id="info"

Zack Whittaker

Zack Whittaker is the security editor for ZDNet, covering cybersecurity, national security, policy and privacy. He is based out of the New York newsroom, and can also be found on sister sites CNET and CBS News. You can contact him with his PGP key: EB6CEEA5.

Charlie Osborne

Charlie Osborne, a medical anthropologist who studied at the University of Kent, UK, is a journalist, freelance photographer and former teacher. She has spent years travelling and working across Europe and the Middle East as a teacher, and has been involved in the running of businesses ranging from media and events to B2B sales. Charlie currently works as a journalist and photographer -- with the occasional design piece -- and writes for ZDNet, CNET and SmartPlanet. She has particular interests in social media, IP law, social engineering and security.

Latest Posts

Italy reveals population's tax, salary details

Italy reveals population's tax, salary details

Italy's tax department posted every Italian's declared earnings and tax contributions on a site that was quickly overwhelmed by onlookers.According to the BBC:There has been outrage in Italy after the outgoing government published every Italian's declared earnings and tax contributions on the internet.

May 1, 2008 by in Government

HP plugs latest ActiveX software update flaw

HP plugs latest ActiveX software update flaw

HP has plugged another ActiveX vulnerability in its software update application.The patch (CVE-2008-0712) covers "a potential vulnerability has been identified with the HPeDiag ActiveX control which is a component of HP Software Update running under windows.

April 28, 2008 by in Security

Developers at fault?  SQL Injection attacks lead to wide-spread compromise of IIS servers

Developers at fault? SQL Injection attacks lead to wide-spread compromise of IIS servers

There's been a lot of noise and violent thrashing over the last couple days regarding a flaw that was originally believed to be a flaw in Microsoft's IIS (Internet Information Server), but has since been pointed out as simply a well thought out SQL Injection attack. For those of you who aren't familiar with SQL Injection attacks, it's a pretty well known web application attack vector that exists in high volume on dynamic applications, say for instance, on your banking site.

April 28, 2008 by in Developer

More URI handler issues to come

More URI handler issues to come

Rob Carter, Billy Rios, and I have been blogging about and speaking at conferences like Black Hat and ToorCon all year on the subject of URI handler abuse.  One might think these types of flaws are soon to go away, but one look at SecurityFocus and FullDisclosure today and you can see that's not the case.

April 25, 2008 by in Security

LendingTree insiders leak customer data

LendingTree insiders leak customer data

LendingTree, an online loan referral service owned by IAC, has informed select customers that their confidential data has been leaked to "a handful of lenders" by company insiders.An email to customers that may have been impacted by the breach refers folks to an FAQ that's basically hidden on the LendingTree site.

April 22, 2008 by in Collaboration

Websense: UN, UK sites compromised by JavaScript injection

Websense: UN, UK sites compromised by JavaScript injection

Websense on Tuesday said that the UN and UK government sites are being attacked in a mass JavaScript injection attack.According to Websense:Websense Security Labs has been tracking a recent development of the malicious JavaScript injection that compromised thousands of domains at the start of this month, just 2-3 weeks ago.

April 22, 2008 by in Developer

Newsletters

You have been successfully signed up. To sign up for more newsletters or to manage your account, visit the Newsletter Subscription Center.
Subscription failed.
See All
See All

Top Stories