Headlines for ZDNet Security

Adobe unbundles Flash Player from Mac OS X bundle; Java next

Word is out that Apple will ship all new Mac OS X machines without Adobe Flash Player pre-installed.

Barbers and security professionals

In this guest editorial, security research professional Michal Zalewski argues that the government should stay away from compulsory certification and licensing in the security industry.

Google Chrome celebrates 2nd birthday with security patches

The Google Chrome 6.0, available in stable and beta channels for Windows, Mac, and Linux, patches a total of 15 documented security vunerabilities.

Apple patches 13 iTunes security holes

The vulnerabilities expose Windows users to remote code execution attacks via maliciously crafted Web sites.

Malware hosted on Google Code project site

Malicious hackers are using the Google Code repository to host Trojans horses, backdoors and password stealing keyloggers

Microsoft ships ‘Fix-It’ for DLL load hijacking attack vector

Microsoft has released a Fix-It tool to help mitigate the latest DLL load hijacking issue that exposes Windows users to remote code execution attacks.

RealPlayer haunted by ‘critical’ security holes

RealNetworks has shipped a critical update to address multiple vulnerabilities, some serious enough to allow a remote, unauthenticated attacker to execute arbitrary code or obtain sensitive information.

Verizon DBIR challenge clue #4

Hopefully, this should be the last clue: “If you’ve found the p(f+) in a fingerprint, you should be able to find the key.”

Critical security holes in Adobe Shockwave

The vulnerabilities, rated “critical,” affect Shockwave Player 11.5.7.609 and earlier versions for Windows and Macintosh.

Apple patches 13 Mac OS X vulnerabilities

The patch includes fixes for security holes in several open-source components, including ClamAV and PHP.