Ryan Naraine

July 28, 2010, 8:24PM Threatpost Original

Hacker Demos Remote Attacks Against ATMs

LAS VEGAS -- Using home-brewed software tools and exploiting a gaping security hole in the authentication mechanism used to update the firmware on automated teller machines (ATMs), a security researcher hacked into ATMs made by Triton and Tranax and planted a rootkit that dispensed cash on demand.

Shorten URL: http://threatpost.com/en_us/c17. Click to copy to clipboard or post to Twitter

July 28, 2010, 2:54PM Threatpost Original

Microsoft Ships Anti-Exploit Tool for IT Admins

LAS VEGAS -- Microsoft today released a new tool to help IT administrators backport anti-exploit mitigations like ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) to older versions of Windows.

Shorten URL: http://threatpost.com/en_us/c1I. Click to copy to clipboard or post to Twitter

July 28, 2010, 2:04PM Threatpost Original

Adobe to Share Vulnerability Data with Security Vendors

LAS VEGAS -- Adobe's push to beef up its security posture took another leap forward here with the announcement of plans to start sharing details on software vulnerabilities with security vendors ahead of time to help reduce the window of exposure to hacker attacks.

Shorten URL: http://threatpost.com/en_us/c1B. Click to copy to clipboard or post to Twitter

July 22, 2010, 1:42PM Threatpost Original

Safari AutoFill Feature Exposes User Data

A prominent security researcher is urging users of Apple’s Safari browser to immediately turn off the AutoFill feature to block hackers from stealing sensitive information.

According to Jeremiah Grossman, founder and Chief Technology Officer of WhiteHat Security, the AutoFill Web Forms feature can be hacked to steal data from the computer’s address book.

Shorten URL: http://threatpost.com/en_us/cxz. Click to copy to clipboard or post to Twitter

July 22, 2010, 10:21AM Threatpost Original

Cisco Plugs Code Execution Hole in CDS Internet Streamer

Cisco has shipped a critical bulletin to warn about a serious security hole in the Cisco Internet Streamer application, which is part of the Cisco Content Delivery System.

In an advisory, Cisco warned that exploitation of this vulnerability may allow a remote, unauthenticated attacker to obtain sensitive information, including password files and system logs.

Shorten URL: http://threatpost.com/en_us/cxy. Click to copy to clipboard or post to Twitter

July 21, 2010, 11:34AM Threatpost Original

Dell Ships Malware-Infected Server Motherboard

Dell has confirmed that some of its PowerEdge server motherboards were shipped to customers with malware code on the embedded server management firmware.

The infected motherboard was found on replacement Dell PowerEdge R410 rack servers, according to a post on a Dell support forum.

Shorten URL: http://threatpost.com/en_us/ccJ. Click to copy to clipboard or post to Twitter

July 21, 2010, 10:05AM Threatpost Original

Firefox Hit by Drive-by Download Flaws

Mozilla has shipped a mega patch for Firefox to fix a total of 16 security flaws that expose Web surfers to drive-by download, data theft and local bar spoofing attacks.

The latest Firefox 3.6.7 update includes fixes for nine "critical" issues that could be exploited to launch remote code execution attacks.  Two of the 16 bugs are rated "high risk" while five carry a "moderate" severity rating.

Shorten URL: http://threatpost.com/en_us/cco. Click to copy to clipboard or post to Twitter

July 20, 2010, 11:34AM Threatpost Original

'Protected Mode' Brings Sandbox to Adobe Reader

The next major version of Adobe's PDF Reader will feature new sandboxing technology aimed at curbing a surge in malicious hacker attacks against the widely deployed software.

The security feature, called "Protected Mode," is similar to the Google Chrome sandbox and Microsoft Office 2010 Protected Viewing Mode, according to Adobe's security chief Brad Arkin.

Shorten URL: http://threatpost.com/en_us/cca. Click to copy to clipboard or post to Twitter

July 19, 2010, 6:01PM Threatpost Original

Apple Ships Critical iTunes for Windows Patch

Apple has shipped a critical iTunes update to fix a security vulnerability that exposes Windows users to malicious hacker attacks.

The latest iTunes 9.2.1 is available for Windows XP, Windows Vista and Windows 7.

Shorten URL: http://threatpost.com/en_us/cOf. Click to copy to clipboard or post to Twitter

July 16, 2010, 11:42AM Threatpost Original

MS Windows Token Kidnapping Problems Resurface

Microsoft's problems with Token Kidnapping [.pdf] on the Windows platform aren't going away anytime soon.

More than a year after Microsoft issued a patch to cover privilege escalation issues that could lead to complete system takeover, a security researcher plans to use the Black Hat conference spotlight to expose new design mistakes and security issues that can be exploited to elevate privileges on all Windows versions including the brand new Windows 2008 R2 and Windows 7.

Shorten URL: http://threatpost.com/en_us/c3M. Click to copy to clipboard or post to Twitter

Syndicate content

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy