Friday, September 27, 2013
How Your Computer Gets Hacked in Under a Minute
Sept. 27 (Bloomberg) – With just a few clicks, hackers can access all of your online information and stay in your system for years. Bloomberg’s Megan Huges talks to the experts to show you how it’s done. (Source: Bloomberg)
Hackers-for-hire uncovered using hit-and-run 'Icefog' APT on Mac OS X and Windows systems - IT News from V3.co.uk
Continue Reading: Hackers-for-hire uncovered using hit-and-run 'Icefog' APT on Mac OS X and Windows systems - IT News from V3.co.uk
Wednesday, January 16, 2013
Why fixing the Java flaw will take so long
The vulnerability patched by Oracle resides in a version of Java 7 designed to extend Web browsers. The defect made it possible for a malicious Java applet on a Web page to execute arbitrary code on the underlying computer.
Read the full article at http://www.infoworld.com: Why fixing the Java flaw will take so long
Friday, July 22, 2011
Saturday, December 18, 2010
Tuesday, November 2, 2010
Yes, you need anti-virus on your Mac.. and now it’s free | Naked Security
Sophos has today announced the world's first free business-strength anti-virus program for home Macs. As Apple computers grow more popular than ever, they're an increasingly-enticing target for hackers (Windows users are still the number one target). And these hackers aren't just mischief-makers—by targeting your computer or applications you use, these criminals are out to steal and profit from your valuable personal information. Don't let them. Get Sophos Anti-Virus Home Edition for the Mac free today.
Friday, September 24, 2010
Wednesday, July 7, 2010
Trend Micro offers free secure surfing tool - V3.co.uk - formerly vnunet.com
The product has been designed to protect against sophisticated threats such as the Hydraq family which was used to such effective ends in the Operation Aurora attacks by Chinese hackers on Google and other firms at the beginning of the year."
Trend Micro offers free secure surfing tool - V3.co.uk - formerly vnunet.com
Tuesday, July 6, 2010
iTunes accounts plundered, Apple's App store needs better control mechanisms
iTunes accounts plundered, Apple's App store needs better control mechanisms
Thursday, April 8, 2010
Macintosh = Hacker-Proof?
Charlie A. Miller loves his Macbook Pro laptop. And his four other Apple ( AAPL - news - people ) PCs, the iPhone he uses daily and two older iPhones he keeps for tinkering. But his relationship with the company that created those gadgets is somewhat more complicated.
In March, for instance, the 36-year-old security researcher publicized his discovery of 20 security vulnerabilities in Apple's software. Each would allow a cybercriminal to take over the computer of a user who's tricked into opening a certain PDF attachment or who simply visits an infected Web page using Apple's Safari browser.
That haul of bugs is a record even for Miller, who over the last four years has become perhaps the world's most prominent Mac hacker. It may also be definitive proof that Apple devices aren't safe "right out of the box," as the company has claimed for years. "When I first began saying that Macs were less secure than Windows, everyone thought I was an idiot," says Miller. "So I had to prove it again and again and again."
In 2007 Miller became the first to hack the iPhone, using a flaw in its Safari browser to remotely gain control of the not-so-smart phone. Six months later he hacked a Macbook Air in two minutes at a competition in Vancouver. Last summer he revealed a method that allowed him to virally hijack the iPhone using text messages spread via a user's contact list.
Miller says his latest research doesn't aim to show off his elite hacking skills,most of which he learned over five years as a global network exploitation analyst for the National Security Agency. Instead, he wants to show just how easy it is to find chinks in the armor of commonly used software. Miller used a technique known as "dumb fuzzing" to find flaws. He ran the procedure more persistently than most hackers, leaving his fuzzing program to throw junk information at each target for three weeks before mining the data for exploitable flaws.
As for Apple, Miller says the company has learned to accept, if not appreciate, his work. He usually gives Apple weeks of notice before publicly describing its bugs. "They're always very polite," he says. "But I suspect they wish I didn't exist."
Read the full story at Forbes.com by Andy Greenberg
Updated:
Apple Patches Pwn2Own Bug
Thursday, March 11, 2010
Sunday, February 7, 2010
Apple's Mac OS X is less secure than Windows (or not)
Read the full story
Friday, February 5, 2010
Microsoft on IE8 Exploit: 'There Is No Patch', And there never will be.
The very fact that resident malware can still 'destroy data on the user's machine' means you as a Windows user have no protection at all. As soon as the black hats uncover another hole in the web periphery, the story will repeat itself.
The very fact Microsoft are attempting to 'isolate' their web interface is a tacit admission the system itself is defenceless. Take a deep breath now while you can. The next attack is right around the corner.
And you have to abandon IE, no matter the version or the version of your 'OS'. There is no patch.
Read the full story at Rixstep
Monday, January 18, 2010
German government warns citizens off IE!
"Don't use IE 6, 7 or 8 and switch browser," says Federal Office
"The German government's Federal Office for Information Security is warning computer users in the country NOT to use Microsoft Internet Explorer due to recent security scares.
The state organisation has issued the warning following Microsoft's admission that IE was a 'vector' in the recent attacks on Google in China.
The German government is thus advising its citizens to use alternative browsers such as Mozilla's Firefox, Google Chrome, Apple Safari or Opera."
Wednesday, December 2, 2009
SSL/TLS Zero-day flaw found in web encryption
The flaw in the TLS authentication process allows an outsider to hijack a legitimate user's browser session and successfully impersonate the user, the researchers said in a technical paper.
The fault lies in an "authentication gap" in TLS, Ray and Dispensa said. During the cryptographic authentication process, in which a series of electronic handshakes take place between the client and server, there is a loss of continuity in the authentication of the server to the client. This gives an attacker an opening to hijack the data stream, they said.
In addition, the flaw allows practical man-in-the-middle attacks against hypertext transfer protocol secure (Https) servers, the researchers said. Https is the secure combination of http and TLS used in most online financial transactions."
Wednesday, September 30, 2009
Russian Hackers pay 43 cents per hijacked Mac
Friday, September 18, 2009
FUD report: Snow Leopard 'not as secure' as Windows...
Story goes like this: The hacker who successfully broke into a Mac at a hacker’s conference some time ago has tested Snow Leopard against WIndows 7, and accuses the Mac OS as being “less secure” than Microsoft’s Vista upgrade.
Charlie Miller is one of the team from Independent Security Evaluators who successfully "pwned and owned" an Apple MacBook Air, in a hacking contest sponsored by TippingPoint's Zero Day Initiative."
Read the full story at 9 to 5 Mac by Jonny Evans
"He conveniently forgets all of the other security features in Snow Leopard. Why doesn't he touch on:
- stack frame protection
- code injection protection
- automatic replacement of common C functions (e.g. srtcpy) with hardened versions
- heap consistency checks
- the reduction in setuid executables
His opinion on ASLR is valid, but extrapolating that to the overall security of the OS is garbage."
Tuesday, August 11, 2009
Saturday, August 1, 2009
Adobe patches 12 Flash bugs, 3 caused by Microsoft
Adobe on Thursday patched 12 vulnerabilities in Flash Player, including three it inherited from faulty Microsoft development code and one that hackers have been exploiting for at least a week.
In a security advisory published Thursday afternoon, Adobe briefly spelled out the dozen vulnerabilities, 10 that were pegged as potentially leading to hijacked systems or with hackers executing their own malware on a machine.
The vulnerabilities affect the Windows, Mac and Linux versions of Flash Player. Still to patch: the Solaris edition.
Flash Player 9.0.246.0 and 10.0.32.18 for Windows, Mac and Linux can be downloaded from Adobe's Web site. Alternately, users can use Flash's built-in automatic update mechanism to grab the new versions.
Sunday, January 25, 2009
Block Wi-Fi Intruders with a Secure Paint Job
The problem of securing wireless networks has been an issue for a while now. Wi-Fi LANs with no encryption or running the obsolete WEP system, run the risk of having hackers outside the building eavesdrop on wireless LAN traffic, or simply stealing bandwidth. However, there are a number of solutions, besides encryption, for companies wishing to secure their networks.
read more | digg story