat and Reader U3D File Invalid Array Index Vulnerability
Microsoft Windows GDI+ TIFF File Parsing Buffer Overflow Vulnerability
Adobe Acrobat and Reader Firefox Plugin Use After Free Vulnerability
IBM AIX rpc.cmsd Stack Buffer Overflow Vulnerability
MSRC Blog
February 2010 Bulletin Release Advance Notification
Security Advisory 980088 Released
January 2010 Out-of-Band Security Bulletin Webcast
Bulletin MS10-002 Released
Security Advisory 979682 Released
Advance Notification for Out-of-Band Bulletin Release
Security Advisory 979352 – Going out of Band
Advisory 979352 Update for Monday January 18
Further Insight into Security Advisory 979352 and the Threat Landscape
January Security Bulletin Webcast
Advisory 979352 Updated
Security Advisory 979352 Released
January 2010 Security Bulletin Release
January 2010 Bulletin Release Advance Notification
Results of Investigation into Holiday IIS Claim
milw0rm
Winplot (.wp2 File) Local Buffer Overflow Exploit
cP Creator 2.7.1 (Cookie tickets) Remote SQL Injection Exploit
CMScontrol 7.x (index.php id_menu) SQL Injection Vulnerability
ProdLer
Loggix Project
WX Guest Book 1.1.208 (SQL/XSS) Multiple Remote Vulnerabilities
Snort < 2.8.5 Unified1 Output Denial of Service Exploit
Joomla com_jinc (newsid) Blind SQL Injection Vulnerability
Joomla com_mytube (user_id) Blind SQL Injection Exploit
BigAnt Server
Joomla com_surveymanager (stype) SQL Injection Vulnerability
DDL CMS 1.0 Multiple Remote File Inclusion Vulnerabilities
Joomla com_jbudgetsmagic (bid) Remote SQL Injection Vulnerability
FSphp 0.2.1 Multiple Remote File Inclusion Vulnerabilities
Zainu (album_id) Remote SQL Injection Vulnerability
Infoworld - Zero Day
Taking down teen hackers
Crimeware-as-a-servi ce taking off
Start-up wins NSF grant, pitches new AV
Exploring the data security quandary
Outlook bleak for Phishing defeat
Core finds new CEO
Conference seeks to bridge risk, research
Clarke sharply criticizes Bush cyber-security plans
Research: IT security maturing, but misaligned
Tips on employee monitoring
Most sites still hack-able
Web attacks won't stop
Badware not pushing users offline
Researchers uncover 100 VoIP vulnerabilities
Innovation, regulation and research on tap at RSA 2008
Security Reason
Security Notes for MacOS X, Matlab, and J.
PHP 5.2.12 Released... unpatched
New Security Notes for: Thunderbird, Camino, Sunbird and Flock
New security notes for KDE, Opera, SeaMonkey and K-Meleon
Multiple BSD printf(1) and multiple dtoa/*printf(3) vulnerabilities
False Security Advisory from Mozilla
New vulnerabilities in libc:fts*(3)
libc:fts_*():multipl e vendors, Denial-of-service
PHP 5.2.9 safe_mode and open_basedir bypass
Multiple Vendors libc/gdtoa printf(3) Array Overrun
New vulnerabilities in PHP 5.3.0 / 5.2.10
glibc holes for years
PHP 5.2.9 safe_mode and open_basedir bypass
libc:fts_*():multipl e vendors, Denial-of-service
PHP 5.2.7 bug free
Out Law
Shopping sites improve legal compliance as consumers get more savvy, says OFT
Model clauses for overseas transfers of personal data updated
Cycling company wrong to suggest Olympian's endorsement, rules ad watchdog
Users run security risk by re-using banking passwords
Europe should adopt US behavioural advertising icon, and quick
Financial services firms given August deadline for publishing complaints data
Irrationality did not undermine TV menu ranking decision, finds Court of Appeal
UK could get icons on behavioural ads
HP ordered to pay £200m within two weeks in interim damages ruling
Police unit formed to take down websites suspected of breaking terror laws
Refusal to stop John Terry story was not a privacy law U-turn, says expert
Ruling gives companies time and certainty in public procurement disputes
How to appeal an ICO decision: new guidance published
EU's compromise telecoms regulator comes to life
EU and Asian nations conduct counterfeits raid on shipping containers
Heise Security
MOD scatters laptops like confetti
Vista's Integrity Levels, Part 1
Vista's Integrity Levels, Part 2
WDM Driver Test
Fuzzy ways of finding flaws
The year 2008 in a review through the crystal ball
Basic security for PHP software
Antivirus software as a malware gateway
Manipulated ATMs
Logging onto Windows networks without a password
Structure of the "Russian Business Network"
The HMRC data loss - the real implications
A second look at the Mac OS X Leopard firewall
Secure programming
Modern Hydra - the new tricks of spammers and phishers
HP Security Bloggers
On Web Application Scanner Comparisons...
Personal Health Information safety rules not being enforced
Law of Diminishing Returns - One Idea
Law of Diminishing Returns
Top Five Web Application Vulnerabilities 1/11/10 - 1/24/10
China, Google and Web Security
".htaccess" for the win! Stomp overaccesible folder vulns.
Top Five Web Application Vulnerabilities 12/15/09 - 1/10/10
Evolving Web Application Security - Q1, 2010 Edition
Top Five Web Application Vulnerabilities 12/1/09 - 12/14/09
National data breach notification bill passed in U.S. House
Top Five Web Application Vulnerabilities 11/09/09 - 11/30/09
SSLv3/TLS Renegotiation Stream Injection
SSLv3/TLS Renegotiation Stream Injection
Automated Security Testing - Can't I Just Point-n-Click? (Part 3)
Light Blue Touchpaper
New attacks on HMQV
The need for privacy ombudsmen
Why is 3-D Secure a single sign-on system?
Multichannel protocols against relay attacks
How online card security fails
How hard can it be to measure phishing?
Placebo bomb detectors
Encoding integers in the EMV protocol
Mobile Internet access data retention (not!)
Practical mobile Internet access traceability
Extending the requirements for traceability
The Real Hustler
Relay attack featured on Dutch TV
When is a leak not a leak ?
Facebook Tosses Graph Privacy into the Bin
ZDNet - Zero Day
Oracle rushes out patch for gaping server hole
Mozilla Firefox hit by malware add-ons
MS Patch Tuesday heads-up: 13 bulletins, 26 vulnerabilities
Does Blippy really pose a security risk?
Microsoft warns of new IE data-leakage vulnerability
Code execution holes in iPhone OS, iPod Touch
Report: 48% of 22 million scanned computers infected with malware
Bogus IQ test with destructive payload in the wild
A Special Offer From Our Sponsor
RealPlayer haunted by 11 critical vulnerabilities
Tor Project suffers hack attack
Microsoft confirms 17-year-old Windows vulnerability
Mozilla drops Firefox 3.6 with security goodies
Microsoft knew of IE zero-day flaw since last September
And the most popular password is...
Secure Works
News: Botnet Targets Web Sites With Junk SSL Connections (Slashdot)
News: Botnet Attack on CIA and Other Sites Failing (PC Magazine)
News: Cyberthieves are hiring, using online ads (Reuters)
Announcement: Hacker Attacks Targeting Healthcare Organizations Doubled in the 4th Quarter of 2009 according to SecureWorks' Data
News: China Closes Hacker Training Site (Information Week)
News: Get Paid to Install Malware (Technology Review)
News: Botnet Floods Major Websites With Fake SSL Connections (Dark Reading)
News: Attempted hacker attacks in healthcare on the rise (Healthcare IT News)
News: Hacker attacks on healthcare organizations double (Help Net Security)
News: Flaws In The 'Aurora' Attacks (Dark Reading)
News: Microsoft IE Emergency Patch Due Thursday (Information Week)
News: Cyber sleuth sees China's fingerprints on 'Aurora' attacks (The Register)
News: US analysis of Google attack code finds Chinese fingerprints (The Guardian)
News: Microsoft IE Patch for Zero-Day Vulnerability Coming Jan. 21 (eWeek)
News: Security Expert Confirms Chinese Fingerprints On Google Attacks Read more: http://www.itproport al.com/security/news /article/2010/1/21/s ecurity-expert-confi rms-chinese-fingerpr ints-google-attacks/ #ixzz0dGcBqfH5 (ProPortal)
Prevx
Windows Black Screen recap
Windows Black Screen Root Cause
Black Screen woes could affect millions on Windows 7, Vista and XP
Tdss rootkit silently owns the net
Well done Jacques Erasmus AKA UK Young IT Professional Of The Year 2009
Detecting and Removing the ZEUS Banking Trojan
Prevx is Hiring Mac OSX Developer - Maybe You ?
FTP Reloaded: My Website has been hacked!
A puzzle called SafeSys
Compromised FTP details being exploited by in the wild malware
MBR Rootkit reloaded
Prevx 3.0 - PCMag.com Editors' Choice
RSA 2009 Internet Banking Fraud and a boss with no silver bullets
RSA Conference 2009
RSA 2009 Banks, Government Agencies, Ecommerce and Large Enterprises share concerns about their organization's state of cyber insecurity
XSSed
New HSBC and Barclays bank XSS and open redirect bugs
Flash clickTAG parameter XSS. Banks, e-shops, Adobe and others vulnerable
Cross-site scripting flaw on Winbank's easypay.gr SSL site
Major Greek bank sites with SSL vulnerable to XSS and open redirects
Google SSL page vulnerable to XSS
Google Chrome universal XSS vulnerability, now fixed
XSS, Iframe injections and XMLHTTP post request errors on McAfee sites
Two critical XSS bugs on Barclays bank website
New critical XSS bug in Google's Orkut
Five Sun.com XSS flaws in the SSL user login page
Critical XSS bugs found today on Symantec.com, now fixed
17-year-old promoted his website on Twitter with harmless XSS worm
Critical XSS and directory traversal flaws on Ebay.co.uk website
Critical Memova-based webmail vulnerability put at risk more than 40 million webmail accounts
New critical XSS on Facebook fixed in record time due to ethical disclosure
SANS Computer Forensics
Internet Evidence Finder (IEF): interview with Jad Saliba of JADSoftware.com
Uncident Response
Digital Forensic Case Leads: Introductions
Twitter Weekly Updates for 2010-02-06
Case Leads: 20100205-001
Examining Windows Mobile Devices Using File System Forensic Tools
It’s the little things (Part One)
Which SANS Digital Forensic Course Should You Take?
Fun with FIFOs (Part II): Output Splitting
M-Trends: The Advanced Persistent Threat
Google Chrome Forensics
The Rights and Wrongs of the Google Hack
Using Image Offsets
SANS vLive SEC508 is offering a 25% tuition discount for the next 7 days!
GIAC Adds GCFA to The List of ANSI/ISO/IEC 17024 Accredited Credentials
ZDNet Zero Day
Oracle rushes out patch for gaping server hole
Mozilla Firefox hit by malware add-ons
MS Patch Tuesday heads-up: 13 bulletins, 26 vulnerabilities
Does Blippy really pose a security risk?
Microsoft warns of new IE data-leakage vulnerability
Code execution holes in iPhone OS, iPod Touch
Report: 48% of 22 million scanned computers infected with malware
Bogus IQ test with destructive payload in the wild
RealPlayer haunted by 11 critical vulnerabilities
Tor Project suffers hack attack
Microsoft confirms 17-year-old Windows vulnerability
Mozilla drops Firefox 3.6 with security goodies
Microsoft knew of IE zero-day flaw since last September
And the most popular password is...
Critical flaws haunt Adobe Shockwave Player
[On your next visit to this page only news items you have not viewed will be displayed - cookies required]
Last Updated: Tuesday, 9th February 2010 @ 09:00:11