New worm exploits critical Windows bug

Monday, November 3rd, 2008

A worm that exploits the bug Microsoft Corp. patched in an emergency update 11 days ago is actively attacking systems, several security companies and researchers said today.The worm, which Symantec Corp. called Wecorl but was dubbed MS08-067.g by Kaspersky Lab and Microsoft itself, likely originated in China, said Kevin Haley, ...

Gooscan - Automated Google Hacking Tool

Monday, November 3rd, 2008

Gooscan is a tool that automates queries against Google search appliances, but with a twist. These particular queries are designed to find potential vulnerabilities on web pages. Think “cgi scanner” that never communicates directly with the target web server, since all queries are answered by a Google appliance, not by ...

Microsoft to Issue Emergency Security Update Today

Thursday, October 23rd, 2008

Microsoft said late Wednesday that it plans to break out of its monthly patch cycle to issue a security update today for a critical vulnerability in all supported versions of Windows. Redmond rarely releases security patches outside of Patch Tuesday, the second Tuesday of each month. The software giant isn't providing ...

Adobe fixes clickjacking flaw

Thursday, October 16th, 2008

Adobe Systems has released a new version of its Flash Player software, fixing a critical security bug that could make the Internet a dangerous place for Web surfers. The new Flash Player 10 software, released Wednesday, fixes security flaws in Adobe's multimedia software including bugs that could allow hackers to pull ...

Exploit code loose for six-month-old Windows bug

Friday, October 10th, 2008

Microsoft Corp. yesterday acknowledged that exploit code is circulating for a vulnerability it acknowledged six months ago, but has yet to patch. It's not clear whether Microsoft intends to fix the flaw next week. On Thursday, Microsoft revised a security advisory it first posted April 19 about a bug in Windows XP, ...