Vulnerabilities

July 29, 2010, 2:11PM Threatpost Original

Researcher Reveals Major SSL and Browser Flaws

LAS VEGAS--A security researcher has found a slew of fundamental problems with the way that modern browsers are designed and built, leading to serious questions about the security of these applications and the way that they handle SSL sessions.

Shorten URL: http://threatpost.com/en_us/c1S. Click to copy to clipboard or post to Twitter

July 29, 2010, 1:31PM

It's Official: DNSSEC Fully Updated

Two years after a major flaw was exposed in the Internet's Domain Name System (DNS), a major upgrade to the infrastructure protocol that fixes that weakness is now up and running in all of the Internet root servers. Read the full article. [Dark Reading]

Shorten URL: http://threatpost.com/en_us/c1t. Click to copy to clipboard or post to Twitter

July 28, 2010, 8:24PM Threatpost Original

Hacker Demos Remote Attacks Against ATMs

LAS VEGAS -- Using home-brewed software tools and exploiting a gaping security hole in the authentication mechanism used to update the firmware on automated teller machines (ATMs), a security researcher hacked into ATMs made by Triton and Tranax and planted a rootkit that dispensed cash on demand.

Shorten URL: http://www.threatpost.com.es/en_us/c17. Click to copy to clipboard or post to Twitter

July 28, 2010, 4:22PM Threatpost Original

Persistent, Covert Malware Causing Major Damage

LAS VEGAS--Security technology and practice have advanced quite a bit in the past few years, but one thing that has become clear is that whatever gains have been made are just not keeping pace with the innovation of attackers. The advances being made by malware authors and crimeware gangs are keeping them well ahead of the curve and will continue to do so for the foreseeable future, researchers say.

Shorten URL: http://threatpost.com/en_us/c1y. Click to copy to clipboard or post to Twitter

July 28, 2010, 3:01PM

Major Check Counterfeiting Ring Uncovered

A researcher has uncovered a sophisticated check counterfeiting ring that uses compromised computers to steal and print millions of dollars worth of bogus invoices and then recruit money mules to cash them. Read the full article. [The Register]

Shorten URL: http://threatpost.com/en_us/c1N. Click to copy to clipboard or post to Twitter

July 28, 2010, 2:54PM Threatpost Original

Microsoft Ships Anti-Exploit Tool for IT Admins

LAS VEGAS -- Microsoft today released a new tool to help IT administrators backport anti-exploit mitigations like ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) to older versions of Windows.

Shorten URL: http://www.threatpost.com.es/en_us/c1I. Click to copy to clipboard or post to Twitter

July 28, 2010, 12:35PM Threatpost Original

Apple Fixes AutoFill Flaw in Massive Safari Update

LAS VEGAS--Apple has released a major update to its Safari browser that includes a number of security fixes, most importantly a patch for the AutoFill vulnerability disclosed recently.

Shorten URL: http://threatpost.com/en_us/c1b. Click to copy to clipboard or post to Twitter

July 28, 2010, 11:10AM

Three Mariposa Botnet Suspects Arrested

Slovenian police will hold a press conference on Friday to discuss the arrest of three men in connection the massive Mariposa botnet that was disabled late last year. Read the full article. [IDG News Service]

Shorten URL: http://threatpost.com/en_us/c1Y. Click to copy to clipboard or post to Twitter

July 28, 2010, 11:07AM

Zeus Botnet Using Windows LNK Flaw

Isolated strains of mainstream malware that took advantage of how the zero-day Windows flaw first exploited by the sophisticated Stuxnet worm began appearing late last week. The same approach has since been applied by the dodgy sorts behind Zeus, a family of sophisticated toolkits frequently used to steal bank login credentials and the like from compromised systems. Read the full article. [The Register]

Shorten URL: http://threatpost.com/en_us/c1C. Click to copy to clipboard or post to Twitter

July 27, 2010, 1:52PM Threatpost Original

Escalating Privileges In the Database Can Wreak Havoc

By Alex Rothacker

Privilege escalation attacks consist of exploiting a bug or design flaw in a software application to gain access to resources which normally are protected from an application or user. The result is that the application allows actions with privileges beyond an acceptable level for the specific user.  

Shorten URL: http://threatpost.com/en_us/cCu. Click to copy to clipboard or post to Twitter

Syndicate content

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy