Security Experts:

Virus & Threats
long dotted

NEWS & INDUSTRY UPDATES

Microsoft is set to fix 34 security vulnerabilities in this month's Patch Tuesday.
The tool, which goes for as little as $10, has built-in SQL injection options as well as the ability to add custom exploits, a researcher said.
Adobe has issued a Security Advisory for a newly disclosed critical security vulnerability (CVE-2013-3336) in Adobe ColdFusion.
Microsoft has released a one-click Fix it to help protect customers from a recently-disclosed security vulnerability affecting Internet Explorer 8.
Billy Rios and Terry McCorkle, researchers for Cylance, discovered that Google was using an outdated version of the Niagara framework building management system.
Several media sites, including two Washington, DC-based radio stations, have been compromised to infect unsuspecting visitors' systems with fake antivirus software.
Smaller open source projects tend to be more secure than proprietary applications, but the opposite is the case for software with more than a million lines of code, according to a new report from Coverity.
Two researchers propose using fake passwords known as "honeywords" to trick attackers that have managed to steal a file of usernames and hashed passwords.
What was thought to be a year-old Internet Explorer vulnerability being exploited on the U.S. Department Labor website is actually a 0-day vulnerability being exploited in a more widespread campaign.
Attackers have improved their social engineering tactics to target banks in the U.K.

FEATURES, INSIGHTS // Virus & Threats

rss icon

Mark Hatton's picture
When it comes to security, you can scan for vulnerabilities all day long and even convince yourself that you know where that threat is hiding, but until you’re able to capture, correlate and contextualize it, it means nothing.
Wade Williamson's picture
Not only is Google raising the bar, installing a ladder and raising the bar again in terms of vuln bounties - they are doing so for an operating system that is virtually non-existent in the wild.
Tal Be'ery's picture
Organizations should always assume third party code—coming from partners, vendors, mergers and acquisitions—is vulnerable, and take relevant precautions.
Tal Be'ery's picture
Tal explains the technical details behind recent Ruby on Rails vulnerabilities and shows how web applications’ administrators can avoid these and similar problems with some proper system hardening.
Tal Be'ery's picture
In this column, Tal analyzes the technical details of the DKIM vulnerability, evaluates possible implications of the exploit, and points to some general lessons.
Alan Wlasuk's picture
By wandering around a public website with easily obtainable tools, it's easy to pick up on several security ‘tells’ that your website gives away, indicating how easy it could be to hack.
Tal Be'ery's picture
Last week, Mozilla removed the latest version of their Firefox Web browser just a day after it was released. Since Mozilla gave us little to work with, we will dive into the technical details of the vulnerability - a JavaScript vulnerability.
Wade Williamson's picture
Data in Microsoft's Security Intelligences report shows the broad impact of the Black Hole exploit kit in terms of its role in the delivery of threats.
Chris Hinkley's picture
As e-commerce ramps up again in advance of the holiday season, businesses need to take mobile payments security seriously. Here are three ways to protect your customers’ information when accepting mobile payments.
Alan Wlasuk's picture
As I wander the world of website security, I run across many reasons why most websites (over 70%) are open to hacks from amateur and professional hackers alike.