Headlines for Vulnerability research

MS Patch Tuesday: Exploits expected for severe drive-by-download flaws

Two of the bulletins are rated "critical" for all versions of Microsoft's flagship operating system, including Windows 7 and Windows Server 2003 R2.

WordPress blogs hacked, redirecting to malware

The attacks occurred mostly on WordPress blogs hosted by Network Solutions but it appears that there are multiple security weaknesses in play.

Researchers get funding to build new secure OS

Researchers at the University of Illinois at Chicago have received a $1.15 million grant from the National Science Foundation to build a new, secure computer operating system.

Sun Java flaw exposes Windows users to dangerous Web attacks

The flaw occurs because the Java-Plugin Browser is running "javaws.exe" without validating command-line parameters.

Adobe PDF silent updater, critical patch coming next Tuesday

The patches will be released alongside a new automatic updater software that the company hopes will speed up the downloading and deployment of its security fixes.

MS Patch Tuesday heads-up: 25 holes in Windows, Office

Five of the 11 bulletins will be rated "critical," Microsoft's highest severity rating. The flaws affect all versions of Windows, including the company's newest Windows 7 operating system.

The real dangers of PDF executable trickery

There is more that can be done with this latest PDF hack that may not be immediately apparent. We could start seeing persistent PDF worm attacks.

Mozilla Firefox first to patch Pwn2Own vulnerability

The Firefox 3.6.3 update is rated critical. It fixes a flaw that was exploited at this year's CanSecWest Pwn2Own hacker challenge.

Apple patching frenzy: Security holes in QuickTime, iTunes, AirPort

Over the last week, Apple has shipped security patches to cover 88 vulnerabilities in Mac operating system, 16 holes in the QuickTime media player, 7 flaws in iTunes and a security bug in the AirPort Base Station.

Adobe, FoxIt investigating PDF executable hack

Security response teams at Adobe and FoxIt are investigating ways to mitigate a new PDF hack that allows the execution of an embedded executable without exploiting any security vulnerabilities.