Last updated:
Wed May 16 19:07:11 2012 GMT
  2011 FIRST Annual Conference in Vienna - Register now


Recent bugs
via SecurityFocus,
IBM Cognos TM1 Admin Server Remote Buffer Overflow Vulnerability
Linux Kernel HFS Plus Filesystem Local Buffer Overflow Vulnerability
Bind DynDB LDAP 'bind-dyndb-ldap' Package Remote Denial of Service Vulnerability
RETIRED: Serendipity SQL Injection and Cross Site Scripting Vulnerabilities
Serendipity SQL Injection and Cross Site Scripting Vulnerabilities
WordPress WP-FaceThumb 'pagination_wp_facethum' Parameter Cross Site Scripting Vulnerability
Apple Mac OS X QuickTime CVE-2012-0658 Movie File Handling Buffer Overflow Vulnerability
Apple Mac OS X CVE-2011-3460 Buffer Overflow Vulnerability
Apple Mac OS X CVE-2011-3458 Remote Code Execution Vulnerability
FFmpeg Multiple Remote Vulnerabilities
Recent advisories
via Secunia, US-CERT,
TA12-073A: Microsoft Updates for Multiple Vulnerabilities
TA12-045A: Microsoft Updates for Multiple Vulnerabilities
TA12-024A: "Anonymous" DDoS Activity
TA12-010A: Microsoft Updates for Multiple Vulnerabilities
TA12-006A: Wi-Fi Protected Setup (WPS) Vulnerable to Brute-Force Attack
TA11-350A: Adobe Updates for Multiple Vulnerabilities
TA11-347A: Microsoft Updates for Multiple Vulnerabilities
TA11-312A: Microsoft Updates for Multiple Vulnerabilities
TA11-286A: Apple Updates for Multiple Vulnerabilities
TA11-284A: Microsoft Updates for Multiple Vulnerabilities
TA11-256A: Microsoft Updates for Multiple Vulnerabilities
TA11-222A: Adobe Updates for Multiple Vulnerabilities
TA11-221A: Microsoft Updates for Multiple Vulnerabilities
TA11-201A: Oracle Updates for Multiple Vulnerabilities
TA11-200A: Security Recommendations to Prevent Cyber Intrusions
TA11-193A: Microsoft Updates for Multiple Vulnerabilities
TA11-165A: Microsoft Updates for Multiple Vulnerabilities
TA11-166A: Adobe Updates for Multiple Vulnerabilities
TA11-130A: Microsoft Updates for Multiple Vulnerabilities
TA11-102A: Microsoft Updates for Multiple Vulnerabilities
Bugtraq Topics
via SecurityFocus,
Trigerring Java code from a SVG image
[ MDVSA-2012:075 ] ffmpeg
[SECURITY] [DSA 2457-2] New icedove/iceweasel packages fix regression
[ MDVSA-2012:074 ] ffmpeg
[ MDVSA-2012:076 ] ffmpeg
Re: rssh security announcement
Universal Reader Filename Denial Of Service Vulnerability
Liferay users can assign themselves to organizations, leading to possible privilege escalation
b2ePMS 1.0 Authentication Bypass Vulnerability
[SECURITY] [DSA 2670-1] wordpress security update
Top Worms and Viruses
via Sophos,
Troj/Invo-Zip
W32/Netsky
Mal/EncPk-EI
Troj/Pushdo-Gen
Troj/Agent-HFU
Mal/Iframe-E
Troj/Mdrop-BTV
Troj/Mdrop-BUF
Troj/Agent-HFZ
Troj/Agent-HGT
Latest MS bulletins
via Microsoft,
MS11-703 - Important: Test MNP bulletin #3 (test0703)
MS11-702 - Moderate: Test MNP bulletin #2 (test0702)
MS11-701 - Low: Test MNP bulletin #1 (test0701)
MS11-069 - Moderate: Vulnerability in .NET Framework Could Allow Information Disclosure (2567951)
MS11-068 - Moderate: Vulnerability in Windows Kernel Could Allow Denial of Service (2556532)
MS11-067 - Important: Vulnerability in Microsoft Report Viewer Could Allow Information Disclosure (2578230)
MS11-066 - Important: Vulnerability in Microsoft Chart Control Could Allow Information Disclosure (2567943)
MS11-065 - Important: Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (2570222)
MS11-064 - Important: Vulnerabilities in TCP/IP Stack Could Allow Denial of Service (2563894)
MS11-063 - Important: Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2567680)
Stock Watch
via Yahoo! Finance
Updated 5/16/2012
NASDAQ 2880.76 -13.00
JNPR 17.41 -0.26
SYMC 15.15 -0.20
CSCO 16.72 +0.18
MFE 0.00 N/A
CKP 7.87 -0.42
MSFT 29.92 -0.29
IBM 200.78 +1.74
INTC 26.68 -0.20
AMD 6.445 -0.155
SNWL 0.00 N/A
CIC.TO 9.21 -0.04
CA 25.86 -0.30
TMICY.PK 28.53 +0.16
WBSN 18.84 -0.02
BCSI 0.00 N/A
SCLD 0.00 N/A
CWDW.OB 0.00 N/A
VRSN 40.255 +0.465
INTZ.OB 0.5992 unch
TMWD 0.00 N/A
PKTR 0.00 N/A
FIRE 52.58 +0.40

 

Recent News

Cisco Tackles BYOD Challenge with 'Smart Solutions'
Enterprise Security Today
Cisco on Wednesday offered up findings from its "bring your own device" study and used the results as a jumping off point to announce new mobility solutions. But can Cisco carve out a niche in the nascent BYOD services space?

The Cisco IBSG Horizons S

The Pirate Bay suffers DDoS attack
Techworld.com Security News
The controversial file-sharing website The Pirate Bay has experienced a distributed denial of service attack, according to the site’s Facebook page.

Android malware using real apps as disguise 'wrappers'
Techworld.com Security News
Mobile malware stepped up an order of magnitude in volume and sophistication during 2011 and this trend has continued in the first quarter of 2012, according to F-Secure’s latest quarterly report.Avira Antivirus false positives http://forum.avira.com/wbb/index.php?page=Thread&threadID=144875, (Wed, May 16th)
SANS Internet Storm Center, InfoCON: green
------ Johannes B. Ullrich, Ph ...(more)...

Researchers Use Virus To Generate Electricity
Enterprise Security Today
Viruses have gotten a bad rap for their role in colds, diseases and malware. But now the reputation of some viruses is being redeemed, as researchers in California have developed a way to use them for the creation of electricity.

The technology work

10 hacks that made headlines
Techworld.com Security News
Here are ten hacking incidents through history that made some of the biggest headlines.

<

Angry Birds meest geblokkeerde app binnen bedrijven
Security.NL nieuws
Het zeer populaire spel Angry Birds is de meest geblokkeerde applicatie binnen bedrijven.

Zeer ernstig lek in Pidgin Off-the-Record
Security.NL nieuws
Een ernstig beveiligingslek in een populaire plug-in voor chatprogramma Pidgin zorgt ervoor dat aanvallers kwetsbare systemen kunnen overnemen.

Wikipedia waarschuwt voor advertentie-malware
Security.NL nieuws
Wikipedia waarschuwt bezoekers dat als ze malware op de populaire gratis encyclopedie te zien krijgen, hun computer met malware is besmet.

Finse WiFi-eigenaar niet aansprakelijk voor illegale downloads
Security.NL nieuws
Een Finse rechter heeft bepaald dat eigenaren van een open WiFi-netwerk niet verantwoordelijk zijn voor illegaal materiaal dat via het access point wordt gedownload.

DSA-2472 gridengine
Debian Security
privilege escalation

Google unleashes Chrome 19, flattens 20 bugs
The Register - Security

Hot fuzz spawns QuickTime patch

Google released a major update to its Chrome browser on Tuesday that tackles 20 security vulnerabilities, eight of which are classified as high-risk bugs.


Reserved IP Address Space Reminder, (Wed, May 16th)
SANS Internet Storm Center, InfoCON: green
As we are running out of IPv4 address space, many networks, instead of embracing IPv6, stretch exist ...(more)...

New Version of Google Chrome released (19.0.1084.46) , (Wed, May 16th)
SANS Internet Storm Center, InfoCON: green
------ Johannes B. Ullrich, Ph ...(more)...

Multiple Web Vulnerabilities Expose MobileSpy App to Attacks, Experts Say
Hack In The Box

Wikipedia warns users about malware injecting ads
LinuxSecurity.com - Latest News
LinuxSecurity.com: Visitors to Wikipedia who see advertisements on the site have most likely fallen victim to a browser-based malware infection, Wikimedia Foundation, the organization operating the website, said on Monday.

Apple Mac Flashback Trojan Gang Still Making Money
LinuxSecurity.com - Latest News
LinuxSecurity.com: The prolific Flashback Trojan that has infected anywhere from a half a million to nearly 1 million Macintosh machines worldwide remains active despite Apple's emergency security update, and its owners continue to rake in revenue

10 hacks that made headlines
LinuxSecurity.com - Latest News
LinuxSecurity.com: In our first Rogues Gallery, we looked at ten infamous social engineers -- con men who exploited human weaknesses rather than technical vulnerabilities.

First Look at Dynamic Access Control in Windows Server 2012
WindowSecurity.com
The author takes a look at Dynamic Access Control in Windows Server 2012.

US firms over-reliant on firewalls to defend against DDoS attacks
Techworld.com Security News
More than half of US businesses still rely on conventional firewalls or intrusion prevention systems to shield them from the scourge of DDoS attacks, a survey by services firm Neustar has found.Avira antivirus upgrade wreaks 'catastrophic' havoc on Windows PCs
Techworld.com Security News
Avira has issued a service pack for its antivirus software that crippled an unknown number of Windows machines, with one customer calling the gaffe "catastrophic" to his company.[Achtergrond] Juridische vraag: verbiedt netneutraliteit virusfilter?
Security.NL nieuws
Heb jij een uitdagende vraag over beveiliging, recht en privacy, stel hem aan ICT-jurist Arnoud Engelfriet en maak kans op zijn boek "Security: Deskundig en praktisch juridisch advies". Vraag: Ik las dat netneutraliteit er door is.

SNS lanceert app voor mobiel bankieren
Security.NL nieuws
De SNS Bank heeft een app gelanceerd om klanten mobiel te laten bankieren, waarmee de bank ING, Rabobank en ABN Amro volgt.

Gratis Windows-tool wapent bedrijven tegen hackers
Security.NL nieuws
Microsoft heeft het voor bedrijven makkelijker gemaakt om zich via een gratis tool tegen hackers en malware te wapenen.

Sogeti gaat Nederlandse bedrijven 'social engineeren'
Security.NL nieuws
IT-bedrijf Sogeti organiseert tijdens de Hack in the Box conferentie in Amsterdam een wedstrijd om de Top 100 Nederlandse bedrijven te social engineeren.

Windows weer kwetsbaar door QuickTime
Security.NL nieuws
Apple heeft een nieuwe versie van QuickTime uitgebracht die verschillende lekken verhelpt waardoor Windows-gebruikers risico liepen.

'Catastrophic' Avira antivirus update bricks Windows PCs
The Register - Security

rundll32.exe? cmd.exe? You clearly don't need those

Security software biz Avira has apologised after its antivirus suites went haywire and disabled customers' Windows machines.


Got Packets? Odd duplicate DNS replies from 10.x IP Addresses, (Wed, May 16th)
SANS Internet Storm Center, InfoCON: green
This is a clarification to Dan's diary from yesterday. We are interested to hear, if anybody else is ...(more)...

Microsoft released an update for its Enhanced Mitigation Experience Tool (EMET) http://blogs.technet.com/b/srd/archive/2012/05/15/introducing-emet-v3.aspx, (Wed, May 16th)
SANS Internet Storm Center, InfoCON: green
------ Johannes B. Ullrich, Ph ...(more)...

Apple Product Security - QuickTime 7.7.2 (APPLE-SA-2012-05-15-1)
Help Net Security - Advisories
APPLE-SA-2012-05-15-1 QuickTime 7.7.2 QuickTime 7.7.2 is now available and addresses the following: QuickTime Available for: Windows 7, Vista, XP SP2 or later Impact: Visiting a maliciously ...

Gentoo Linux Security Advisory - ConnMan: Multiple vulnerabilities (GLSA 201205-02)
Help Net Security - Advisories
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201205-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - ...

Debian Security Advisory - gridengine (DSA-2472-1)
Help Net Security - Advisories
- ------------------------------------------------------------------------- Debian Security Advisory DSA-2472-1 security@debian.org http://www.debian.org/security/ ...

Vigil@nce - libpng: buffer overflow via png_decompress_chunk, analyzed on 16/02/2012
Vigil@nce - public vulnerabilities
An attacker can invite the victim to open a malicious PNG image with an application linked to libpng, in order to create an overflow, which stops the application, or leads to code execution.

Vigil@nce - Citrix XenServer Web Self Service: multiple vulnerabilities, analyzed on 16/02/2012
Vigil@nce - public vulnerabilities
An attacker can use several vulnerabilities of the Web Self Service component of Citrix XenServer.

Angry Birds tops corporate mobile blacklist, Facebook, YouTube follow
Techworld.com Security News
Research by mobile device management firm Zenprise found that Angry Birds was the most-blacklisted application among users enrolled in its Zencloud MDM service

Kamermeerderheid wil vingerafdruk uit paspoort
Security.NL nieuws
Als het aan een meerderheid in de Tweede Kamer ligt, verdwijnt de vingerafdruk uit het paspoort.

Avira update verlamt miljoenen computers
Security.NL nieuws
Een defecte update voor Avira Anti-virus heeft miljoenen computers wereldwijd verlamd.

Virusscanners filteren meeste besmette websites
Security.NL nieuws
Websites die bezoekers via drive-by downloads proberen te infecteren of malware bevatten, worden in de meeste gevallen door virusscanners herkend.

Microsoft ontdekt lek in Google Chrome
Security.NL nieuws
Google heeft Chrome 19 gelanceerd, waarin het 20 beveiligingslekken verhelpt.

Mensenrechtenorganisaties doelwit cyberspionage
Security.NL nieuws
De afgelopen maanden zijn verschillende websites van mensenrechtenorganisaties en NGO's gehackt, wat onderdeel van een omvangrijke cyberspionagecampagne is.

LightSquared's bankruptcy is a cautionary tale
Hack In The Box

EU to 'remain vigilant' on Microsoft's browser commitments
Hack In The Box
Apple argues plaintiffs are too vague in class action lawsuit over Siri
Hack In The Box
NVIDIA virtualizes the GPU for streamed desktops and cloud gaming
Hack In The Box
MPAA: Censorship Good For Consumers, Will Help Innovation
Hack In The Box
Older News

Wikipedia warns users about malware injecting ads into its pages
Hack In The Box

Angry Birds tops corporate mobile blacklist, Facebook, YouTube follow
Hack In The Box

Researchers harness engineered viruses to produce electrical energy
Hack In The Box

Google fixes 18 Chrome glitches, enables tab syncing
Hack In The Box

Tenable Network Security Creates A Gibson-esque Network Visualizer
Hack In The Box

Sogeti Netherlands Aims Social Engineering and CTF Challenge at Top 100 Dutch Companies
Hack In The Box

Stuxnet cyberwar, says US Army Cyber Command officer
The Register - Security

Hackers booby-trap foreign policy group websites
Yahoo! News: Security News

Microsoft readies NUads: They watch you watching them
CNET News.com - Security

ISC StormCast for Wednesday, May 16th 2012 http://isc.sans.edu/podcastdetail.html?id=2536, (Wed, May 16th)
SANS Internet Storm Center, InfoCON: green

Utah tech director resigns in wake of data theft
Yahoo! News: Security News

Apple QuickTime update for Windows only; Macs already secure
CNET News.com - Security

Avira update blocked Windows applications
CNET News.com - Security

Sophos Offers Partners New Complete Security Suites To Meet Clients' Changing Needs
Sophos security news

Check Out Your Cloud Service Providers, Experts Advise
Enterprise Security Today

Epicom Honored as SugarCRM Partner of the Month
Enterprise Security Today

CTIA Wireless Kicks Off in New Orleans
Enterprise Security Today

Patch Tuesday Breeds Confusion with Hodgepodge Bulletin
Enterprise Security Today

Cloud Has a Silver Lining for Interop Conference
Enterprise Security Today

U.S. Natural Gas Sector Hit by Coordinated Cyber Attacks
Enterprise Security Today

Court Won't Order Google-NSA Interactions Released
Enterprise Security Today

Computer Crashes and Lost Data: Avoid the Next Mishap
Enterprise Security Today

Security Firm Says Apple Asking for Assessment
Enterprise Security Today

LiveTime Reduces Government IT Resource Costs
Enterprise Security Today

Scammers exploit wannabe demon-slayers hyped by Diablo III
The Register - Security

Odd DNS replies from 10 nets and RFC1323 impacting firewalls, (Tue, May 15th)
SANS Internet Storm Center, InfoCON: green

Ubuntu Security Notice - quagga vulnerabilities (USN-1441-1)
Help Net Security - Advisories

Mandriva Linux Security Update Advisory - ffmpeg (MDVSA-2012:075)
Help Net Security - Advisories

MS12-017 - Important : Vulnerability in DNS Server Could Allow Denial of Service (2647170) - Version: 1.1
Microsoft Security Bulletins

Defensie looft 200.000 euro uit voor cyber-idee
Security.NL nieuws

Bitcoin bank Bitcoinica still titsup after cyberheist
The Register - Security

Rebekah Brooks charged in phone-hacking scandal
CNET News.com - Security

Bots dominate small Web site traffic, research shows
CNET News.com - Security

Pod2g Hints iOS 5.1.1 Jailbreak to be Released During #HITB2012AMS?
Hack In The Box

Ethical hacking can help businesses improve security strategies
LinuxSecurity.com - Latest News

Why you don't need a firewall
LinuxSecurity.com - Latest News


all content is copyright its respective owner or owners. the tools and components behind this page are copyright © 2003-2010 jose nazario, all rights reserved. this page is available as RSS 2.0.