The Web Hacking Incidents Database (http://whid.webappsec.org), or WHID for short, is a Web Application Security Consortium (http://www.webappsec.org) project dedicated to maintaining a list of web applications related security incidents. WHID goal is to serve as a tool for raising awareness of the web application security problem and provide information for statistical analysis of web applications security incidents. The last week was very rich in Web Hacking Incidents. Too rich. The following incidents where added to WHID last week: * WHID 2009-26: F-Secure Joins The Breached AV Vendors Club http://whid.webappsec.org/whid/2009/26/f-secure_breached * WHID 2009-20: BitDefender joins Kasperski on the Breached side http://whid.webappsec.org/whid/2009/20/bitdefender_joins_kasperski The duo join Kasperski which was breached last week. * WHID 2009-25: Zone-H defaced http://whid.webappsec.org/whid/2009/25/zone-h_defaced The defacements archive site got defaced itself. * WHID 2009-24: New Phishing Attacks Combine Wildcard DNS and XSS http://whid.webappsec.org/whid/2009/24/phishing_combine_dns_xss A new blended attack threat interesting for the techies among us * WHID 2009-23: Miley Cyrus Twitter Account Hit By Sex-Obsessed Hacker http://whid.webappsec.org/whid/2009/23/miley_cyrus_twitter_hacked Twitter again. A Celebrity Again. * WHID 2009-22: Federal Travel Booking Site Spreads Malware http://whid.webappsec.org/whid/2009/22/fed_travel_site_spreads_malware One of the more serious iframe planting cases recently * WHID 2009-21: This Time Uno is after the Herald Tribute http://whid.webappsec.org/whid/2009/21/uno_is_after_the_tribute ~ Ofer Ofer Shezaf [shezaf@xiom.com, +972-54-4431119, www.xiom.com] Founder, Xiom.com, Proactive Web Application Security, http://www.xiom.com Leader, WASC Web Hacking Incidents Database Project Chairman, OWASP Israel