MilitarySingles owned by remote file inclusion hole 

MilitarySingles owned by remote file inclusion hole

Site hacked, 170,000 unsalted passwords exposed.
Hacker hawks exploit in blue chip email system 

Hacker hawks exploit in blue chip email system

NASA implicated in exploit auction.
AusCERT2012: FreeBSD talks amateur bug hunting 

AusCERT2012: FreeBSD talks amateur bug hunting

Squashing bugs shouldn't just be left to the pros.
AusCERT2012: Fish and chip shops in hacker sights 

AusCERT2012: Fish and chip shops in hacker sights

Credit card info at risk in point-of-sale compromises.
Exploits greeting users at foreign policy, human rights sites 

Exploits greeting users at foreign policy, human rights sites

A host of websites, including the US-based Center for Defense Information, have been compromised with malicious code in order to target and infect visitors.
Adobe pulls pay-for-patch, issues fix 

Adobe pulls pay-for-patch, issues fix

Gaffe was a 'PR disaster'.
Apple shutters FileVault password hole 

Apple shutters FileVault password hole

Urges users to mop up logs.
151,000 domains attacked via dangerous PHP hole 

151,000 domains attacked via dangerous PHP hole

PHP Group issues fix for the second time.
Apple update fixes major flaws in iPhones, iPads 

Apple update fixes major flaws in iPhones, iPads

Hole remains in Apple desktop browser.
Mac FileVault passwords stored in clear text 

Mac FileVault passwords stored in clear text

Flawed update contained debug logs that trap passwords.
Microsoft patches three critical flaws 

Microsoft patches three critical flaws

Patches will send IT admins scrambling.
Dangerous Flash flaw plugged 

Dangerous Flash flaw plugged

'Object confusion' could lead to system hijacking.
PHP 'zero-day' hole found 

PHP 'zero-day' hole found

Bugged patch fails to fix flaw.
Chinese firm leaked RDP exploit code 

Chinese firm leaked RDP exploit code

Vulnerability sharing programs called into question.
Oracle issues workarounds for zero-day hole 

Oracle issues workarounds for zero-day hole

Company moves after public disclosure.
Splunk calls bug bunk 

Splunk calls bug bunk

No authentication allows attackers to upload malcode.
Microsoft squashes Hotmail hijack bug 

Microsoft squashes Hotmail hijack bug

Accounts cracked in 60 seconds.
Public sector orgs flunk OWASP Top 10 

Public sector orgs flunk OWASP Top 10

Research finds 84 per cent of web apps deemed unacceptable against security benchmarks.
Four-year old critical Oracle bug still alive 

Four-year old critical Oracle bug still alive

Patch ignored older installs.
Holes found in Rackspace, VPS.Net cloud services 

Holes found in Rackspace, VPS.Net cloud services

Weak implementations allow dirty data to be tapped.
Samsung TVs, Blu-ray vulnerable to eternal boot loop 

Samsung TVs, Blu-ray vulnerable to eternal boot loop

Not your typical remote control.
Bug reports fall, bounties exclude amateurs 

Bug reports fall, bounties exclude amateurs

Less critical flaws go unreported.
Oracle patches 88 vulnerabilities 

Oracle patches 88 vulnerabilities

Fixes for Sun, Solaris and MySQL.
Android concept app siphons sensitive data 

Android concept app siphons sensitive data

Application bypasses permissions to steal SD and app data.
Updates make Adobe patches a flash 

Updates make Adobe patches a flash

Released for Linux, Windows and OS X.
Mobile vulnerabilities top IBM report 

Mobile vulnerabilities top IBM report

Thousands of disclosures studied.
Five million machines potentially vulnerable to RDP exploit  

Five million machines potentially vulnerable to RDP exploit

Scan shows not just 'stupid users' are vulnerable.
Microsoft probes security partners for RDP leak   

Microsoft probes security partners for RDP leak

Trusted partners may have leaked exploit code.
Chrome cracked at Pwn2Own 

Chrome cracked at Pwn2Own

Google's browser first to fall at CanSecWest.
The six most dangerous infosec attacks 

The six most dangerous infosec attacks

And what's coming next.
Adobe and Google patch flaws 

Adobe and Google patch flaws

Dirty dozen high risk flaws fixed in Chrome.
Adobe patches Flash XXS hole  

Adobe patches Flash XXS hole

Update closes in the wild cross-site scripting vulnerability.
Google pays $381,000 in bug bounties 

Google pays $381,000 in bug bounties

Payments used to squash 1100 vulnerabilities since November 2010.
PcAnywhere code stolen, Symantec warns of exploits 

PcAnywhere code stolen, Symantec warns of exploits

Company recommends to stop using its product pending fixes.
McAfee patches spam relay flaw 

McAfee patches spam relay flaw

Customers find their email and IP addresses on blacklists.
Oracle patches 78 vulnerabilities 

Oracle patches 78 vulnerabilities

Sixteen products vulnerable to remote code execution.
US spy agency issues damage-controlling Android 

US spy agency issues damage-controlling Android

NSA's SEAndroid too tough for GingerBreak, RageAgainstTheCage.
ANZ botches bank statement fix 

ANZ botches bank statement fix

Shuts down online statements service within 24 hours.
Six OpenSSL holes plugged 

Six OpenSSL holes plugged

Padding Oracle Attack squashed.
Qualys, MetricStream build vulnerability framework 

Qualys, MetricStream build vulnerability framework

Routes vulnerabilities through investigation and remediation processes.
Microsoft preps seven security patches 

Microsoft preps seven security patches

Includes one 'critical' fix.
ASP.NET hole workaround published 

ASP.NET hole workaround published

One crafted ~100kb HTTP request can consume 100 percent of a CPU core.
Analysis: HTML5 security holes detailed 

Analysis: HTML5 security holes detailed

Security shortfalls in burgeoning standard.
Android app installs shell, bypasses permissions  

Android app installs shell, bypasses permissions

App silently taps data.
99 MS critical bug fixes lowest on record 

99 MS critical bug fixes lowest on record

Redmond says it hardened up.
Aussie exploit challenges for noob to leet 

Aussie exploit challenges for noob to leet

Learn to beat Linux non-executable memory, ASLR, and stack smashing protection.
Yahoo IM zero day patched 

Yahoo IM zero day patched

Status messages hijacked.
HP printer bug sparks law suit 

HP printer bug sparks law suit

A New York man has started a class action suit over a printer exploit said to be capable of starting fires.
"Significant" holes found in Droid X, Evo 4G, Wildfire S 

"Significant" holes found in Droid X, Evo 4G, Wildfire S

Android phone apps create potential backdoors to user data.
Java exploit added to Metasploit 

Java exploit added to Metasploit

Microsoft says up to half of all exploits are Java based.
1 2 3 4 | Next »
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read