News (71)

RealNetworks fixes 'highly critical' flaw

RealNetworks has released a security patch aimed at plugging a flaw in its multimedia software that could allow hackers to run their own code on people's computers. Read more »

Microsoft warns of unpatched IE flaw

Microsoft has issued a security advisory for Internet Explorer, after a research firm published a working exploit to demonstrate how attackers could take advantage of the flaw. Read more »

Critical fixes for Windows, Office coming

As part of its monthly patching cycle, Microsoft on Tuesday plans to release three security alerts for flaws in Windows and Office. Read more »

Apple QuickTime exploit in the wild

Symantec has found active exploit code in the wild for an unpatched Apple QuickTime vulnerability. Read more »

Security flaws found in fix for Firefox, SeaMonkey

Mozilla Foundation earlier this week issued a critical fix designed to address vulnerabilities in a recent security update for the Firefox browser and SeaMonkey application suite. Read more »

Mozilla fixes critical flaws in Firefox 2.0, Thunderbird

Mozilla has fixed seven vulnerabilities in the latest release of Firefox — SeaMonkey and Thunderbird are also affected. Read more »

Microsoft exec kicks off new browser security war

Internet Explorer is more secure than Firefox, according to a senior Microsoft executive, who compared how many vulnerabilities were found in the two browsers -- but critics say his study is flawed. Read more »

Apple unloads dozens of fixes for OS X

Apple Computer released one of its larger security updates for Mac OS X on Monday, with fixes for 44 flaws. Read more »

Kaminsky details DNS flaw

Security researcher Dan Kaminsky has offered more details about a fundamental flaw in the Domain Name System and the extent of the vulnerability. Read more »

Microsoft probes report of IE flaw

A new flaw in Internet Explorer could be exploited to launch spoof-based attacks, or access and change data on vulnerable PCs, security experts have warned. Read more »

Features (9)

Windows' HTML converter vulnerability rated Critical

A problem has been discovered in the way Windows handles HTML file conversion during cut-and-paste. This buffer overrun could allow an attacker to run rogue code. Read more »

Clickjacking: Potentially harmful web browser exploit

Clickjacking has the potential to redirect unknowing users to malicious websites or even spy on them. We all need to be aware of clickjacking and how to avoid its trappings. Read more »

Watch out for IE Local Zone script injection flaw

A flaw in the way Internet Explorer handles some errors, discovered by security company GreyMagic, could result in an attacker being able to read local files on a system or run various scripting commands. Get the details. Read more »

IE is evolving, but is it enough?

Microsoft's Internet Explorer Web browser is in the process of getting its first significant update in two years this week, as part of the company's overhaul of its operating system. Read more »

When will Microsoft fully embrace Web standards?

I recently revisited the issue of using Web standards when working with Microsoft SharePoint 2007 and Outlook 2007. The products' lack of adherence to Web standards was surprising given the advancements incorporated in Internet Explorer 7. Read more »

Bug hunters, software firms in uneasy alliance

Although many software makers promote responsible disclosure, it isn't universally backed by the security community. Critics say it could make security companies lazy in patching. Full disclosure of flaws is better is preferred. Read more »

Are keywords the answer for font sizing?

With font sizes in CSS, you have three choices: absolute measurements, relative measurements, and keywords. Here's why we think keywords are the best compromise Read more »

The secrets of open source security

The Linux vs. Windows security debate is a contest of examples, which stand in place of the concepts that comprise a larger, more fundamental question of what the security benefits and detriments are for the open source and closed source development models. Read more »

Don't get burned by downloaded code

Reusing code from the Web can save time and money, but there are potential problems too. Avoid these pitfalls when using downloaded code. Read more »

Log in


Sign up | Forgot your password?

What's on?