Vulnerabilities

February 3, 2012, 6:56PM

Privacy Fail: Is Uncle Sam Encouraging Bad Security?

CANCUN, MEXICO - A prominent privacy activist says that leading software vendors, and the U.S. government are failing the public when it comes to Internet privacy, and that big changes are needed to prevent consumers from criminals, advertisers and government spies. Read more »


February 2, 2012, 12:00PM

Driving Up the Cost of Exploit Development Becomes a Key Defensive Strategy

CANCUN--The skill of attackers, combined with the difficulty and cost of finding and fixing vulnerabilities in software--especially after deployment--has reached the point that it's now more effective and efficient for vendors to concentrate on making life more difficult for those attackers looking to exploit bugs.  Read more »


February 2, 2012, 10:28AM

Apple Ships Huge Set of Patches for OS X

Apple patchApple has released a massive set of patches for a wide range of security vulnerabilities in a number of its products and components, including OSX Lion and QuickTime. The patches, which are rolled up in OS X 10.7.3, fix a slew of serious bugs, many of which can be used to execute remote code on vulnerable machines. Read more »


February 1, 2012, 8:59AM

Market Fail: Regulations May Be Only Hope For Securing Critical Infrastructure

Threatpost's exclusive interview with Ralph Langner continues, as our conversation shifts from  the legacy of the Stuxnet worm to larger issues facing the critical infrastructure sector including mounting attacks, tensions between vendors and security researchers over responsible disclosure, and what's needed to secure critical infrastructure and industrial control systems.   Read more »


January 31, 2012, 1:45PM

Report Warns of Woeful Readiness For Cyber Attacks Globally

A new report finds that the 'bad guys' are winning, and that most nations are ill-prepared for crippling cyber attacks. Read more »


January 31, 2012, 1:15PM Around the Web

Game On: Gamma Ray Scanners To Guard 'Most Technologically Secure' Super Bowl Ever

Gamma ray scanners? Night vision cameras? bomb-proof manhole covers? G-Men? It must be Super Bowl time again, and Marion County, Indiana says that they've gone where no other municipality has gone before: a permanent, $18 million regional operation center (yes - ROC) that will manage security at the Big Game.

 Read more »


January 30, 2012, 11:27AM

Massive Compromise of Wordpress Sites Leads To Phoenix Exploit Kit

WordpressResearchers at the security firm M86 report that hackers have compromised hundreds of Web sites that use the Wordpress content management system. The sites, mostly small Web pages and blogs, are being used to fool spam filters and redirect unwitting visitors to drive by download Websites that will install malicious software on vulnerable systems. Read more »


January 29, 2012, 6:30AM

UPDATE: Why Stuxnet-Like Attacks Aren't Going Away

StuxnetRalph Langner is the closest thing to a rock star that you get in the Dockers and pocket-protector world of industrial control systems. The German researcher made headlines in 2010 as among the first security experts to analyze parts of the Stuxnet worm's code devoted to manipulating programmable logic controllers by Siemens, and the first to explicitly link the Stuxnet malware with an effort to disable Iran's uranium enrichment operation.

 Read more »


January 25, 2012, 2:30PM

Slideshow: Scenes from S4 2012

S4

VIEW SLIDESHOW Scenes from S4 2012

S4 is a conference hosted by Digital Bond, a security consulting firm based in Sunrise, Florida. Now in its fifth year, the S4 draws some of the world's top experts in securing industrial control systems to sunny Miami Beach to discuss the state of the art.  Read more »


January 25, 2012, 7:57AM

Multiple Bugs Haunt WordPress Setup

Wordpress bugsResearchers have found a string of weaknesses in the WordPress default installation page, including PHP code execution and a persistent cross-site scripting flaw, affecting versions 3.3.1 and later. WordPress officials say that they're not planning to fix the vulnerabilities as there's only a small possibility of exploitation by attackers. Read more »


Syndicate content

 

Copyright © 2012 threatpost.com | Terms of Service | Privacy