Firefox among first browsers to fix DLL load hijacking bug

Posted by admin | Posted in Application Security, Browsers, Firefox, Mozilla, News, Patch management, Security Central | Posted on 08-09-2010

Mozilla on Tuesday patched 15 vulnerabilities in Firefox, 11 of them labeled critical.

One of yesterday’s patches addressed a problem found in scores of Windows applications, making Firefox one of the first browsers to be patched against the DLL load hijacking bug that went public three weeks ago.

Secunia security program automatically tracks down, applies patches

Posted by admin | Posted in Cyber Crime, Data Security, Endpoint security, Hacking, Malware, News, Patch management, Security Central | Posted on 03-09-2010

Secunia has updated its Personal Software Inspector (PSI) with the ability to silently download and apply patches from multiple vendors soon after their release. PSI 2.0 is now available in an open beta test,

Google disputes bug patching report

Posted by admin | Posted in Application Security, Google, News, Patch management, Security Central | Posted on 31-08-2010

Google on Monday said that a recent report claiming it failed to patch a third of the serious bugs in its software had the facts wrong.

IBM’s X-Force security company, which released the report last week, acknowledged the error and issued a revised chart that shows Google patched all the vulnerabilities rated “critical” or “high” in its online services.

Cisco patches bug that caused partial Internet blackout

Posted by admin | Posted in Cisco Systems, Network Testing, Networking, News, Patch management, Security Central, internet | Posted on 30-08-2010

Cisco has fixed a bug in its IOS (Internetwork Operating System) router software that contributed to a brief Internet blackout last week, thought to have affected about 1 percent of the Internet.

Sun, Microsoft, and Mozilla leave the most vulnerabilities unpatched

Posted by admin | Posted in Application Security, Microsoft, Mozilla, News, Patch management, Security Central, Sun Microsystems | Posted on 26-08-2010

Sun is the king of unpatched software vulnerabilities followed closely by Microsoft and Mozilla, according to the mid-year security report by IBM’s X-Force.

Zero-day exploits spur uptick in Adobe updates

Posted by Christina Wood | Posted in Adventures in IT, News, Patch management, Security Central, User Problems, gripe_adobe | Posted on 26-08-2010

Gripe Line reader Scott recently sent out a challenge to find out what’s going on with all those pesky Adobe Reader updates.

“The frequency of these updates is getting quite ridiculous,” he laments. “This is worse than Microsoft ever was before they started their monthly updates. Can someone please find out why they are sending out so many updates lately?”

Apple fixes big security bugs in Mac OS X

Posted by admin | Posted in Mac, Mac OS X, News, Patch management, Security Central | Posted on 24-08-2010

Apple has released a security update to its Mac OS X operating system, fixing 13 critical security issues in the software. The update, released early Tuesday afternoon fixes bugs in various Mac OS X components, including core components such as Apple Type Services and CFNetwork. It’s Apple’s fifth Mac OS X security update this year.

Many open-source Mac OS X components are also patched, including Samba, PHP, and ClamAV software.

Microsoft leaves critical DLL loading bugs unpatched

Posted by admin | Posted in Microsoft, News, Patch management, Security Central, Windows | Posted on 23-08-2010

Microsoft has told a researcher that it won’t patch a problem that has left scores of Windows applications open to attack.

According to a growing number of reports, crucial Windows functionality has been misused by countless developers, including Microsoft’s, leaving a large number of Windows programs vulnerable to attack because of the way they load components.

Google patches 10 Chrome bugs, pays out $10K in bounties

Posted by admin | Posted in Application Security, Applications, Browsers, Google, Google Chrome, News, Patch management, Security Central | Posted on 20-08-2010

Google on Thursday patched 10 vulnerabilities in Chrome, but did not award any of the researchers who reported bugs the new top-dollar reward of $3,133. Google’s most serious threat rating, seven labeled “high” and another pegged as “medium.”

Adobe to patch Reader zero-day bug Thursday

Posted by admin | Posted in Adobe Systems, News, Patch management, Security Central | Posted on 18-08-2010

Adobe Systems said today that it would patch a critical Reader vulnerability on Thursday.

Got Adobe ColdFusion? Start patching

Posted by InfoWorld Tech Watch | Posted in Adobe Systems, News, Patch management, Security Central | Posted on 17-08-2010

Got Adobe ColdFusion? Start patching.

Adobe’s ColdFusion may seem like a legacy product, but in fact more than 12,000 companies still use the Web application platform on more than 125,000 servers, including BMW, Bank of America, and AT&T.

Microsoft: Record number of bug exploits expected

Posted by admin | Posted in Application Security, Malware, Microsoft, News, Patch management, Security Central, Windows | Posted on 12-08-2010

Microsoft warned customers this week that a record number of just-patched bugs will probably be exploited in the next 30 days.

Registry hack tricks Windows XP SP2 into installing security updates

Posted by admin | Posted in Hacking, Microsoft, News, Patch management, Security Central, Windows, Windows XP | Posted on 10-08-2010

People still running the now-retired Windows XP Service Pack 2 (SP2) can trick the operating system into installing security updates, a researcher said Monday.

Data breaches exploit configuration errors, not software vulnerabilities

Posted by admin | Posted in Data Security, Hacking, Intrusion detection and prevention, Malware, News, Patch management, Security Central | Posted on 29-07-2010

Hackers appear to be increasingly counting on configuration problems and programming errors rather than software vulnerabilities in order to steal information from computer systems, according to a new study from Verizon.

Microsoft’s bug reports fail to produce prompt patches

Posted by admin | Posted in Application Security, Microsoft, News, Patch management, Security Central, Windows | Posted on 29-07-2010

Even Microsoft can’t move software makers to patch their products.

According to data released Wednesday by the company, third-party developers patched just 45 percent of the vulnerabilities that Microsoft’s security team reported to them during the 12 months from July 2009 to June 2010.

Apple patches up Safari and rolls out extensions

Posted by InfoWorld Tech Watch | Posted in News, Patch management, Security Central | Posted on 28-07-2010

Apple patches up Safari and rolls out extensions

When Jeremiah Grossman, CTO of WhiteHat Security, announced last week that he had found a security hole in the Safari browser, he certai

Adobe joins Microsoft’s patch-reporting program

Posted by admin | Posted in Adobe Systems, Microsoft, News, Patch management, Security, Security Central | Posted on 28-07-2010

Adobe Systems and Microsoft are now working together to give security companies a direct line into their bug-fixing efforts.

Google patches Chrome, sidesteps Windows kernel bug

Posted by admin | Posted in Browsers, Google, Google Chrome, News, Patch management, Security Central | Posted on 28-07-2010

Google on Monday patched five vulnerabilities in Chrome by issuing a new “stable” build of the browser.

G Data releases tool to block Windows shortcut attacks

Posted by admin | Posted in Malware, Microsoft, News, Patch management, Security Central, Windows | Posted on 27-07-2010

The German security company G Data released a tool on Tuesday that blocks attacks using Microsoft’s shortcut vulnerability but also preserves shortcut icons unlike the hotfix released recently by Microsoft.

Free Sophos tool blocks Windows shortcut attacks

Posted by admin | Posted in Hacking, Malware, News, Patch management, Security Central, Windows | Posted on 27-07-2010

The security firm Sophos released a tool on Monday that it claimed will block any attacks trying to exploit the critical unpatched vulnerability in Windows’ shortcut files.