Dennis Fisher

About

Dennis Fisher is a journalist with more than 13 years of experience covering information security.

New Flaw Found in Microsoft SharePoint

There is a cross-site scripting flaw in SharePoint 2007, Microsoft’s collaboration product, which could give an attacker the ability to execute arbitrary JavaScript code on a machine through a browser.


The new piece of malware that surfaced this week and has been hailed as a return of the Storm worm, is in fact simply the worm’s original spam engine with some new components wrapped around it, researchers say, and not a rebirth of the botnet itself.

A fresh batch of malicious PDFs is making the rounds via email, with the attackers trying to trick users into opening the files by making them look like instructions for an update to their email accounts. The difference this time, however, is that the attack uses a technique recently published by a researcher that takes advantage of the /launch command in Adobe software.

It’s no secret to anyone who has been paying attention that Adobe Reader and Acrobat have become prime targets for attackers in the last year or so, but new research shows just how dramatic the increase has been in the number of high-risk vulnerabilities identified in Adobe products recently.

A pair of security researchers has discovered a number of new attack vectors that give them the ability to not only locate any GSM mobile handset anywhere in the world, but also find the name of the subscriber associated with virtually any cellular phone number, raising serious privacy and security concerns for customers of all of the major mobile providers.