Fresh Java exploit has ties to Bit9 attack 

Fresh Java exploit has ties to Bit9 attack

Pings the same command and control server.
More than 100 e-commerce sites vulnerable to shopping cart flaw 

More than 100 e-commerce sites vulnerable to shopping cart flaw

Lack of patching leaves companies exposed.
Security bug keeps ICANN gTLD grounded 

Security bug keeps ICANN gTLD grounded

Applicant filenames exposed.
Wicked exploit found in Linux WiFi 

Wicked exploit found in Linux WiFi

Anonymous student hacker finds holes in WICD tool.
RDP proof of concept triggers blue screen of death 

RDP proof of concept triggers blue screen of death

Proof of concept kills Windows machines.
Hackers post bounty for RDP exploit 

Hackers post bounty for RDP exploit

HD Moore chips in for Metasploit module.
RDP flaw a harbinger of breaches  

RDP flaw a harbinger of breaches

Small businesses most at risk from dangerous vulnerability.
Flaw lets crooks rob Google Wallets 

Flaw lets crooks rob Google Wallets

Google kills Android app "as a precaution".
Bug means iPhone thieves get iMessages, too 

Bug means iPhone thieves get iMessages, too

iMessages relayed to strangers' iPhones.
Thousands of WordPress sites sucked into BlackHole 

Thousands of WordPress sites sucked into BlackHole

Exploits aging TimThumb vulnerability.
Researcher discloses vulnerability to firm, gets police visit 

Researcher discloses vulnerability to firm, gets police visit

Millions exposed by super hole.
OpenSSH released, plays in sandbox 

OpenSSH released, plays in sandbox

Pre-auth attacks are dead.
Microsoft will pay $186k to fix memory holes 

Microsoft will pay $186k to fix memory holes

Prefers 'defensive tech' over vulnerability bounty-hunting.
Video details Android browser intercept flaw 

Video details Android browser intercept flaw

Users must wait for Frozen Yoghurt fix.
Zero day found in popular tool used by Word Press 

Zero day found in popular tool used by Word Press

Hacking victim releases temporary fix.
Microsoft preps 16 patches, one for cookiejacking 

Microsoft preps 16 patches, one for cookiejacking

Microsoft plays down risk of cookiejacking.
Smartcards reduce APT exposure, vendor claims 

Smartcards reduce APT exposure, vendor claims

Smartcards can be used to mitigate an advanced persistent threat (APT) due to the security of the physical card.
Adobe patches Flash hole 

Adobe patches Flash hole

Adobe unsure if Acrobat, Reader are vulnerable.
LinkedIn profiles at hijack risk 

LinkedIn profiles at hijack risk

Even changing your password won't protect you.
Standardised vulnerability reports to hit this year 

Standardised vulnerability reports to hit this year

Finding relevant details in security vulnerability reports can be a minefield.
Apple pushes a vulnerable Opera browser 

Apple pushes a vulnerable Opera browser

Apple users might ditch the App Store and go it alone, experts say.
Android identity hole fixed 

Android identity hole fixed

Android users are set to receive an automatic patch for an authentication hole discovered in February.
 NZ researchers find SCADA holes 

NZ researchers find SCADA holes

The US Cyber Emergency Response Team has warned of a critical vulnerability in two popular SCADA systems, found by security-assessment.com.
Skype buy heralds wiretaps, Linux death 

Skype buy heralds wiretaps, Linux death

And will the buy be the death of cross-platform video conferencing?
Skype asks Mac users to patch exploit 

Skype asks Mac users to patch exploit

Aussie exploit scares Skype
iPhones, iPads secretly collecting user location data 

iPhones, iPads secretly collecting user location data

Device spies ripe pickings for jealous spouses, police, thieves.
Microsoft to publish third-party bugs 

Microsoft to publish third-party bugs

Coordinated vulnerability disclosure system will take some bugs public.
Cisco sends NSS Labs another firewall 

Cisco sends NSS Labs another firewall

Challenges it to replicate test results.
Epsilon corporate victim list swells 

Epsilon corporate victim list swells

More victims emerge, battered.
Hacker takes off with TripAdvisor's customer email database  

Hacker takes off with TripAdvisor's customer email database

Personal details for as many as 20 million travellers in the wind.
IE9 a 'non-event' for most businesses 

IE9 a 'non-event' for most businesses

No Windows XP compatibility.
Adobe finds Flash flaw in Excel docs 

Adobe finds Flash flaw in Excel docs

Patch due on Monday.
Google patches WebKit flaw after Pwn2Own contest 

Google patches WebKit flaw after Pwn2Own contest

Rewards hack team.
Pulse 2011: Businesses must tackle growing mobile threat 

Pulse 2011: Businesses must tackle growing mobile threat

Mobile security threats have grown exponentially in recent years and organisations must ensure policies are in place to stave off attacks, according to IBM.
Microsoft downplays Windows vulnerability 

Microsoft downplays Windows vulnerability

Microsoft says a vulnerability could allow remote code execution, but it's not likely anyone will be able to do it.
Cyber war needs ‘rules of engagement’ 

Cyber war needs ‘rules of engagement’

Civilising internet conflicts.
Microsoft's monthly update to include two 0-day fixes 

Microsoft's monthly update to include two 0-day fixes

Microsoft will next week push out 12 patches to close 22 vulnerabilities.
Could a vulnerability tax work? 

Could a vulnerability tax work?

The new Apple security chief believes a vulnerability tax could really help make software safer. Could it work?
Apple security chief calls for vulnerability tax 

Apple security chief calls for vulnerability tax

Could it work?
Mac OS X update fixes over 130 vulnerabilities 

Mac OS X update fixes over 130 vulnerabilities

Mac looking more vulnerable over time.
Vulnerability disclosure gap causes cyber crime opportunity: Lumension 

Vulnerability disclosure gap causes cyber crime opportunity: Lumension

CTO calls for vendors to cooperate on patch releases.
Apple tops public vulnerability list 

Apple tops public vulnerability list

Trend Micro Threat Report shows Apple has more public flaws than Microsoft or Adobe.
Google-owned social network sees 400,000 users hit by XSS attack 

Google-owned social network sees 400,000 users hit by XSS attack

Attack on Orkut required no user interaction.
Vic highschooler sparks Twitter’s onMouseOver woes 

Vic highschooler sparks Twitter’s onMouseOver woes

Javascript command used to distribute malware.
Adobe confirms existence of new zero-day in Flash Player 

Adobe confirms existence of new zero-day in Flash Player

Patches planned for the next few weeks.
Twitter fixes cross-site scripting vulnerability 

Twitter fixes cross-site scripting vulnerability

Exploit stole a user's cookie to distribute compromised links.
'Old-new' Windows vulnerability discovered 

'Old-new' Windows vulnerability discovered

200 apps possibly affected.
Microsoft classifies Win32k.sys vulnerability as a low grade threat 

Microsoft classifies Win32k.sys vulnerability as a low grade threat

No plans for an out-of-band patch.
Sophos unveils tool to cover Windows zero-day vulnerability  

Sophos unveils tool to cover Windows zero-day vulnerability

As industry waits for a patch.
Cisco warns of vulnerability in CDS 

Cisco warns of vulnerability in CDS

Internet Streamer flaw leaves data at risk.
1 2 3 4 | Next »
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read