Security


Web Sites Rife with Unpatched Vulnerabilities

Although the overall number of vulnerabilities being discovered in software appears to be leveling off or even dropping, two recent reports on Web security say that the overwhelming majority of Web sites studied still have unpatched vulnerabilities that could expose visitors to malicious code.

BitLocker Password Exploit Is 'Very Unlikely,' Sisk Says

Redmond responded on Wednesday to an independent security vendor's discovery of a hard-drive encryption vulnerability affecting Microsoft's BitLocker function, Intel/HP's BIOS and several other products and programs.

Troubles in Terrorist Database

A variety of technical flaws in an upgrade of the system that supports the government's terrorist watch list has drawn congressional fire and raised concerns that the entire system might be in jeopardy.

Security Software: How Suite It Is

The writing's on the wall, it seems, for purveyors of security point solutions. Gone is the day of the best-of-breed anti-virus, firewall, e-mail security or encryption vendors. These days, it's a security suite play.

Browser Security Gets Focus in ZoneAlarm 8.0 App

Check Point Software Technologies today released a new solution to address Internet security woes.

Red Hat Hacked, Company Issues Security Advisory

In a sign that hackers have no problem taking advantage of open source solutions, Linux-based product distributor Red Hat issued a "critical" security advisory on Friday, saying that its servers had been compromised.

UPDATED: Microsoft Tool Helps Filter SQL Injection Attacks

Microsoft on Thursday released an improved security filter for its Internet Information Service (IIS) Web server that is designed to help thwart SQL injection attacks.

Microsoft Tool Helps Filter SQL Injection Attacks

Microsoft released an improved security filter for its Internet Information Service Web server that is designed to help thwart SQL injection attacks.

Vulnerability Management Needed for Security, Study Says

Companies can avoid attacks and minimize security cost overruns by practicing IT vulnerability management, according to a July study published by the Aberdeen Group.

Microsoft Unveils 'Ultimate' Support Service

Microsoft rolled out the highest level of its enterprise support programs to date, adding a new offering called "Microsoft Services Premier Ultimate."

Emmett's Integration Security Quiz o' Doom

Security and integration are far from mutually exculsive. Which is why it might help to know a little something about password authentication, asymmetric cryptography, server security, IPsec...

VMware's Updates Cause Problems, CEO Apologizes

Yesterday, August 12, was a blow-out day for some users of VMware's ESX 3.5 and ESXi 3.5 virtualization products, especially if they had applied the latest product updates called "Update 2."

SQL Injection Attacks on the Rise

MessageLabs reports that the number of SQL injection attacks spiked sharply last month.

WSUS Blocking: A Real Problem, Microsoft Says

Microsoft closed its investigation into an update blocking issue that affected users of Windows Server Update Service 3.0 or WSUS 3.0 Service Pack 1.

Microsoft's August Patch Brings 11 Security Fixes

Microsoft's August patch, slated to be the largest patch rollout since 12 bulletins hit users in February of 2007, came up short by one.

Microsoft Ships Visual Studio 2008 and .NET SP1

Microsoft released to manufacturing its widely touted first service pack (SP) of Visual Studio 2008 and .NET Framework 3.5.

DNS May Be Patched, but Danger Still Lurks

We dodged a bullet last month -- the discovery of a fundamental flaw in the Domain Name System, Dan Kaminsky told a standing-room only (and some sitting on the floor) crowd at the Black Hat Briefings Wednesday.

Analyst: Beware of the Google Gadgets

One fun thing about the interactive world of Web 2.0 is the online applications you can take advantage of, such as Google Gadgets.

Coreflood Trojan Stole 500G of Personal Financial Data

A cache of stolen data gathered from a botnet that has been quietly sweeping up information for years contained the user names and passwords for 8,485 bank accounts.

Seven Critical Fixes Expected on Tuesday

IT Pros and system administrators will be mighty busy this month as Microsoft announced plans to release 12 patches.

Subscribe on YouTube

Upcoming Training Events

0 AM
Live! 360 Orlando
November 17-22, 2024
TechMentor @ Microsoft HQ
August 11-15, 2025