ARN

exploits and vulnerabilities

  • Hackers exploit latest IE zero-day with drive-by attacks 11 March, 2010 06:26:00

    Researchers expect attacks to explode once exploit code goes public
    Hackers are exploiting the just-disclosed unpatched bug in Internet Explorer (IE) to launch drive-by attacks from malicious Web sites, security researchers said today.
  • Microsoft warns of new IE bug; attacks under way 10 March, 2010 06:27:00

    It's the second zero-day vulnerability in the last 60 days
    Microsoft today warned of a critical vulnerability in Internet Explorer that is already being exploited by hackers, the second such admission in the last two months.
  • New exploit technique nullifies major Windows defense 04 March, 2010 06:23:00

    Google engineer posts sample code to show how to bypass DEP in Windows
    The disclosure of a new exploit technique that bypasses an important Windows security feature may result in more successful attacks against Microsoft's newer operating systems, researchers said today.
  • IBM: Vulnerabilities fell in 2009, but other risks abound 26 February, 2010 08:08:00

    IBM's latest X-Force report says there are fewer software bugs overall, but many in document and multimedia applications
    The number of software vulnerabilities fell overall in 2009, but the number of bugs in document readers and multimedia applications increased by 50 percent, according to IBM's annual X-Force Trend and Risk Report.
  • Twitter forces password reset to protect some accounts 04 February, 2010 05:48:00

    The company has discovered that log-in information has been stolen in compromised torrent file-sharing sites
    Twitter required some users to reset their passwords on Tuesday after discovering that their log-in information may have been harvested via security-compromised torrent Web sites, the company said.
  • Why traditional security doesn't work for SOA 19 January, 2010 07:38:00

    SOA's strengths turn out to be highly exploitable entry points for attackers
    Many organizations are embracing SOA as a way to increase application flexibility, make integration more manageable, lower development costs, and better align technology systems to business processes. The appeal of SOA is that it divides an organization's IT infrastructure into services, each of which implements a business process consumable by users and services.
  • Adobe warns of Reader, Acrobat attack in the wild 16 December, 2009 06:46:00

    The flaw has been used in limited attacks since Friday
    Adobe is investigating new reports that hackers are attacking a previously unknown bug in the latest version of the company's Reader and Acrobat software.
  • After code is released, Adobe Illustrator fix due Jan 8 08 December, 2009 12:15:00

    The zero-day attack was released last week
    Nearly a week after an unidentified hacker posted attack code that exploits a flaw in Adobe's Illustrator software, the company says it will fix the issue by Jan. 8.
  • Metasploit releases IE attack, but it's unreliable 27 November, 2009 08:23:00

    The code is not as reliable as first thought
    Developers of the open-source Metasploit penetration testing toolkit have released code that can compromise Microsoft's Internet Explorer browser, but the software is not as reliable as first thought.
  • Attacks appear imminent as IE exploit is improved 26 November, 2009 08:36:00

    The attack, first released on Friday, is made more reliable
    Hackers working on the open-source Metasploit project have spiffed up a zero-day attack on Microsoft's Internet Explorer, making it more reliable -- and more likely to be used by criminals.
  • Microsoft issues security advisory on IE vulnerability 25 November, 2009 08:49:00

    Exploit code released over weekend for browser attack
    Microsoft Monday night issued a security advisory that provides customers with guidance and workarounds for dealing with a zero-day exploit aimed at Internet Explorer.
  • New attack fells Internet Explorer 23 November, 2009 08:09:00

    The zero-day flaw is unreliable, but Symantec expects reliable exploits in the 'near future'
    A hacker has posted attack code that could be used to break into a PC running older versions of Microsoft's Internet Explorer browser.
  • Security pro says new SSL attack can hit many sites 22 November, 2009 08:17:00

    The researcher has developed generic attack code, but is keeping it private.
    A Seattle computer security consultant says he's developed a new way to exploit a recently disclosed bug in the SSL protocol, used to secure communications on the Internet. The attack, while difficult to execute, could give attackers a very powerful phishing attack.
  • Developer finds major coding errors in Facebook, MySpace 06 November, 2009 08:29:00

    The simple problems may have exposed users' data for an unknown length of time
    Social-networking sites MySpace and Facebook have apparently fixed coding errors that could have allowed an attacker access to all of their users' data and photos.
  • Java, BlackBerry desktop get security bug fixes 05 November, 2009 09:25:00

    Sun releases critical update to Java Runtime Environment
    Sun Microsystems and Research In Motion have issued critical bug fixes for security issues with their products.
More >
Syndicate content
 
Jobs
ARN Vendor Directory
ARN Library

Microsoft Anti-Piracy Infringement Alert

The Microsoft Anti-Piracy Newsletter outlines what Microsoft is doing to protect your business from Software Piracy and highlights recent legal action taken against those who infringe our copyright.