Headlines for Microsoft
Serious XSS flaw haunts Microsoft SharePoint
The vulnerability, which can be exploited via the browser, could allow a malicious hacker to execute arbitrary JavaScript code within the vulnerable application.
Microsoft admits MS10-025 patch didn’t fix vulnerability
Microsoft has yanked the security updates shipped in the MS10-025 bulletin after realizing the patch did not fix the underlying security vulnerability.
Report: ZeuS crimeware kit, malicious PDFs drive growth of cybercrime
New report indicates that the combination of the ZeuS crimeware kit, and the tremendous increase of malicious PDFs seen in 2009, play a crucial role in the growth model of the cybercrime ecosystem.
Microsoft to fix security hiccups in IE 8 XSS filter
On the heels of a Black Hat EU presentation that exposed security problems with the cross-site scripting (XSS) filter in Internet Explorer 8, Microsoft plans to ship an update to the filter to fix what is hopefully the last remaining attack scenario.
Security gone awry: IE 8 XSS filter exposes sites to XSS attacks
The cross-site scripting filter that ships with Microsoft's Internet Explorer 8 browser can be abused by attackers to launch cross-site scripting attacks on websites and web pages that would otherwise be immune to this threat.
Java zero-day flaw under active attack
Virus hunters have spotted the attacks on a popular song lyrics Web site. Any visitor to that Web site with the Java Plugin for Browsers installed (Internet Explorer or Firefox) will get infected with malware.
MS Patch Tuesday: Exploits expected for severe drive-by-download flaws
Two of the bulletins are rated "critical" for all versions of Microsoft's flagship operating system, including Windows 7 and Windows Server 2003 R2.
Copyright violation alert ransomware in the wild
A currently ongoing ransomware campaign is using a novel approach to extort money from end users whose PCs have been locked down - it attempts to extorts $400 from users which would otherwise face a copyright violation suit.
Sun Java flaw exposes Windows users to dangerous Web attacks
The flaw occurs because the Java-Plugin Browser is running "javaws.exe" without validating command-line parameters.
MS Patch Tuesday heads-up: 25 holes in Windows, Office
Five of the 11 bulletins will be rated "critical," Microsoft's highest severity rating. The flaws affect all versions of Windows, including the company's newest Windows 7 operating system.

Twitter
RSS