Headlines for Vulnerability research

‘Extremely severe’ flaw in Opera web browser

An "extremely severe" security vulnerability in the Opera browser could put web surfers at risk of remote code execution attack

Microsoft to fix security hiccups in IE 8 XSS filter

On the heels of a Black Hat EU presentation that exposed security problems with the cross-site scripting (XSS) filter in Internet Explorer 8, Microsoft plans to ship an update to the filter to fix what is hopefully the last remaining attack scenario.

Attackers hit Google single sign-on password system

The New York Times is reporting that Google's password system was compromised during a targeted attack last December.

Security gone awry: IE 8 XSS filter exposes sites to XSS attacks

The cross-site scripting filter that ships with Microsoft's Internet Explorer 8 browser can be abused by attackers to launch cross-site scripting attacks on websites and web pages that would otherwise be immune to this threat.

Researchers hack into Palm WebOS with text messages

Security researchers at the Intrepidus Group found that the Palm WebOS SMS client did not properly validate input/output validation on any SMS messages sent to the handset.

Critical flaw in Cisco Secure Desktop

If an attacker can entice a user to visit an attacker controlled web page, the vulnerable ActiveX control could be invoked to download an attacker-modified package.

Embedded PDF executable hack goes live in Zeus malware attacks

The identity thieves behind the Zeus malware attacks are now using the "/launch" command feature in Adobe Reader to launch malicious attacks without exploiting a vulnerability in the software.

As attacks surface, Sun ships sudden Java patch

In a sudden about-face, Sun has rushed out a Java update to fix a drive-by download vulnerability that exposed Windows users to in-the-wild malware attacks.

Apple patches Pwn2Own flaw used to hack Safari

According to Apple's advisory accompanying the patch, the actual vulnerability was not in the Safari browser but in the way ATS (Apple Type Services) handles certain fonts.

Critical flaws haunt Adobe PDF Reader, Acrobat

The update is rated "critical" because of the risk of remote code execution attacks via rigged PDF files.