How Snow Leopard can save Mac OS X from malware attacks 23 Jun 2008 23:49 GMTGuest Editorial by Dino Dai Zovi As reported by Intego and Matasano Security, a new local privilege escalation vulnerability has been found that gives local root access on Mac OS X Tiger and Leopard. While Intego calls this a critical vulnerability, I'm mostly with...
Source: ZDNet Demo exploits posted for unpatched MS Word vulnerability 23 Jun 2008 16:16 GMTA security researcher has released demo exploits for what appears to be a critical -- unpatched -- memory corruption vulnerability affecting the ubiquitous Microsoft Word software program. The proof-of-concept exploits accompany a warning that the flaw affects Microsoft Office 2000 and Microsoft Office 2003. In addition to...
Source: ZDNet News to Know: Googlenomics; Windows Mobile 7 phones; Broadband hell 23 Jun 2008 10:07 GMTNotable headlines: Ryan Naraine: Free Sourcefire tool pinpoints hostile MS Office files Apple security team finds code execution holes in Ruby Google using invalid security certificate Dancho Danchev: Phishers targeting Facebook users, fake logins...
Source: ZDNet Attack Vector 23 Jun 2008 04:01 GMTA new report on security breaches leads Frank Hayes to conclude that your company's business partners should be treated like worst enemies.

Source: Computerworld Seeking Dollars for Scholars 23 Jun 2008 04:01 GMTA doctorate in information security entices our security manager. But how will she pay for one?

Source: Computerworld Global Dispatches 23 Jun 2008 04:01 GMTChinese police arrested a 19-year-old man for allegedly issuing a fake online earthquake warning; Citrix disclosed plans to open a second R&D facility in India.

Source: Computerworld Software Update Snafus Block Microsoft Patches 23 Jun 2008 04:01 GMTMicrosoft scrambled to fix a flaw in a patch-distribution tool that blocked some systems administrators from installing its latest batch of security fixes on PCs.

Source: Computerworld Microsoft targets password stealers 21 Jun 2008 08:51 GMTMicrosoft's June 10 update of its Malicious Software Removal Tool MSRT was updated to detect and remove game password-stealing malware. The results are pretty amazing - more than 2 million PCs disinfected in the first week (out of some 330 million downloads of the MSRT). by Adrian Kingsley-Hughes
Source: ZDNet Security researcher keeps "Carpet Bomb" attack alive, despite patch 21 Jun 2008 08:16 GMTSecurity research Billy Rios posted an article today about the Apple Safari "Carpet Bomb" attack, discussing a new issue that, despite the patch which prevented a "blended" remote command execution attack when Safari was used in conjunction with IE on a Windows system, keeps the "Carpet Bomb" attack alive and well. ...
Source: ZDNet