New attack kit targets bag of ActiveX bugs

Monday, April 7th, 2008

Hackers are using a new multiple-attack package composed of seven ActiveX exploits, many of them never seen in the wild before, said a security company on Friday. Fewer than half of the flawed ActiveX controls have been patched. The attack framework probes Windows PCs for vulnerable ActiveX controls from software vendors Microsoft, ...

Password theft via vulnerability in Google code

Monday, April 7th, 2008

Billy Rios has discovered a vulnerability in the Google Code service which could be exploited to steal passwords from developers who have registered on the site. The Google Security Team has since fixed the vulnerability. Rios succeeded in gaining cross-domain access by uploading a crafted Java applet to a project on ...

Before Patch Tuesday, There Were Malware

Monday, April 7th, 2008

Recycling an old social engineering technique and using two different attack methods, a new spam run emerges as a threat to Web users before Microsoft’s Patch Tuesday. And not because it exploits soon-to-be named vulnerabilities. What this spamming operation takes advantage of is the anticipation itself for the release of patches ...

Snort 2.8.1 Released

Thursday, April 3rd, 2008

New Additions Target-Based support to allow rules to use an attribute table describing services running on various hosts on the network. Eliminates reliance on port-based rules. Support for GRE encapsulation for both IPv4 & IPv6. Support for IP over IP tunneling for both IPv4 & IPv6. SSL preprocessor to allow ability to not inspect ...

Microsoft Plans Five ‘Critical’ Security Updates For Windows, Explorer

Thursday, April 3rd, 2008

Microsoft said Thursday that it plans to release eight software updates for the Windows operating system and Internet Explorer Web browser to patch security holes, five of which the company described as "critical."Microsoft said it plans to release the updates on April 8. PC users can determine if they need ...