Heise Security

Syndicate content
IT security news and features
Updated: 22 hours 13 min ago

Firefox 3.6 gains anti-clickjacking support, Thunderbird & SeaMonkey updated

Wed, 08/09/2010 - 06:48
Firefox 3.6.9 now supports a server header which can help to prevent clickjacking. The new version also fixes 14 vulnerabilities, including the DLL vulnerability in the Windows version

Facebook closes spamming hole

Wed, 08/09/2010 - 06:05
At the beginning of the week, a cross-site request forgery hole could be exploited to automatically send spam e-mails via Facebook

Apple releases Safari security updates

Wed, 08/09/2010 - 05:24
Apple has released versions 5.02 and 4.1.2 of Safari, security updates that address several critical vulnerabilities in the company's WebKit-based browser

Microsoft withdraws SteadyState

Tue, 07/09/2010 - 12:30
The kiosk mode for Windows will only remain available for downloading until the end of this year. In June 2011, Microsoft will largely discontinue support

PS3 hack source code published - Update

Tue, 07/09/2010 - 04:14
Source code which can be used on programmable developer boards to circumvent the Playstation 3's security systems, analogous to a PS3 Jailbreak, has been released under the name PSGroove

Data theft in Internet Explorer via two-year old vulnerability

Mon, 06/09/2010 - 12:14
An ancient vulnerability in Internet Explorer allows attackers to access confidential data by importing web pages as style sheets

TrueCrypt 7.0a released

Mon, 06/09/2010 - 10:20
The TrueCrypt release team has released the first update to version 7.0 of its open source, cross platform, disk encryption tool, addressing a bug that caused some systems to crash when using custom storage device controller drivers

MSIL/Zeven malware impersonates warning pages

Mon, 06/09/2010 - 09:59
Zeven pretends to be the browsers malware blocker to encourage the user to install a "recommended" update, which turns out to be a rogue antivirus application

Flash Player as a spy system

Mon, 06/09/2010 - 09:14
Adobe's Flash Player potentially allows web pages to access a computer's web cam and microphone. Using a remote man-in-the-middle attack, the player's settings can be modified so they allow arbitrary web pages to access these components

Using the HAVP anti-virus proxy to protect from web attacks

Mon, 06/09/2010 - 06:29
The free HAVP proxy, combined with free virus scanners for Linux, reduces the risk of falling prey to attacks when browsing the internet on a Windows PC. Its installation is anything but rocket science

The H Week - Tablets, Ubuntu 10.10, Chrome 6, & QuickTime vulnerabilities

Sat, 04/09/2010 - 07:06
Canonical released a beta for Ubuntu 10.10, version 3.0 of Ruby on Rails arrived, Google released Chrome 6 and a number of companies released open source-based tablets aimed at competing with Apple's iPad. India gave RIM two more months, IBM revised its X-Force security report and the source code for hacking PS3 game consoles arrived online

Microsoft hardening tool with graphical user interface

Fri, 03/09/2010 - 09:49
The tool allows users and IT professionals to harden existing software against known attacks - without the need to recompile

Google Chrome turns version 6 on its second birthday

Thu, 02/09/2010 - 11:41
On the second anniversary of the release of the first version of Chrome, Google has released version 6 of its Chrome web browser into the stable and beta channels which also closes critical holes

PS3 hack source code published

Thu, 02/09/2010 - 11:30
Source code which can be used on programmable developer boards to circumvent the Playstation 3's security systems, analogous to a PS3 Jailbreak, has been released under the name PSGroove

Wireshark 1.4.0 drops Windows 2000 support

Thu, 02/09/2010 - 06:05
The Wireshark project has released version 1.4.0 of its open source, cross-platform network protocol analyser, adding and updating a number of new features and dropping support for Windows 2000 systems

iTunes 10 addresses 13 security vulnerabilities

Thu, 02/09/2010 - 05:21
All of the holes are contained in WebKit and can be exploited to compromise systems

Secunia's PSI 2.0 beta tackles Windows update annoyances

Wed, 01/09/2010 - 11:25
Outdated programs make it easy for attackers to compromise a system. The newly released beta of version 2.0 of Secunia's Personal Software Inspector (PSI) not only sniffs out vulnerable software, it also updates some programs automatically

Microsoft continues to workaround DLL vulnerability

Wed, 01/09/2010 - 09:28
Microsoft has released a 'fix-it' which automatically creates the registry entry required to protect against the DLL vulnerability

Backdoor discovered in QuickTime

Tue, 31/08/2010 - 12:28
A forgotten parameter which has been dormant in QuickTime's ActiveX control for 9 years and is still present in the current version can reportedly be exploited to inject malicious code

Unpatched security holes: IBM re-evaluates

Tue, 31/08/2010 - 09:25
A report by IBM said that Google left every third critical hole unpatched in the first half of 2010. IBM have now admitted their mistake and corrected their report