Vulnerabilities

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

By

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

By

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.

Adobe ColdFusion exploit spreading

By

The weakness allows for an intruder to quietly have access to any files stored on the server.

Microsoft offers temporary fix for live Internet Explorer exploit

By

The software giant is trying to put the brakes on a serious flaw that is being leveraged as part of possible espionage campaign against U.S. energy workers.

U.S. Department of Labor website was serving zero-day Internet Explorer 8 exploit

U.S. Department of Labor website was serving zero-day Internet Explorer 8 exploit By

Originally, researchers believed that the Labor Department site led to malware that took advantage of a known vulnerability. But that is no longer the case, and Microsoft has confirmed a fresh, unpatched vulnerability in IE 8.

Adobe confirms PDF tracking issue, plans to ship fix soon

Adobe confirms PDF tracking issue, plans to ship fix soon By

The software maker seemed to downplay the threat posed by issue, which McAfee is calling a security vulnerability that could be used in APT-style campaigns.

Websites gradually shedding vulnerabilities, though most still contain a serious one

Websites gradually shedding vulnerabilities, though most still contain a serious one By

WhiteHat Security's annual survey of tens of thousands of websites also studied whether certain best practices are helpful in preventing such flaws as information leakage and cross-site scripting.

Debate: Is advanced malware no longer a problem when administrator rights are removed?

In this month's debate, experts discuss if advanced malware is still a persistent challenge after administrator rights are removed.

Researchers investigate Adobe vulnerability that enables a PDF to be tracked

Researchers investigate Adobe vulnerability that enables a PDF to be tracked By

McAfee said it considers this a security issue because the flaw could be leveraged as part of a malicious attack to gather reconnaissance about a target.

Microsoft issues replacement for botched patch

By

Microsoft is now issuing a replacement patch for a fix that was shelved two weeks ago after customers reported problems resulting after they installed it.

New Java exploit on the loose following recent security update

New Java exploit on the loose following recent security update By

In addition to the exploit, which leverages a recently patched bug, a researcher has discovered a fresh vulnerability in the newly minted version of Java SE.

ACLU asks FTC for help forcing mobile carriers to patch bugs faster

By

The American Civil Liberties Union has filed a complaint with the Federal Trade Commission over several major carriers' alleged sluggish patching practices, a concern for enterprises as BYOD pervades the business world.

Oracle releases 42 fixes for Java bugs as part of wider security update

By

An improved notification system will help protect users from running risky applications from untrusted sources.

"Watering hole" websites present largest innovation for targeted attacks

By

Symantec's annual "Internet Security Threat Report 2013" concentrated on the success attackers are attaining by sabotaging legitimate websites.

Microsoft shelves patch, asks customers to uninstall, after error discovered

By

The software giant said applying the update could prevent machines and applications from properly restarting and loading.

Microsoft fixes three "critical" flaws with Patch Tuesday release

By

The biggies are two vulnerabilities in Internet Explorer and a single weakness in Remote Desktop Connection.

April's Patch Tuesday from Microsoft includes another Internet Explorer patch

April's Patch Tuesday from Microsoft includes another Internet Explorer patch By

The software giant expects to distribute eight other fixes to correct vulnerabilities in Windows, Office, Server Software and Security Software.

Firefox 20 released, makes "private browsing" easier

By

The release patches 13 vulnerabilities, five of which are deemed "critical."

Sophos' flagship web security product open to attack

By

The security company is urging customers to upgrade to the latest version of the appliance, which is not susceptible to the vulnerabilities reported Wednesday by researchers at SEC Consult.

Threat of the month: Universal Plug and Play vulnerabilities

Threat of the month: Universal Plug and Play vulnerabilities

April's "threat of the month" are Universal Plug and Play (UPnP) vulnerabilities, which allow attackers to execute arbitrary code.

Cleaning up the CVSS

By

Prioritization is a key part of the patching strategy of any customer, says SC Magazine's Dan Kaplan.

Web-based malware threats primary challenge for industry pros, survey says

By

Of the companies polled in a recent survey, eight in 10 indicated that they experienced web attacks in 2012.

Research reveals 94 percent of endpoints currently running outdated versions of Java

By

Owing to outdated browsers, an attack aimed at older Java vulnerabilities can be just as successful for miscreants as targeting new vulnerabilities, according to new research.

Experiment shows how often hackers want to attack critical infrastructure

Experiment shows how often hackers want to attack critical infrastructure By

Honeypots installed by researchers at security firm Trend Micro provided bait for 39 attacks on simulated ICS environments over the course of a month.

Apple updates Mountain Lion OS, includes Java Web Start fix

Apple updates Mountain Lion OS, includes Java Web Start fix By

The security update patched 21 vulnerabilities and a Java Web Start bug that could allow apps to be launched automatically.

Cyber criminals offer black market peers bug discovery service

By

The new offering shows that, as cyber criminals become more sophisticated, they'll need more options to secure their infrastructure.

Microsoft pushes seven patches, including fix for "evil maid"-style attack

By

The vulnerability allows anyone with "casual physical access, such as a custodian sweeping your office at night or a security guard making his rounds" to plug in a USB device and become an administrator, according to Microsoft.

Sponsored video: Philippe Courtot, chairman and CEO of Qualys, at RSA Conference 2013

By

In this video shot at RSA Conference 2013 in San Francisco, Illena Armstrong, VP of editorial at SC Magazine, sits with Courtot to discuss some of the big problems facing CISOs today, as well as his thoughts on this year's big conference.

Nearly all apps vulnerable to exploit

By

Researchers also found that the median number of vulnerabilities per application was 13 flaws.

Microsoft schedules seven security patches for monthly Patch Tuesday

By

They address flaws in Internet Explorer (IE), Windows, Office, Server Software and Silverlight.

Advertisement

How to Prevent Insider Threats!

POLL