Headlines for Patch Watch

Critical flaws haunt Adobe PDF Reader, Acrobat

The update is rated "critical" because of the risk of remote code execution attacks via rigged PDF files.

MS Patch Tuesday: Exploits expected for severe drive-by-download flaws

Two of the bulletins are rated "critical" for all versions of Microsoft's flagship operating system, including Windows 7 and Windows Server 2003 R2.

Apache.org hit by targeted XSS attack, passwords compromised

The hackers hit the server hosting the software that Apache.org uses to it to track issues and requests and stole passwords from all users.

Adobe PDF silent updater, critical patch coming next Tuesday

The patches will be released alongside a new automatic updater software that the company hopes will speed up the downloading and deployment of its security fixes.

MS Patch Tuesday heads-up: 25 holes in Windows, Office

Five of the 11 bulletins will be rated "critical," Microsoft's highest severity rating. The flaws affect all versions of Windows, including the company's newest Windows 7 operating system.

The real dangers of PDF executable trickery

There is more that can be done with this latest PDF hack that may not be immediately apparent. We could start seeing persistent PDF worm attacks.

Java update plugs 27 critical security holes

The update, available for Windows, Solaris and Linux, addresses issues that could be remotely exploitable without authentication.

Mozilla Firefox first to patch Pwn2Own vulnerability

The Firefox 3.6.3 update is rated critical. It fixes a flaw that was exploited at this year's CanSecWest Pwn2Own hacker challenge.

Apple patching frenzy: Security holes in QuickTime, iTunes, AirPort

Over the last week, Apple has shipped security patches to cover 88 vulnerabilities in Mac operating system, 16 holes in the QuickTime media player, 7 flaws in iTunes and a security bug in the AirPort Base Station.

Adobe, FoxIt investigating PDF executable hack

Security response teams at Adobe and FoxIt are investigating ways to mitigate a new PDF hack that allows the execution of an embedded executable without exploiting any security vulnerabilities.