Secunia: Average insecure program per PC rate remains high
Dancho Danchev: With the time frame for an exploit to become an inseparable part of a web malware exploitation kit shrinking, and with the average Internet user’s over-confidence in an antivirus scanner’s ability to detect and block exploits (Secunia: popular security suites failing to block exploits) it shouldn’t come as a surprise that Secunia’s recently released WorldMap [...]
Thu Jun 25 11:21:38 PDT 2009
Guy Kawasaki's Twitter account hijacked, pushes Windows and Mac malware
Ryan Naraine: The Twitter account belonging to venture capitalist and Mac evangelist Guy Kawasaki was hijacked yesterday and used to push malware to some 140,000 Twitter users. The attack (screenshot above) included a link to what purported to be a “sex tape video free download” linked to Gossip Girls star Leighton Meester but, after a series of [...]
Wed Jun 24 11:54:02 PDT 2009
Critical Adobe Shockwave flaw affects millions
Ryan Naraine: Adobe’s Shockwave Player contains a critical vulnerability that could be exploited by remote hackers to take complete control of Windows computers, according to a warning from the software maker. The flaw affects Adobe Shockwave Player 11.5.0.596 and earlier versions. Details from Adobe’s advisory: This vulnerability could allow an attacker who successfully exploits this vulnerability to take control [...]
Wed Jun 24 09:41:18 PDT 2009
Remote code execution exploit for Green Dam in the wild
Dancho Danchev: The recently exposed as vulnerable to trivial remotely exploitable flaws Chinese censorware Green Dam, has silently patched the security flaws (China confirms security flaws in Green Dam, rushes to release a patch) outlined in the original analysis detailing the vulnerabilities. However, not only is the latest Green Dam v3.17 version still vulnerable to remotely exploitable flaws, [...]
Wed Jun 24 07:52:24 PDT 2009
[Sponsored]
Mon Jun 22 13:39:30 PDT 2009
Mozilla tackles XSS vulnerabilities with new technology
Ryan Naraine: Mozilla’s security engineers are working on new technology that promises to mitigate a large class of Web application vulnerabilities, especially the cross-site scripting (XSS) plague against modern Web browsers. The project, called Content Security Policy, is designed to shut down XSS attacks by providing a mechanism for sites to explicitly tell the browser which content is [...]
Mon Jun 22 13:39:30 PDT 2009
No comments:
Post a Comment