![]() |
Tags | Domains | Searches | Statistics | Options | Advanced Search |
Zero Day - Nov 21, 2008
Under sustained attack from what is described as a rapidly spreading network worm, the U.S. army has banned the use of USB sticks, CDs, flash media cards, and all other removable data storage devices, according to …
Also tagged: malware, browsers, anti virus, data theft, exploit code, rootkits, viruses and worms, spyware and adware
Zero Day - Sep 26, 2008
[ UPDATE: See e-mail from NoScript creator Giorgio Maone on a possible mitigation ] Researchers are beginning to raise an alarm for what looks like a scary new browser exploit/threat affecting all the major desktop …
Also tagged: microsoft, research, flash, adobe, google, firefox, ebay, malware, browsers, java, mozilla, botnets, vulnerability research, exploit code, zero day attacks, responsible disclosure, patch watch, arbitrary code execution, complex attacks, google chrome
Zero Day - Sep 20, 2008
VMware has released new ESXi and ESX 3.5 packages to fix a “critical” security issue that allows a remote, unauthenticated attacker to launch harmful code on the host running the hypervisor. According to this VMWare …
Also tagged: open source, passwords, data theft, vulnerability research, zero day attacks, pen testing, patch watch, denial of service dos, arbitrary code execution, kernel level exploits, complex attacks
Zero Day - Sep 4, 2008
Microsoft is downplaying the severity of a password leakage issue in BitLocker, the full disk encryption feature built into Windows Vista, insisting that a real world attack scenario is “very unlikely.” According to an …
Also tagged: windows vista, microsoft, research, browsers, passwords, botnets, data theft, vulnerability research, exploit code, pen testing, patch watch, denial of service dos, complex attacks
Zero Day - Sep 2, 2008
Virtualization specialist VMware has shipped a mega-patch to cover several “highly critical” vulnerabilities affecting its server and workstation product lines. In all, the patch batch addresses at least 16 documented …
Also tagged: firefox, malware, browsers, data theft, exploit code, web applications, pen testing, patch watch, arbitrary code execution, complex attacks
Zero Day - Aug 28, 2008
Do not trust that passcode lock on Apple’s iPhone. The feature, which lets users set a four-digit pincode to limit access to the device, can be easily bypassed with a few finger taps on the iPhone to give an intruder …
Also tagged: apple, browsers, wireless, passwords, data theft, vulnerability research, exploit code, spam and phishing, responsible disclosure, pen testing, patch watch, arbitrary code execution, mobile in security
Zero Day - Aug 26, 2008
The U.S. Computer Emergency Readiness Team (CERT) has issued a warning for what it calls “active attacks” against Linux-based computing infrastructures using compromised SSH keys. The attack appears to initially use …
Also tagged: research, open source, botnets, data theft, vulnerability research, exploit code, zero day attacks, metasploit, pen testing, patch watch, arbitrary code execution, kernel level exploits, complex attacks
Zero Day - Aug 23, 2008
The United States Computer Emergency Response Team (US-CERT) has raised an alarm for a serious vulnerability in Apache Tomcat, warning that a proof-of-concept exploit is publicly available. The code, posted to …
Also tagged: privacy, open source, malware, hackers, passwords, phishing, anti virus, data theft, vulnerability research, exploit code, zero day attacks, responsible disclosure, pen testing, patch watch, denial of service dos, arbitrary code execution, complex attacks
Zero Day - Aug 20, 2008
Opera Software has shipped a new version of its flagship Web browser with fixes for at least seven documented security problems but details on one vulnerability — a cross-site scripting issue reported by Chris Weber– …
Also tagged: research, firefox, malware, browsers, java, passwords, anti virus, botnets, data theft, vulnerability research, exploit code, viruses and worms, responsible disclosure, pen testing, denial of service dos, arbitrary code execution, complex attacks
Zero Day - Aug 15, 2008
Guest editorial by Derek Callaway This post is meant to provide an approximation of BIND nameserver updates that occurred during the past month, most likely in response to Dan Kaminsky’s DNS cache poisoning …
Also tagged: open source, browsers, botnets, data theft, vulnerability research, exploit code, metasploit, pen testing, arbitrary code execution, complex attacks