|
Security
|
|
Written by Terry Tran
|
|
Wednesday, 05 November 2008 |
|
A bug that Microsoft patched in a security release nearly two weeks ago, is actively being exploited by a worm, said security researchers. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Monday, 20 October 2008 |
|
A dodgy anti-virus update from AVG wrongly flagged up the popular ZoneAlarm firewall as a Trojan on Tuesday. The mis-firing AVG definition file tagged components of ZoneAlarm as infected with the Agent_r.CX Trojan horse and quarantined important files. As a result users running the popular antivirus package alongside security suite software from Check Point were left with a malfunctioning firewall, mystery infection reports and an inability to re-install their ZoneAlarm software. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Sunday, 19 October 2008 |
|
An 18-year-old New Jersey man will plead guilty to the January online attacks that took down the Church of Scientology's website, US federal prosecutors said on Friday. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Sunday, 19 October 2008 |
|
IT security and control firm Sophos is warning computer users to be vigilant following its discovery that legitimate webpages on the website of Adobe Systems were hosting malicious code that can infect visiting computers. Sophos identified the threat, known as Mal/Badsrc-C, on the Fortune 1000 company's 'Vlog It support center section' - an area providing tips for video bloggers - on Friday 3 October. Despite repeated attempts by Sophos to contact Adobe about the problem, the malicious code was still present until last night. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Tuesday, 14 October 2008 |
Microsoft has warned that scammers are sending out fake emails that claim to include critical Windows security alerts.
The fake alerts describe themselves as part of a new "experimental private version of an update for all Microsoft Windows OS users", Microsoft said in a note on the scam. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Thursday, 09 October 2008 |
 The desktop PC version of Asus' popular Eee PC has shipped with a virus in Japan, the company has warned. The low-cost Eee Box, designed as a basic for managing photos, sending email, surfing the web, and other day-to-day tasks, launched in Japan last week, but Asus has warned owners that it contains a virus file named 'recycled.exe'. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Thursday, 09 October 2008 |
|
Today is the day we can finally start talking about clickjacking. This is just meant to be a quick post that you can use as a reference sheet. It is not a thorough advisory of every site/vendor/plugin that is vulnerable - there are far too many to count. Jeremiah and I got the final word today that it was fine to start talking about this due to the click jacking PoC against Flash that was released today (watch the video for a good demonstration) that essentially spilled the beans regarding several of the findings that were most concerning. Thankfully, Adobe has been working on this since we let them know, so despite the careless disclosure, much of the work to mitigate this on their end is already complete. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Thursday, 09 October 2008 |
|
NoScript, the security add-on for Firefox, has been upgraded to protect against clickjacking.
NoScript blocks scripts in programming languages such as JavaScript and Java from executing on untrusted web pages. The scripts could be used to launch an attack on a PC The new improvement to NoScript, called ClearClick, can detect if there is a hidden, embedded element within the web page. It then displays a warning message asking the user if they still want to click on it. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Thursday, 09 October 2008 |
|
There’s been a bit of drama over the last week or so around the upcoming world OWASP conference in New York. It’s surrounding a talk that Jeremiah and I were planning on doing the first day of the conference. Jeremiah and I have been working on some interesting browser security issues which also effect a lot of downstream people/websites/technologies as well. Sounds like a good talk right? We thought so too! |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Thursday, 09 October 2008 |
A new vulnerability that puts users of every major web browser at risk, has been discovered by security researchers.
Last week, a pair of security researchers spread the news that a new class of vulnerabilities, called 'clickjacking' puts users of every major browser at risk from possible attack. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Sunday, 05 October 2008 |
|
Police have identified the hacker behind the infamous Gpcode 'ransomware' virus that hit computers in July. The individual is believed to be a Russian national, and has been in contact with at least one anti-malware company, Kaspersky Lab, in an attempt to sell a tool that could be used to decrypt victims' files. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Sunday, 05 October 2008 |
|
Losses from online banking fraud hit a record £21.4m in the first half of 2008 - an increase of 185 percent on the previous year, says APACS. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Friday, 26 September 2008 |
|
Apple this week patched almost 30 Java vulnerabilities in its Mac OS X operatimg system. The Apple fixes came up to six months after Sun Microsystems, Java's developer, fixed most of the same flaws for other operating systems. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Friday, 26 September 2008 |
|
Neosploit, the notorious hacker exploit kit, has returned to the web and is responsible for a dramatic increase in attacks, a security researcher has claimed. |
|
Read more...
|
|
|
Security
|
|
Written by Terry Tran
|
|
Friday, 26 September 2008 |
|
Psychologists at North Carolina State University have found that computer users struggle to distinguish between fake Windows warning messages and the real thing. |
|
Read more...
|
|