Splunk calls bug bunk 

Splunk calls bug bunk

No authentication allows attackers to upload malcode.
Bug means iPhone thieves get iMessages, too 

Bug means iPhone thieves get iMessages, too

iMessages relayed to strangers' iPhones.
Microsoft scrambles to address widespread ASP.NET bug 

Microsoft scrambles to address widespread ASP.NET bug

Bug impacts entire .Net framework.
Google bug bounty tops $100,000 in first year 

Google bug bounty tops $100,000 in first year

Google pays out $US14,000 for flaws found in Chrome
Facebook updates bug disclosure policy 

Facebook updates bug disclosure policy

Disclosure less likely to result in lawsuit.
Get bug hunting: Mozilla extends bounty to apps 

Get bug hunting: Mozilla extends bounty to apps

Firefox developer will now pay out for vulnerabilities found in some web applications.
Google's cash-for-bugs: We've been generous 

Google's cash-for-bugs: We've been generous

US$20,000 awarded so far.
New Internet Explorer bug found in the wild 

New Internet Explorer bug found in the wild

Fake hotel confirmation used.
Google extends bug bounties to YouTube, Blogger 

Google extends bug bounties to YouTube, Blogger

Finds could be worth thousands.
Microsoft fixes another Stuxnet-related bug, 10 others 

Microsoft fixes another Stuxnet-related bug, 10 others

Three labeled "critical" and five "important".
Facebook fixes privacy bug 

Facebook fixes privacy bug

Flaw existed for unknown length of time.
ZDI bug bounty program imposes fix deadline for vendors  

ZDI bug bounty program imposes fix deadline for vendors

31 high-risk vulnerabilities on waiting list.
Microsoft announces "coordinated" plan for bug reporting 

Microsoft announces "coordinated" plan for bug reporting

Attempts to reframe the debate around vulnerability disclosure.
Twitter bug lets users force new followers 

Twitter bug lets users force new followers

Company racing to fix flaw and roll back changes.
Internode finds bug in Ericsson DSLAMs 

Internode finds bug in Ericsson DSLAMs

Other ISPs upgrade to avoid problems.
Facebook bug exposes private emails 

Facebook bug exposes private emails

Addresses were visible for up to 30 minutes.
Mozilla promises March 30 fix for critical Firefox bug 

Mozilla promises March 30 fix for critical Firefox bug

As German government advises residents not to use the web browser.
Microsoft responds to Black Hat talk with IE bug advisory 

Microsoft responds to Black Hat talk with IE bug advisory

View state flaw revealed.
App bug in new Facebook dashboard 

App bug in new Facebook dashboard

More problems for social networking giant.
SpamAssassin bug leads to blocking of legitimate emails 

SpamAssassin bug leads to blocking of legitimate emails

False positive rate lifted dramatically.
Snow Leopard users complain about deletion of files 

Snow Leopard users complain about deletion of files

Documents, photos and music lost.
Twitter among web apps affected by patched XSS bug 

Twitter among web apps affected by patched XSS bug

Flaw lies in "escaping code".
Microsoft disputes password-stealing SQL Server bug 

Microsoft disputes password-stealing SQL Server bug

No need for an update, says Microsoft.
Twitter XSS vulnerability not yet fixed 

Twitter XSS vulnerability not yet fixed

Claims patch doesn't work.
SMS bug can disable iPhone usage: Black Hat 

SMS bug can disable iPhone usage: Black Hat

One single malicious text message can knock an iPhone offline, a pair of researchers disclosed at Black Hat.
Mozilla upgrades Firefox 3.5 to fix bug 

Mozilla upgrades Firefox 3.5 to fix bug

Known flaw in the browser's Just-in-time JavaScript compiler.
Security bug found in latest version of Firefox 

Security bug found in latest version of Firefox

An unpatched vulnerability in version 3.5 of Firefox, which was released last month, could enable a hacker to remotely run arbitrary code on users' machines, security firm ...
Another ActiveX zero-day bug from Microsoft 

Another ActiveX zero-day bug from Microsoft

Microsoft is trying to combat another ActiveX vulnerability being actively exploited -- the second in a week.
Source of Adobe zero-day bug patched 

Source of Adobe zero-day bug patched

One of the flaws at the heart of Adobe's ColdFusion 8.0.1 zero-day vulnerability has been patched.
Apple patches QuickTime for 10 security holes 

Apple patches QuickTime for 10 security holes

Apple has released an updated version of its popular QuickTime software.
First Windows 7 bug discovered 

First Windows 7 bug discovered

Microsoft is warning customers downloading the Release Candidate of its long-awaited Windows 7 operating system that its first bug has been detected, potentially causing ...
Apple's iPhone may be vulnerable to shellcode 

Apple's iPhone may be vulnerable to shellcode

A possible bug has been identified in Apple's iPhone, according to reports.
Apple posts iTunes 8.1 update, fixes bug 

Apple posts iTunes 8.1 update, fixes bug

Apple has released an updated version of its iTunes media player application, adding an extra layer of security.
Microsoft Windows Server RPC bug finds new way to spread 

Microsoft Windows Server RPC bug finds new way to spread

Exploits taking advantage of a Windows Server Service vulnerability still are running rampant, nearly 1-1/2 months after Microsoft delivered an emergency fix, according to ...
Microsoft readies emergency fix for Internet Explorer bug 

Microsoft readies emergency fix for Internet Explorer bug

Microsoft announced on Tuesday that it will issue an emergency fix on Wednesday for a dangerous zero-day vulnerability in Internet Explorer.
FBI warns of vishing threat due to software bug 

FBI warns of vishing threat due to software bug

The FBI is warning of a vulnerability in an open-source toolkit used to make VoIP calls.
Microsoft serves up out-of-cycle patch for Windows bug 

Microsoft serves up out-of-cycle patch for Windows bug

As it turns out, Microsoft's emergency fix plugs a previously unknown Windows vulnerability that was being exploited in limited attacks.
Microsoft looks into Visual Studio bug 

Microsoft looks into Visual Studio bug

Microsoft is investigating a zero-day vulnerability in Visual Studio.
Microsoft to release 12 patches 

Microsoft to release 12 patches

Microsoft plans 12 fixes - seven for "critical" bugs - in next week's monthly patch delivery.
Bug exposed in web security standard 

Bug exposed in web security standard

VBAAC flaw in the standard web authorisation technology could affect hundreds of thousands of sites, security experts have warned.
Proof-of-concept revealed for Safari for Windows bug 

Proof-of-concept revealed for Safari for Windows bug

A security researcher has published proof-of-concept code for the blended Internet Explorer-Safari for Windows threat.
Exploits target new Adobe Flash bug 

Exploits target new Adobe Flash bug

Symantec on Tuesday revealed that the latest version of the Adobe Flash Player contains an unpatched vulnerability that is being actively exploited.
BitDefender issues fix for IE7 printing bug 

BitDefender issues fix for IE7 printing bug

Vulnerability in the way IE7 parses web pages for printing.
OpenSSL bug found in Debian Linux 

OpenSSL bug found in Debian Linux

Debian Linux got a bit of a black eye this week with the announcement that a nasty cryptographic vulnerability exists in its version of the OpenSSL package.
Another Apple QuickTime bug reported 

Another Apple QuickTime bug reported

US-CERT has issued an alert concerning a new zero-day vulnerability in the Apple QuickTime media player.
Microsoft patches Excel zero-day bug, three other flaws 

Microsoft patches Excel zero-day bug, three other flaws

Microsoft issued four "critical" patches, including one for the zero-day Excel vulnerability reported in January, in its March Patch Tuesday round of bug fixes. In all, the ...
Mozilla patches QuickTime bug in Firefox 

Mozilla patches QuickTime bug in Firefox

Mozilla released an updated version of its browser on Tuesday to correct a critical QuickTime security vulnerability for which proof-of-concept code was available.
McAfee warns of Yahoo Messenger Webcam bug 

McAfee warns of Yahoo Messenger Webcam bug

Users of Yahoo's instant messaging platform are being warned to avoid webcam invites from unknown sources after a vulnerability in the platform was disclosed this week.
Secunia says Firefox URI handling bug is also a Microsoft issue 

Secunia says Firefox URI handling bug is also a Microsoft issue

Secunia blamed Microsoft this week for a URI handling flaw that can be exploited when a user browses with Firefox but has Internet Explorer (IE) 7 installed.
LinkedIn fixes critical bug 

LinkedIn fixes critical bug

Business networking site LinkedIn has remedied a dangerous zero-day vulnerability in its Internet Explorer toolbar, one day after researchers went public with the exploit code.
1 2 | Next »
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read