Security


Microsoft's August Patch Brings 11 Security Fixes

Microsoft's August patch, slated to be the largest patch rollout since 12 bulletins hit users in February of 2007, came up short by one.

Microsoft Ships Visual Studio 2008 and .NET SP1

Microsoft released to manufacturing its widely touted first service pack (SP) of Visual Studio 2008 and .NET Framework 3.5.

DNS May Be Patched, but Danger Still Lurks

We dodged a bullet last month -- the discovery of a fundamental flaw in the Domain Name System, Dan Kaminsky told a standing-room only (and some sitting on the floor) crowd at the Black Hat Briefings Wednesday.

Analyst: Beware of the Google Gadgets

One fun thing about the interactive world of Web 2.0 is the online applications you can take advantage of, such as Google Gadgets.

Seven Critical Fixes Expected on Tuesday

IT Pros and system administrators will be mighty busy this month as Microsoft announced plans to release 12 patches.

Coreflood Trojan Stole 500G of Personal Financial Data

A cache of stolen data gathered from a botnet that has been quietly sweeping up information for years contained the user names and passwords for 8,485 bank accounts.

Tuesday Patch Cycles To Include Risk Assessments

Microsoft is initiating a new security notification approach, the company announced on Tuesday at the Black Hat security conference.

Data Thefts Show Need for Comprehensive Security

On Tuesday, the U.S. Department of Justice charged 11 hackers with allegedly hitting the computer records of as many as nine major retail companies and selling more than 40 million credit and debit card numbers.

Black Hat Researchers Overcome Security Learning Curve

The Black Hat Briefings return to Caesars Palace this week with a new batch of hands-on security research for a crowd of 4,000 IT administrators, hackers, industry experts and government officials.

Collaboration Key to Security, Microsoft Says

Microsoft ratcheted up its PR and client communications efforts to demonstrate that it's serious about security.

Security Woes Up, as PHP and OSS Make the List

Software vulnerabilities are up this year, especially Web browser-based ones, according to a new report from IBM Internet Security Systems.

Virtualization Showdown at Black Hat

Next week at the Black Hat conference in Las Vegas, security researcher Joanna Rutkowska promises to demonstrate how a malicious attacker, working remotely, could take control of the open-source Xen virtualization software.

Virtual Security

Virtualization heralds a brave new world of security. Here are a few things to keep in mind when it comes to securing a virtual infrastructure.

Apple Reacts to Spoof Threats, Issues DNS Hotfix

Apple Inc. took action on Friday to address the infamous Domain Name System (DNS) problem. And none too soon.

First Instance of New DNS Exploit Reported

Reports are coming in that an AT&T Domain Name System (DNS) server may have been compromised with malicious code that exploits a vulnerability reported earlier this month. This apparently is the first instance of the exploit in the wild.

WebLogic Security Hole Found

A recently uncovered flaw with the Oracle WebLogic server allows users to gain entry to the software's server without a user name or password.

Small Companies Lax About Computer Security, Report Finds

Large companies are valuable targets for cyber criminals, but what about the small fry?

DNS Problem Is 'Important' To Patch, Microsoft Says

Microsoft issued a formal security advisory with an "urgent warning" to patch a general Domain Name System vulnerability that can enable spoofing attacks.

Most Malware Found on Trusted Web Pages, Report Says

Five seconds into reading this story, a Web page somewhere will become infected with malware or some other malicious code.

Microsoft's DNS Fix Leads to More Problems

The blogosphere is awash with talk about the possible overall weakness of the Domain Name System (DNS) architecture.

Subscribe on YouTube