Firefox Extension Blocks Dangerous Web Attack

Wednesday, October 8th, 2008

A popular free security tool for the Firefox browser has been upgraded to block one of the most dangerous and troubling security problems facing the Web today. NoScript is a small application that integrates into Firefox. It blocks scripts in programming languages such as JavaScript and Java from executing on untrusted ...

Google Chrome vulnerable to carpet-bombing flaw

Tuesday, September 2nd, 2008

Google’s shiny new Web browser is vulnerable to a carpet-bombing vulnerability that could expose Windows users to malicious hacker attacks. Just hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities — a flaw in Apple Safari (WebKit) and a Java bug discussed at ...

Vista’s Security Rendered Completely Useless by New Exploit

Thursday, August 7th, 2008

This week at the Black Hat Security Conference two security researchers will discuss their findings which could completely bring Windows Vista to its knees.Mark Dowd of IBM Internet Security Systems (ISS) and Alexander Sotirov, of VMware Inc. have discovered a technique that can be used to bypass all memory protection ...

A photo that can steal your online credentials

Monday, August 4th, 2008

At the Black Hat computer security conference in Las Vegas next week, researchers will demonstrate software they've developed that could steal online credentials from users of popular Web sites such as Facebook, eBay, and Google.The attack relies on a new type of hybrid file that looks like different things to ...

Security researcher publishes exploit toolkit

Tuesday, July 29th, 2008

An Argentinian security researcher has published a security exploit toolkit targeting the update mechanisms of Java, Mac OS X, OpenOffice.org and other software, and relying on man-in-the-middle techniques such as those made possible by the recently disclosed DNS security hole. The toolkit, ISR-Evilgrade 1.0, was released by Francisco Amato, a researcher ...