Security


IE7 Cross-Browser Scripting Exploit Goes Zero Day

Since its debut, Internet Explorer (IE) 7.0 has arguably established itself as Microsoft Corp.'s most secure Web browser to date. To be sure, Redmond has dutifully included IE 7.0 patches in its Internet Explorer patch roll-ups -- but at the very least, Microsoft's newest IE flavor hasn't fallen prey to any of the blockbuster exploits that have so bedeviled Internet Explorer in the past.

IE 7 Cross-Browser Scripting Exploit Goes Zero Day

Just this week, a security researcher alerted Internet Explorer users (and Microsoft itself) to a new input validation vulnerability in IE 7.0.

Microsoft Patches Three Critical Flaws

With this week's Patch Tuesday release, Microsoft kicked off its monthly patching exercise with three critical security bulletins.

Windows Vista SP1 Gets Fast-Tracked

Windows Vista Service Pack (SP)1 is back on track.

Google Buys Postini for $625 Million

Google Inc. is buying e-mail security specialist Postini Inc. for $625 million, fortifying the Internet search leader's effort to sell online software services to corporate customers seeking alternatives to Microsoft Corp.'s long-dominant products.

Three Critical Patches on Tap for Tuesday

The Microsoft Security Response Center (MSRC) plans to publish six security bulletins next Tuesday, according to Thursday's advance notification.

Google-DoubleClick Deal Draws Criticism

Europe's major consumer group BEUC said Wednesday that it feared Internet search engine Google Inc.'s takeover of online ad tracker DoubleClick Inc. would damage European Union privacy rights and limit consumers' choice of Web content.

iPhone Lure Used in Hacker Exploit

The iPhone hype makes it a natural target -- by scammers looking to sell Apple's first cell phone for a huge markup, and also by hackers looking to add to their bot networks.

Cyber Attacks Engulf Kremlin's Critics

A political battle is raging in Russian cyberspace. Opposition parties and independent media say murky forces have committed vast resources to hacking and crippling their Web sites in attacks similar to those that hit tech-savvy Estonia as the Baltic nation sparred with Russia over a Soviet war memorial.

Ohio's Laptops Often Stolen or Missing

In Dayton, a state employee returns to work to find a $2,000 computer stolen. In Cleveland, someone walks into an unlocked office and takes a $2,200 laptop belonging to the state auditor's office.

The Essential Security Toolbox

From protocol analyzers to vulnerability scanners, here are some tools that can help keep your network secure.

Windows Mobile Dogged by Reliability Issues

Readers appreciate the features of Windows Mobile 5.0, but getting it to work consistently on most devices is difficult.

Set Access Control on Mandatory

Getting past the complexities in Windows Integrity Control.

Exchange 2007: Always On

Exchange 2007 comes equipped to let you use several high availability techniques.

Mobile Devices: Ready To Explode?

Mobile personal devices are very convenient, but often quite dangerous.

Hacker Defaces Microsoft U.K. Web Page

A hacker managed a rare feat Wednesday, successfully attacking a Web page within Microsoft's U.K. domain and replacing the page with several graphics related to Saudi Arabia.

Microsoft Security Worker Called Sixth-Worst Science Job

Employees who work in Microsoft's Security Response Center (MSRC) can breathe easy: they don't have the worst job in science. Just the sixth worst.

Masters of Disaster

Partners do their best to help customers survive the worst.

Ohio Gov.: Stolen Tape Had Taxpayer Info

A missing computer backup tape containing personal information on state employees also holds the names and Social Security numbers of 225,000 taxpayers, Gov. Ted Strickland said.

Cyber Attack Hits Pentagon

The Defense Department took as many as 1,500 computers off line because of a cyber attack, Pentagon officials said Thursday.

Subscribe on YouTube