WorldWar-E™

The Global Cyber War from MentalWardPublishing.com presented free by McGuinnessPublishing.com

WorldWar-E™ RSS Feed
 
 
 
 

Posts tagged Zero Day

Google bug hunter discovers serious Windows XP flaw

Google engineer Tavis Ormandy, a bug hunter known for finding kernel-level operating system coding errors, has released details about a serious zero-day vulnerability in Windows XP that could leave an open hole for a remote attacker.
The flaw is contained in the Windows Help and Support Center, a Web-based feature providing technical support to end users. [...] Read more »

Researcher reveals Safari zero-day bug

Apple’s Safari browser contains a critical, unpatched bug that attackers can use to infect Windows PCs with malicious code, researchers at US-CERT and other security firms said today.
Hackers could compromise PCs with simple “drive-by” attack tactics, researchers added.
The vulnerability, first reported by Danish vulnerability tracker Secunia and confirmed by the United States Computer Emergency Readiness [...] Read more »

Microsoft Investigates SharePoint 2007 Zero Day

Microsoft is scrambling to fix a bug in its SharePoint 2007 groupware after a Swiss firm abruptly released code that could be used in an attack.
The proof-of-concept code was released Wednesday, just over two weeks after security consultancy High-Tech Bridge says it disclosed the issue to Microsoft on April 12.
Although Microsoft hasn’t said much about [...] Read more »

Most resistance to ‘Aurora’ hack attacks futile, says report

Most businesses are defenseless against the types of attacks that recently hit Google and at least 33 other companies, according to a report to be published Monday that estimates the actual number of targeted companies could top 100.
The attackers behind the cyber assault dubbed Aurora patiently stalked their hand-chosen victims over a matter of months [...] Read more »

Dear Adobe: It’s time for security rehab

The stories about Adobe software keep coming, and the news hasn’t been good. Critical bugs in Reader and Flash have come under real-world, zero-day attacks so many times in the past year that the exploits almost seem routine.
Security researchers such as Mike Bailey, Dan Kaminsky and Jeremiah Grossman and Robert “RSnake” Hansen have been exposing [...] Read more »

Microsoft to patch IE zero-day with emergency fix Tuesday

Microsoft announced it will issue an emergency security update for Internet Explorer (IE) to patch a zero-day vulnerability that has been used to launch drive-by attacks for at least several weeks.
Tuesday’s update will be the second out-of-band update — Microsoft’s term for one outside its normal once-each-month Patch Tuesday — in the last three months. [...] Read more »

Adobe’s Reader And Flash Installing Software Can Install Malware

A researcher has unearthed a bug in software used to install Adobe’s ubiquitous Reader and Flash applications that can be exploited to remotely install malicious files on end user PCs.
The Adobe Download Manager is an ActiveX script that is invoked when people install or update Reader or Flash using Internet Explorer. Researcher Aviv Raff has [...] Read more »

Fighting the Aurora Malware: Real-Time Detection & Monitoring.

Description of the attack
 
McAfee Labs identified a zero-day vulnerability in Microsoft Internet Explorer that was used as an entry point for “Operation Aurora” to exploit Google and a rapidly-growing list of other companies. Microsoft has issued a security bulletin and McAfee is working closely with them on this matter. “Operation Aurora” was a coordinated attack [...] Read more »

Contest offers $100,000 for smartphone, browser hacks

An annual hacking contest that has made mincemeat of security on both Mac and Windows computers will set its sights on smartphones and browsers with as much as $100,000 in awards next month.
Now in its fourth year, the Pwn2Own competition will award $60,000 for exploits that successfully penetrate Apple’s iPhone 3GS, Research in Motion’s Blackberry [...] Read more »

Web browser flaw used in Google attack highlights black market for ‘zero-day’ vulnerabilities

The recent hacking attack that prompted Google’s threat to leave China is underscoring the heightened dangers of previously undisclosed computer security flaws — and renewing debate over buying and selling information about them in the black market.
Because no fix was available, the linchpin in the attack was one of the worst kinds of security holes. [...] Read more »

Pages

Double Click Any Word!

 

July 2010
M T W T F S S
« Jun    
 1234
567891011
12131415161718
19202122232425
262728293031  

Archives

Best Practices

Federal Security Info

Our Sites

Security Regulations & Standards

Tech Information

Recent Posts

Popular Posts

  • None found

Recent Posts

Categories

Recent Comments

Guestbook


Subscribe

Polls

Can You Trust Your IT Staff?

View Results

Loading ... Loading ...

What Is The State Of Your Organization's IT Security?

View Results

Loading ... Loading ...