All

July 29, 2010, 2:11PM Threatpost Original

Researcher Reveals Major SSL and Browser Flaws

LAS VEGAS--A security researcher has found a slew of fundamental problems with the way that modern browsers are designed and built, leading to serious questions about the security of these applications and the way that they handle SSL sessions.

Shorten URL: http://threatpost.com/en_us/c1S. Click to copy to clipboard or post to Twitter

July 28, 2010, 8:24PM Threatpost Original

Hacker Demos Remote Attacks Against ATMs

LAS VEGAS -- Using home-brewed software tools and exploiting a gaping security hole in the authentication mechanism used to update the firmware on automated teller machines (ATMs), a security researcher hacked into ATMs made by Triton and Tranax and planted a rootkit that dispensed cash on demand.

Shorten URL: http://www.threatpost.com.es/en_us/c17. Click to copy to clipboard or post to Twitter

July 28, 2010, 4:22PM Threatpost Original

Persistent, Covert Malware Causing Major Damage

LAS VEGAS--Security technology and practice have advanced quite a bit in the past few years, but one thing that has become clear is that whatever gains have been made are just not keeping pace with the innovation of attackers. The advances being made by malware authors and crimeware gangs are keeping them well ahead of the curve and will continue to do so for the foreseeable future, researchers say.

Shorten URL: http://threatpost.com/en_us/c1y. Click to copy to clipboard or post to Twitter

July 28, 2010, 2:54PM Threatpost Original

Microsoft Ships Anti-Exploit Tool for IT Admins

LAS VEGAS -- Microsoft today released a new tool to help IT administrators backport anti-exploit mitigations like ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) to older versions of Windows.

Shorten URL: http://www.threatpost.com.es/en_us/c1I. Click to copy to clipboard or post to Twitter

July 28, 2010, 2:04PM Threatpost Original

Adobe to Share Vulnerability Data with Security Vendors

LAS VEGAS -- Adobe's push to beef up its security posture took another leap forward here with the announcement of plans to start sharing details on software vulnerabilities with security vendors ahead of time to help reduce the window of exposure to hacker attacks.

Shorten URL: http://www.threatpost.com.es/en_us/c1B. Click to copy to clipboard or post to Twitter

July 28, 2010, 12:35PM Threatpost Original

Apple Fixes AutoFill Flaw in Massive Safari Update

LAS VEGAS--Apple has released a major update to its Safari browser that includes a number of security fixes, most importantly a patch for the AutoFill vulnerability disclosed recently.

Shorten URL: http://threatpost.com/en_us/c1b. Click to copy to clipboard or post to Twitter

July 27, 2010, 1:52PM Threatpost Original

Escalating Privileges In the Database Can Wreak Havoc

By Alex Rothacker

Privilege escalation attacks consist of exploiting a bug or design flaw in a software application to gain access to resources which normally are protected from an application or user. The result is that the application allows actions with privileges beyond an acceptable level for the specific user.  

Shorten URL: http://threatpost.com/en_us/cCu. Click to copy to clipboard or post to Twitter

July 26, 2010, 2:20PM Threatpost Original

Changes to DMCA Protect Jailbreaking, Some Security Research

A new change to the much-maligned Digital Millennium Copyright Act free users who jailbreak their iPhones and other mobile handsets from worries about prosecution under the provisions of the DMCA that prevented circumvention of protection technologies. A separate change announced Monday also gives security researchers some new protections.

Shorten URL: http://threatpost.com/en_us/cCj. Click to copy to clipboard or post to Twitter

July 26, 2010, 2:02PM Podcast Threatpost Original

Paul Judge and David Maynor on Twitter Crime and Searching for Malware

Digital Underground podcast with Dennis Fisher

You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.

Dennis Fisher talks with Paul Judge and David Maynor of Barracuda about new research the pair will be presenting at BSides Las Vegas and Defcon this week on the start of a reputation system for Twitter accounts, how attackers use search engines to spread malware and what kinds of sites are most likely to be serving you SEO-related malware.

Shorten URL: http://threatpost.com/en_us/cCr. Click to copy to clipboard or post to Twitter

July 26, 2010, 11:01AM Threatpost Original

Researcher to Show Off GSM Intercept Attack at Defcon

At the Defcon conference later this week, Chris Paget, a well-known security researcher who focuses on wireless and RFID issues, will give a demonstration of a technique that enables him to intercept calls made on GSM wireless handsets without any interaction with the user's handset.

Shorten URL: http://threatpost.com/en_us/cCl. Click to copy to clipboard or post to Twitter

Syndicate content

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy