Internet service providers that serve advertising when a user requests a Web page that doesn't exist are exposing their users to a giant security breach, according to security researcher Dan Kaminsky. The vulnerability resulting from the practice, which is an increasingly common way for ISPs to make money from users' typos, was identified last week on Earthlink by Kaminsky, who is director of penetration testing for security firm IOActive. Kaminsky presented his findings at the Toorcon hacker conference on Saturday.