Dennis Fisher

July 29, 2010, 2:11PM Threatpost Original

Researcher Reveals Major SSL and Browser Flaws

LAS VEGAS--A security researcher has found a slew of fundamental problems with the way that modern browsers are designed and built, leading to serious questions about the security of these applications and the way that they handle SSL sessions.

Shorten URL: http://threatpost.com/en_us/c1S. Click to copy to clipboard or post to Twitter

July 28, 2010, 4:22PM Threatpost Original

Persistent, Covert Malware Causing Major Damage

LAS VEGAS--Security technology and practice have advanced quite a bit in the past few years, but one thing that has become clear is that whatever gains have been made are just not keeping pace with the innovation of attackers. The advances being made by malware authors and crimeware gangs are keeping them well ahead of the curve and will continue to do so for the foreseeable future, researchers say.

Shorten URL: http://threatpost.com/en_us/c1y. Click to copy to clipboard or post to Twitter

July 28, 2010, 12:35PM Threatpost Original

Apple Fixes AutoFill Flaw in Massive Safari Update

LAS VEGAS--Apple has released a major update to its Safari browser that includes a number of security fixes, most importantly a patch for the AutoFill vulnerability disclosed recently.

Shorten URL: http://threatpost.com/en_us/c1b. Click to copy to clipboard or post to Twitter

July 26, 2010, 2:20PM Threatpost Original

Changes to DMCA Protect Jailbreaking, Some Security Research

A new change to the much-maligned Digital Millennium Copyright Act free users who jailbreak their iPhones and other mobile handsets from worries about prosecution under the provisions of the DMCA that prevented circumvention of protection technologies. A separate change announced Monday also gives security researchers some new protections.

Shorten URL: http://threatpost.com/en_us/cCj. Click to copy to clipboard or post to Twitter

July 26, 2010, 2:02PM Podcast Threatpost Original

Paul Judge and David Maynor on Twitter Crime and Searching for Malware

Digital Underground podcast with Dennis Fisher

You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.

Dennis Fisher talks with Paul Judge and David Maynor of Barracuda about new research the pair will be presenting at BSides Las Vegas and Defcon this week on the start of a reputation system for Twitter accounts, how attackers use search engines to spread malware and what kinds of sites are most likely to be serving you SEO-related malware.

Shorten URL: http://threatpost.com/en_us/cCr. Click to copy to clipboard or post to Twitter

July 26, 2010, 11:01AM Threatpost Original

Researcher to Show Off GSM Intercept Attack at Defcon

At the Defcon conference later this week, Chris Paget, a well-known security researcher who focuses on wireless and RFID issues, will give a demonstration of a technique that enables him to intercept calls made on GSM wireless handsets without any interaction with the user's handset.

Shorten URL: http://threatpost.com/en_us/cCl. Click to copy to clipboard or post to Twitter

July 23, 2010, 1:48PM Threatpost Original

This Week in Security: Microsoft's CVD Policy, Stuxnet Part Deux and Double Rainbows

This week brought us the rare double rainbow of a re-emergence of the disclosure discussion and major security news from Microsoft, all wrapped into one. It truly was a gift from Mother Nature. But Microsoft's decision to change its disclosure stance--and refusal to pay bug bounties--wasn't the only big news. The Stuxnet saga continued to widen and weirden, a major privacy leak cropped up in Safari and the roots of the mass SQL injection attacks were exposed. What does it all mean? Read on for the full week in review.

Shorten URL: http://threatpost.com/en_us/caL. Click to copy to clipboard or post to Twitter

July 23, 2010, 11:44AM Podcast Threatpost Original

Dino Dai Zovi on Return-Oriented Exploitation and Bug Bounties

Digital Underground podcast with Dennis Fisher

You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.

In this episode, Dennis Fisher talks with independent security researcher Dino Dai Zovi about his upcoming Black Hat talk on return-oriented exploitation, the value of exploit mitigations such as DEP and ASLR, the new crop of vendor bug bounties and why we don’t have any good data on zero-day attacks.

Shorten URL: http://threatpost.com/en_us/caG. Click to copy to clipboard or post to Twitter

July 23, 2010, 11:33AM Threatpost Original

New Malware Emerges to Exploit Windows LNK Flaw

Researchers have found two distinct new malware families that are exploiting the newly discovered Windows shell LNK vulnerability, leading to concerns that the development of a worm could be in the offing.

Shorten URL: http://threatpost.com/en_us/cav. Click to copy to clipboard or post to Twitter

July 22, 2010, 4:54PM Threatpost Original

Microsoft Says No to Paying Bug Bounties

Microsoft has no plans to follow in the footsteps of Mozilla and Google and pay researchers cash rewards for the bugs that they find in Microsoft's products.

Shorten URL: http://threatpost.com/en_us/caY. Click to copy to clipboard or post to Twitter

Syndicate content

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy