Vulnerability
Let's face it. Software has holes. And hackers love to exploit them. New vulnerabilities appear almost daily. If you have software---we all do---you need to keep tabs on the latest vulnerabilities.
-
Mitja Kolsek argues that there's a hidden danger in focusing on limiting exploitability instead of exterminating vulnerabilities.
-
Mozilla rates this a "critical" vulnerability that can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.
-
Fixes coming for dangerous security holes in Microsoft Windows, Microsoft Office, the Internet Explorer browser and .NET/Silverlight.
-
M86Security's newly released report "Security Labs Report - July – December 2011 Recap", details some of the most commonly observed Web exploits currently in the wild.
-
Security researchers from TrendMicro have spotted a fake version of popular game Temple Run, currently available at Android's Market.
TechRepublic Discussions
- 4Speed in decision making?
- 3The use and misuse of the XOR stream cipher
- 19Never use dynamic variable names
- 57Microsoft makes Firefox vulnerable; Mozilla responds
- 37How to deal with Adobe Flash and Reader vulnerability
- 23Understanding risk, threat, and vulnerability
- 1What are your Views about the new attacks going on over TCP/445 (MS-08067)
-
Should we be focusing on vulnerabilities or exploits?
Mitja Kolsek argues that there's a hidden danger in focusing on limiting exploitability instead of exterminating vulnerabilities.
-
Mozilla patches 'critical' Firefox security hole
Mozilla rates this a "critical" vulnerability that can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.
-
Patch Tuesday heads-up: 21 vulnerabilities, including 'critical' IE bulletin
Fixes coming for dangerous security holes in Microsoft Windows, Microsoft Office, the Internet Explorer browser and .NET/Silverlight.
-
Hackers pounce on just-patched Windows Media vulnerability
The end result is a malicious Trojan with rootkit capabilities. The attack happens silently in the background and all the user sees is a blank WMP application playing a file.
-
How SCADA highlights the futility of finding security vulnerabilities
Pete Lindstrom argues that 'irresponsible' disclosure of security holes in SCADA systems could put human lives at risk and calls on the security research community to start thinking about the...
-
-
Attack tool published for WiFi setup flaw; Cisco issues warning
A working attack tool for this vulnerability is publicly available so it's important for affected users to heed all vendor warnings.
-
Oracle to patch 79 DB server vulnerabilities
The most serious of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.
-
'Critical' Windows Media flaws put millions at risk
Pay special attention to MS12-004, a "critical" bulletin that provides fixes for two serious flaws in the way Windows Media handles certain media files.
-
iPhone date glitch exposes photo albums
If your iOS device's clock is rolled back, your entire photo album is visible even if the device is locked with a passcode.
-
Microsoft releases out-of-band security update to plug .NET hole
Just in time for the new year, Microsoft released a rare out-of-band security update, its 100th of the year. The update represents "holiday heroics" for the team that sacrificed Christmas to plug...
-
Windows Phone hit by SMS vulnerability
SMS message causes device to reboot and disables access to the messaging hub.
-
Adobe PDF Reader zero-day under attack
According to a warning from Adobe, the attacks have been observed in the wild against Windows users running Adobe Reader version 9.4.6. An emergency fix is coming next week.
-
Apple fixes iOS vulnerability exposed by Charlie Miller
Apple fixes the security vulnerability that was at the center of its decision to dismiss Charlie Miller from the iOS developer program.
-
Microsoft fixes gaping hole in Windows TCP/IP stack
An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Microsoft urges Windows users to treat this update with the utmost priority.
-
Windows kernel 'zero-day' found in Duqu attack
One version of the attack was triggered by a rigged Microsoft Word .doc that probably included some social engineering and required the target to open the booby-trapped file.
-
Opera denies ignoring critical font manipulation vulnerability
Opera Software spars with a security researcher over (ir)responsible disclosure of a critical security vulnerability.
-
Apple slaps another security band-aid on iTunes
Apple patches 79 gaping security holes in the iTunes for Windows software.
-
Complex IT security risks can only be treated with comprehensive response, not point products
There are so many different points at which security incidents can occur; the real trick is getting your arms around all of them and focusing your attention on those that are most likely to cause...
-
If your PC picks up a virus, whose fault is it?
Want to avoid being attacked by viruses and other malware? Two recent studies reveal the secret: regular patching. A fully patched system with a firewall enabled offers almost complete protection...
-
27 of 100 tested Chrome extensions contain 51 vulnerabilities
A group of security researchers have analyzed 100 Chrome extensions and found out that 27 of the 100 extensions contain one or more vulnerabilities in their cores, for a total of 51 vulnerabilities.
Resources from our Sponsor
- Find the people, products and plan you need to implement a data loss prevention (DLP) solution.
- Learn how to protect against data loss with proven solutions from CDW.
- Security threats come in many forms, CDW offers solutions to suit your needs.
- Discover protection in depth, learn about a layered security approach from CDW.
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox
Facebook Activity
White Papers, Webcasts, & Resources
- Live Webcast: Fast and Efficient Business Security Strategies Check out this webcast to learn more about fast and efficient business security strategies. You're in the midst of an arms race, make sure you win it. Download Now
- Live Webcast: Top Considerations for Effective Managed Security for 2012 and Beyond Register for this webcast, Top Considerations for Effective Managed Security for 2012 and Beyond, to learn more about what you can do to keep your network protected for years to come. Download Now
- eBook "Real-World Virtualization for Your Business" The next revolution has arrived, and this time it's all about virtualization. Check out this ebook, Real-World Virtualization For Your Business, to see what the big deal is. Download Now









