All major browsers fall during second day at Pwn2Own hacking contest

Friday, March 14th, 2014

Security researchers demonstrated zero-day exploits against Google Chrome, Microsoft Internet Explorer, Apple Safari, Mozilla Firefox and Adobe Flash Player during the second day of the Pwn2Own hacking competition Thursday, racking up total prizes of US$450,000. A team from French vulnerability research firm Vupen hacked Google Chrome by exploiting a use-after-free vulnerability ...

New variant of Zeus banking trojan concealed in JPG images

Tuesday, February 18th, 2014

A new variant of the nefarious Zeus banking trojan – dubbed ZeusVM – is concealed in JPG image files, according to the collaborative findings of Jerome Segura, senior security researcher with Malwarebytes, and French security researcher Xylitol. The act is known as steganography – concealing messages or images in other messages or images. In ...

New IE Zero-Day Found in Watering Hole Attack

Thursday, February 13th, 2014

FireEye Labs has identified a new Internet Explorer (IE) zero-day exploit hosted on a breached website based in the U.S. It’s a brand new zero-day that targets IE 10 users visiting the compromised website–a classic drive-by download attack. Upon successful exploitation, this zero-day attack will download a XOR encoded payload ...

Adobe releases patch for Flash zero-day

Wednesday, February 5th, 2014

Adobe has released a fix for a zero-day vulnerability in Flash Player, which impacts users running Windows, Mac and Linux operating systems. On Tuesday, the company made the updates available via a security bulletin, urging Windows and Mac users to download Flash Player versions 12.0.0.44 and 11.7.700.261 (for those who cannot ...

More than 180K Chrome users have installed ad-injecting extensions

Tuesday, February 4th, 2014

More than 180,000 Google Chrome users have installed at least one of a dozen ad-injecting extensions that are serving up spam on 44 different websites, according to findings by the threat and research analysis team with Barracuda Labs. As of Jan. 30, the “logo quiz game” extension has been installed by nearly 82,000 ...