Scores of vulnerable SAP deployments uncovered 

Scores of vulnerable SAP deployments uncovered

Scan finds critical systems unpatched, facing the public web.
Java closes 40 vulns 

Java closes 40 vulns

Remotely exploitable.
Spear phish exploits Office vulns 

Spear phish exploits Office vulns

Users in India, Vietnam targeted.
Plesk exploit gives Apache privilege escalation edge  

Plesk exploit gives Apache privilege escalation edge

Kingcope dropped exploit code.
Google dev drops Windows kernel exploit 

Google dev drops Windows kernel exploit

Leads to privilege escalation.
Attack campaign targeting old Word flaws 

Attack campaign targeting old Word flaws

Makes for good phishing.
Oracle details Java security facelift 

Oracle details Java security facelift

Applets signing alerted.
Google: Respond in a week to vulnerabilities 

Google: Respond in a week to vulnerabilities

Comes three years after Google requested a 60 day response.
Secunia accidentally drops zero-day on public mailing list 

Secunia accidentally drops zero-day on public mailing list

Autocomplete error.
Ruby on Rails exploit builds IRC bot 

Ruby on Rails exploit builds IRC bot

Bot open for hijack.
QuickTime dirty dozen flaws closed 

QuickTime dirty dozen flaws closed

Apple pushes update.
Thirteen flaws fixed in Firefox 

Thirteen flaws fixed in Firefox

Gets health report feature.
Microsoft patches 33 flaws, including Internet Explorer 8 zero-day 

Microsoft patches 33 flaws, including Internet Explorer 8 zero-day

Fix blocks drive-by download attacks.
A million drivers licenses possibly stolen via ColdFusion hole 

A million drivers licenses possibly stolen via ColdFusion hole

US courts office popped.
Microsoft readies patch for IE zero day 

Microsoft readies patch for IE zero day

Patch Tuesday to close 33 vulnerabilities.
Researchers gain root to Google Australia's office system 

Researchers gain root to Google Australia's office system

Management system unpatched.
Adobe confirms PDF tracking issue, plans to ship fix soon 

Adobe confirms PDF tracking issue, plans to ship fix soon

McAfee says the security vulnerability could be used in advanced attacks.
HP launches vulnerability inspection tool 

HP launches vulnerability inspection tool

WebInspect updated.
ColdFusion zero day used in web host hack 

ColdFusion zero day used in web host hack

Hole patched.
42 fixes released in Java update  

42 fixes released in Java update

Risky apps flagged.
Microsoft fixes three critical flaws 

Microsoft fixes three critical flaws

Remote code execution in Internet Explorer.
Sophos' flagship web security product open to attack 

Sophos' flagship web security product open to attack

Upgrade urged.
Blackhat pen test service opens 

Blackhat pen test service opens

PHP bugs zapped.
Chrome; Firefox; IE 10; Java; Win 8 fall at #pwn2own hackfest 

Chrome; Firefox; IE 10; Java; Win 8 fall at #pwn2own hackfest

Vupen develops new ASLR and DEP bypass technique.
Popular apps riddled with flaws 

Popular apps riddled with flaws

Authentication bypass, SQLi and clear text data.
Yahoo! updates four-year-old Java download 

Yahoo! updates four-year-old Java download

Bundled with small business website builder.
Microsoft patches squash 13 IE vulns 

Microsoft patches squash 13 IE vulns

Flaws could allow remote code execution.
Spammers stole Yahoo Xtra contact lists: exec 

Spammers stole Yahoo Xtra contact lists: exec

Users smashed.
Mega security bugs detailed 

Mega security bugs detailed

Serious bugs found.
Microsoft to patch 57 holes 

Microsoft to patch 57 holes

Internet Explorer bugs affect all platforms.
Oracle issues megapatch to fix 50 holes 

Oracle issues megapatch to fix 50 holes

Fixes brought forward.
Five eyes push to declassify security vulnerability data 

Five eyes push to declassify security vulnerability data

Security pundits push for Australian and allied agencies to release threat information to industry.
Oracle says Java security, communications improvements in pipeline 

Oracle says Java security, communications improvements in pipeline

Java in the browser under the scope.
Barracuda appliances contain backdoors 

Barracuda appliances contain backdoors

Spam and Virus Firewall, Web Application Firewall, Web Filter and SSL VPN.
HP software bug makes printers pwned 

HP software bug makes printers pwned

Printing jobs nicked, machines bricked.
60% of exploits target two-year old bugs 

60% of exploits target two-year old bugs

Russia the hub of exploit writing.
Apps steal private Twitter data 

Apps steal private Twitter data

Bug now squashed.
Pen tester launches infosec bootcamp  

Pen tester launches infosec bootcamp

Free application security training.
LinkedIn shuts clickjacking flaw 

LinkedIn shuts clickjacking flaw

Users could be tricked into deleting contacts.
Patient data revealed in medical device hack 

Patient data revealed in medical device hack

DHS steps in, takes ownership of medical vulnerability research.
Another Java zero-day for sale 

Another Java zero-day for sale

Patch incomplete.
Remote zero-day hole found in Linksys routers 

Remote zero-day hole found in Linksys routers

Researchers say all routers likely affected.
Microsoft issues out-of-band Internet Explorer patch 

Microsoft issues out-of-band Internet Explorer patch

Dangerous bug used in ongoing spy attacks.
BugCrowd brings bounties to the masses 

BugCrowd brings bounties to the masses

Aussies pitch startup to Silicon Valley.
Oracle patches Java zero day 

Oracle patches Java zero day

Mozilla and Apple act on security flaw.
Java zero day infections increase 

Java zero day infections increase

Exploit attacks thousands.
$10k-a-month exploit kit trumps BlackHole 

$10k-a-month exploit kit trumps BlackHole

Two hundred new servers found hosting the Cool exploit kit.
Ruby on Rails remote exploit developed, researcher says 

Ruby on Rails remote exploit developed, researcher says

More than 200,000 websites at risk.
Ruby on Rails pushing out 'extremely critical' fixes 

Ruby on Rails pushing out 'extremely critical' fixes

Workaround available.
Yahoo patches XSS mail flaw  

Yahoo patches XSS mail flaw

Researcher claims fix isn't adequate.
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read