The iPhone has vulnerabilities. In the past, some have been very serious. Sometimes, Apple takes a very long time to get them fixed.
The security hiccups have done nothing to slow down the sales and usage of the device so it just might be a good idea to go the extra mile to secure the device [...]
Denial of Service attacks are based upon a simple idea: generate the maximum amount of traffic using the minimum amount of work. At one time this was as simple as sending a spoofed ICMP echo packet to a broadcast address or similar shenanigans. Modern DDoS attacks rely upon the unwilling complicity of tens [...]
[ UPDATE: See below for Google’s official response to these issues ]
Security vulnerabilities in the new Google Chrome browser are beginning to pile up.
Following our coverage of the carpet bombing combo threat and denial-of-service crashes, several readers have sent pointers to Chrome exploit code floating around the Web:
First up is an automatic file download [...]
Do you know what that innocent-looking Facebook app is really doing?
Researchers at the Institute of Computer Science (ICS) have created a proof-of-concept Facebook application capable of covertly herding users of the popular social network into a powerful — and malicious — botnet.
The demo application, called Photo of the Day, delivers a different image from National [...]
In the wake of the recent malvertising attacks where malicious flash ads were appearing at trusted web sites, evidence from multiple vendors and researchers indicates that spammers and malware authors have once again switched tactics, and are one again abusing legitimate services such as Google’s Picasa and ImageShack. Whereas the technique is nothing new, and [...]
Microsoft today announced plans to ship four security bulletins next Tuesday (September 9, 2008) to cover worm holes affecting Windows users.
All four bulletins in September’s Patch Tuesday will be rated “critical,” Microsoft’s highest severity rating. A “critical” rating is used to rate a vulnerability that can be exploited to allow the propagation of an Internet [...]
Whoa! Google Chrome has crashed. Restart now? While Google’s Chrome team is cheering, Rishi Narang from Evil Fingers is typing and releasing a proof of concept for a denial of service vulnerability that is successfully crashing the Chrome browser with all tabs. According to Narang’s advisory :
“An issue exists in how chrome behaves with undefined-handlers [...]
Security bloggers are already commenting on Google’s slightly premature “Chrome” browser leak. Built on top of the Apple sponsored WebKit engine, the browser offers several security features that we have only seen so far in the beta releases of IE8.
The most interesting feature discussed so far is the strict memory separation afforded by the technology, [...]
Google’s shiny new Web browser is vulnerable to a carpet-bombing vulnerability that could expose Windows users to malicious hacker attacks.
Just hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities — a flaw in Apple Safari (WebKit) and a Java bug discussed at this year’s Black Hat conference [...]
Microsoft is downplaying the severity of a password leakage issue in BitLocker, the full disk encryption feature built into Windows Vista, insisting that a real world attack scenario is “very unlikely.”
According to an advisory from iViZ, the password checking routine of Microsoft Bitlocker fails to sanitize the BIOS keyboard buffer after reading passwords, resulting in [...]