Headlines for Arbitrary Code Execution
As attacks surface, Sun ships sudden Java patch
In a sudden about-face, Sun has rushed out a Java update to fix a drive-by download vulnerability that exposed Windows users to in-the-wild malware attacks.
Java zero-day flaw under active attack
Virus hunters have spotted the attacks on a popular song lyrics Web site. Any visitor to that Web site with the Java Plugin for Browsers installed (Internet Explorer or Firefox) will get infected with malware.
Critical flaws haunt Adobe PDF Reader, Acrobat
The update is rated "critical" because of the risk of remote code execution attacks via rigged PDF files.
MS Patch Tuesday: Exploits expected for severe drive-by-download flaws
Two of the bulletins are rated "critical" for all versions of Microsoft's flagship operating system, including Windows 7 and Windows Server 2003 R2.
WordPress blogs hacked, redirecting to malware
The attacks occurred mostly on WordPress blogs hosted by Network Solutions but it appears that there are multiple security weaknesses in play.
Researchers get funding to build new secure OS
Researchers at the University of Illinois at Chicago have received a $1.15 million grant from the National Science Foundation to build a new, secure computer operating system.
Sun Java flaw exposes Windows users to dangerous Web attacks
The flaw occurs because the Java-Plugin Browser is running "javaws.exe" without validating command-line parameters.
Adobe PDF silent updater, critical patch coming next Tuesday
The patches will be released alongside a new automatic updater software that the company hopes will speed up the downloading and deployment of its security fixes.
MS Patch Tuesday heads-up: 25 holes in Windows, Office
Five of the 11 bulletins will be rated "critical," Microsoft's highest severity rating. The flaws affect all versions of Windows, including the company's newest Windows 7 operating system.
Report: Bank of America ATM hacker to plead guilty
A Bank of America (BofA) computer specialist will plead guilty to charges that he hacked the bank's automated tellers to dispense cash without recording the activity.

Twitter
RSS