News (23)

DNS disaster: first attacks reported

The first attacks that are likely to have stemmed from a serious Domain Name System flaw have been reported. Read more »

Hackers claim zero-day flaw in Firefox

The open-source Firefox Web browser is critically flawed in the way it handles JavaScript, two hackers said Saturday afternoon in the US. Read more »

Firefox phishing vulnerability discovered

A newly discovered flaw in Firefox could allow cybercriminals to take advantage of Web surfers. Read more »

Apple QuickTime zero-day flaw 'extremely critical'

Security research firm Secunia has reported what it calls an "extremely critical" vulnerability in media-streaming program Apple QuickTime. Read more »

RealNetworks fixes 'highly critical' flaw

RealNetworks has released a security patch aimed at plugging a flaw in its multimedia software that could allow hackers to run their own code on people's computers. Read more »

Public info kiosk running Citrix hacked in demo

A consultant from McAfee Foundstone has shown how to map the internal network on a public kiosk running Citrix XenApp. Read more »

Black Hat with a Vista twist

Black Hat is not just about breaking and entering this year as Windows Vista and IE7 come under the spotlight. Read more »

Symantec: Mozilla browsers more vulnerable than IE

Mozilla Web browsers are potentially more vulnerable to attack than Microsoft's Internet Explorer, according to a Symantec report. Read more »

Microsoft denies flaw in Vista

Microsoft has confirmed that Vista can be affected by malware from 2004, but argues this is not a flaw in the operating system. Read more »

Hacker backpedals on Firefox zero-day

A hacker who claimed to have found a serious zero-day bug in Firefox now says he was never able to exploit the supposed vulnerability to hijack computers. Read more »

Features (2)

Bug hunters, software firms in uneasy alliance

Although many software makers promote responsible disclosure, it isn't universally backed by the security community. Critics say it could make security companies lazy in patching. Full disclosure of flaws is better is preferred. Read more »

Develop secure software at the application level

Protect your application from input overflow and underflow attacks, and from other common tactics with these development techniques. Read more »

Log in


Sign up | Forgot your password?

What's on?