Hackers claim exploit cache in raid 

Hackers claim exploit cache in raid

Rival vulnerability service hacked.
Microsoft, Adobe patch a range of vulnerabilities 

Microsoft, Adobe patch a range of vulnerabilities

Exploits could emerge over holiday break.
Attackers can read USB storage attached to Samsung TVs  

Attackers can read USB storage attached to Samsung TVs

Remote attackers get root on smart TVs.
Adobe Reader zero-day selling on criminal underground 

Adobe Reader zero-day selling on criminal underground

Company launches investigation.
Older Symantec AVs open to remote code execution  

Older Symantec AVs open to remote code execution

No update planned for affected scan engine.
Co-lo VMs busted by crypto attack 

Co-lo VMs busted by crypto attack

Side-channel cache-sniffers steal keys.
Safari, iOS 6 flaws patched 

Safari, iOS 6 flaws patched

Apple has fixed two critical vulnerabilities.
Thousands scammed by .gov open redirect flaw 

Thousands scammed by .gov open redirect flaw

20,000 victims follow malicious shortened URLs.
HP suppresses ToorCon router bug reveal  

HP suppresses ToorCon router bug reveal

Major holes found in Huawei and H3C routers.
Microsoft engineer crafts exploitability index tool  

Microsoft engineer crafts exploitability index tool

Curbs vulnerability hype.
Surprise patch party as Adobe, Microsoft issue fixes 

Surprise patch party as Adobe, Microsoft issue fixes

Flash fixes
Teenager cracks Chrome again 

Teenager cracks Chrome again

Full exploit earns teen a cool US$60,000.
Tool sniffs vulnerable sites flagged by McAfee, Trust Guard 

Tool sniffs vulnerable sites flagged by McAfee, Trust Guard

Website security badges an invitation for hackers.
Microsoft critical patch hours away  

Microsoft critical patch hours away

Updates to arrive 3AM Saturday.
Internet Explorer zero day found 

Internet Explorer zero day found

Internet Explorer 10 safe.
Phonetic attack commands crash bank phone lines 

Phonetic attack commands crash bank phone lines

Touch tone and voice activated systems open to attack.
Etsy joins bug bounty crew 

Etsy joins bug bounty crew

Offers $500 minimum, a t-shirt and a high-five.
Java exploit on the loose, unofficial patch issued 

Java exploit on the loose, unofficial patch issued

Experts say attacks may become more widespread.
US warns of hole in control system routers 

US warns of hole in control system routers

Power plants, railway switches at risk.
Adobe releases second Flash patch in a week 

Adobe releases second Flash patch in a week

Critical fix covers six vulnerabilities.
Paydirt: Vulnerabilities found to foil popular DDoS toolkit 

Paydirt: Vulnerabilities found to foil popular DDoS toolkit

Buggy code lets victims stop attacks.
Google boosts bug bounty  

Google boosts bug bounty

Cash prizes double.
Adobe misses serious bugs in Reader 

Adobe misses serious bugs in Reader

Vulnerabilities detailed in Windows, Mac and Linux
Microsoft to shutter a 'hacker's playground' of bugs 

Microsoft to shutter a 'hacker's playground' of bugs

Patch Tuesday to offer nine patches for 10 vulnerabilities.
Patched Windows bug wreaks havoc 

Patched Windows bug wreaks havoc

Vulnerability used to target political, industrial and defense organisations.
Payroll admins targeted by dangerous Java exploit 

Payroll admins targeted by dangerous Java exploit

Attacks against recent Java runtime hole spike.
NVIDIA privilege escalation flaw disclosed  

NVIDIA privilege escalation flaw disclosed

Red Hat engineer says vendor ignored bug report.
#BlackHat: Phones hijacked by malicious NFC tag 

#BlackHat: Phones hijacked by malicious NFC tag

Android, Nokia compromised.
#BlackHat: Supressed smart meter vulnerability tool is unleashed 

#BlackHat: Supressed smart meter vulnerability tool is unleashed

Allows for wireless access to meters.
Anonymous to release 40GB cache from hacked ISP 

Anonymous to release 40GB cache from hacked ISP

Victim said to be among Australia's largest telcos.
Skype fixes leaky instant message bug 

Skype fixes leaky instant message bug

But not for Mac.
Black Hat's guide to what's hot at the con 

Black Hat's guide to what's hot at the con

More than 500 talks culled to 80.
Plesk zero-day may be behind thousands of hacked sites 

Plesk zero-day may be behind thousands of hacked sites

Company works on fix.
NetGear routers rooted by SQLi 

NetGear routers rooted by SQLi

Don't overlook the simple stuff.
Microsoft still bucks bug bounty trend 

Microsoft still bucks bug bounty trend

Redmond says BlueHat is better.
Provider cuts smart meter vulnerabilities in half  

Provider cuts smart meter vulnerabilities in half

Avoids patch cost blow-outs.
Booby-trapped playlist pwns iTunes 

Booby-trapped playlist pwns iTunes

Apple patches buffer overflow hole.
Virtualisation holes detailed on multiple platforms 

Virtualisation holes detailed on multiple platforms

Local privileged escalation, virtual machine escapes possible.
Microsoft patches second RDP hole, IE bugs 

Microsoft patches second RDP hole, IE bugs

Baker's dozen of flaws found in Internet Explorer.
Critical hole fixed in Rails 

Critical hole fixed in Rails

Users urged to patch, upgrade.
Denial of service found in iOS 5.1.1 

Denial of service found in iOS 5.1.1

Crashes updated iPads, iPhones.
Adobe pulls pay-for-patch, issues fix 

Adobe pulls pay-for-patch, issues fix

Gaffe was a 'PR disaster'.
Apple shutters FileVault password hole 

Apple shutters FileVault password hole

Urges users to mop up logs.
151,000 domains attacked via dangerous PHP hole 

151,000 domains attacked via dangerous PHP hole

PHP Group issues fix for the second time.
Apple update fixes major flaws in iPhones, iPads 

Apple update fixes major flaws in iPhones, iPads

Hole remains in Apple desktop browser.
Microsoft patches three critical flaws 

Microsoft patches three critical flaws

Patches will send IT admins scrambling.
Dangerous Flash flaw plugged 

Dangerous Flash flaw plugged

'Object confusion' could lead to system hijacking.
PHP 'zero-day' hole found 

PHP 'zero-day' hole found

Bugged patch fails to fix flaw.
Chinese firm leaked RDP exploit code 

Chinese firm leaked RDP exploit code

Vulnerability sharing programs called into question.
Oracle issues workarounds for zero-day hole 

Oracle issues workarounds for zero-day hole

Company moves after public disclosure.
1 2 | Next »
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read