Security: Vulnerabilities


Briefs

Problems Found in Graphics Library, Mozilla, and PDAs

In Brief

Windows XP security best practices, better SAML administration

Attacks Against Financial Services Double

Already under the regulatory gun, attacks against the IT infrastructures of financial services firms have doubled in the last year

Briefs

A new Internet Explorer security flaw; heading off phishing attacks

Security Briefs

Active X Allows File Loading; Defining Spyware

Security Briefs

New vulnerability erases hard drives; open source tool at risk; Oracle SQL exposure

Q&A: Stress Testing Your Network Against DoS Attacks

While most companies don’t face worms designed to turn computers against them, denial-of-service attacks remain a problem. How can organizations stress test their network against such attacks? We turned to Alan Newman of Spirent Communications, which manufacturers network stress-testing appliances and simulation software, for some ideas.

Security Briefs: WiFi Attacks, Outlook Vulnerability

DoS attacks possible on 802.11 devices, public access points particularly vulnerable; tricking Outlook 2003 to download and run files

Security Briefs

Despite Arrest, Worm Exploits Continue; Microsoft Help Vulnerability Revealed; Symantec Firewall Management Improved

Security Briefs: Worm Attacks Unpatched Computers; Apple Closes Vulnerability

Global organizations go offline to prevent Sasser damage; Apple patches QuickTime, OS X to close buffer overflow vulnerability

Security Briefs: April Recap, Can-Spam Charges, Eset's Antivirus Software

Top vulnerabilities include a virus and a Hotmail hoax; FTC charges spammers; NOD32 antivirus software for consumers and the enterprise

Security Briefs: Two Protocol Vulnerabilities Disclosed

TCP vulnerability exploit found in the wild; buffer overflow weakness uncovered in Microsoft PCT protocol

Worst Security Problem: Attachments

Security policies and education aren't enough

In Brief

Cisco sign-on, IE cross-scripting lead vulnerabilities this week

Security Briefs: Encrypted Attachments Carry Threats

Sneaking vulnerabilities into the enterprise through encrypted attachments pose new problems; ISPs will spend $245 million this year to combat problems, in large part because of home users.

Security Managers Report Virus Problem Worse

New report charts security manager dissatisfaction

F-Secure Targets Attacks on Linux

As popularity of Linux grows, company predicts increasing attempts to create malicious programs that will attack it

Combating Apathy with Free Security Check

WholeSecurity gives businesses the ability to offer their customers an opt-in PC security sweep to quarantine malicious software

Briefs: Vulnerabilities in CPanel, ISS products, Symantec Internet Security

New warnings about Web hosting control panel protection, ISS server-response processing, and Symantec's security software