Headlines for Data theft

‘Extremely severe’ flaw in Opera web browser

An "extremely severe" security vulnerability in the Opera browser could put web surfers at risk of remote code execution attack

Microsoft admits MS10-025 patch didn’t fix vulnerability

Microsoft has yanked the security updates shipped in the MS10-025 bulletin after realizing the patch did not fix the underlying security vulnerability.

‘Google even knows what you’re thinking’

Privacy advocate Moxie Marlinspike used the spotlight of the SOURCE conference here to call attention to Google's data harvesting practices, warning that the search engine giant can mine information to figure out even what Web surfers are thinking about.

Hundreds of high profile sites unprotected from domain hijacking

A MarkMonitor review indicates that less than 10% of the top 300 high trafficked sites have adopted VeriSign's Registry Lock Service.

Attackers hit Google single sign-on password system

The New York Times is reporting that Google's password system was compromised during a targeted attack last December.

Security gone awry: IE 8 XSS filter exposes sites to XSS attacks

The cross-site scripting filter that ships with Microsoft's Internet Explorer 8 browser can be abused by attackers to launch cross-site scripting attacks on websites and web pages that would otherwise be immune to this threat.

New Mac OS X malware variant spotted

According to Intego's security memo, OSX/HellRTS.D is being distributed on a number of forums shows that it will be accessible to a large number of malicious users who may attempt to use it to attack Macs.

Embedded PDF executable hack goes live in Zeus malware attacks

The identity thieves behind the Zeus malware attacks are now using the "/launch" command feature in Adobe Reader to launch malicious attacks without exploiting a vulnerability in the software.

Apple patches Pwn2Own flaw used to hack Safari

According to Apple's advisory accompanying the patch, the actual vulnerability was not in the Safari browser but in the way ATS (Apple Type Services) handles certain fonts.

Java zero-day flaw under active attack

Virus hunters have spotted the attacks on a popular song lyrics Web site. Any visitor to that Web site with the Java Plugin for Browsers installed (Internet Explorer or Firefox) will get infected with malware.