LAS VEGAS, NEV. — Roughly 85 percent of Fortune 500 companies have patched their networks to fix a security flaw that lets cyber criminals redirect visitors to counterfeit or malicious Web sites, but Internet users still remain at grave risk due to the large number of infrastructure providers that have not yet addressed the issue, a prominent security researcher warned today. The data comes from a talk presented here at the Black Hat security conference in Las Vegas by Dan Kaminsky, the Seattle based IOActive researcher who discovered a fairly trivial way that bad guys could corrupt records found in the domain name system (DNS) and fill them with inaccurate information. On July 8, Microsoft, Cisco, Sun Microsystems and dozens of other Internet companies shipped software updates to fix this fundamental design in DNS, the communications standard that acts as a kind of phone book for the Internet, translating human-friendly