Adobe Patches Zero-Day Vulnerability

Tuesday, March 10th, 2009

Adobe released a patch today for a zero-day vulnerability under attack by hackers. The patch, available for version 9 of Adobe Reader and Adobe Acrobat, comes a day earlier than the company’s planned release. Patches for earlier versions of the product are still slated for March 18. The vulnerability is the result ...

No User Action Required In Newly Discovered PDF Attack

Tuesday, March 10th, 2009

Merely storing -- without opening -- a malicious PDF file can trigger an attack that exploits the new, unpatched zero-day flaw in Adobe Reader, a researcher has discovered. Didier Stevens, a researcher and IT security consultant with Contrast Europe NV, today released a proof-of-concept demonstration that shows how a file ...

GMail Service CSRF Vulnerability

Tuesday, March 3rd, 2009

Gmail is Google's "free webmail service. It comes with built-in Google search technology and over 2,600 megabytes of storage (and growing every day). You can keep all your important messages, files and pictures forever, use search to quickly and easily find anything you're looking for, and make sense of it ...

Excel 0-Day Exploited

Tuesday, February 24th, 2009

Symantec is reporting that Trojan.Mdropper.AC is exploiting an unpatched vulnerability in Excel 2007. Earlier versions of Excel may also be vulnerable. The vulnerability is described as a "Boundary Condition Error" and can result in remote code execution, but that's it for details for now. The research is obviously in its early ...

Researcher Shows New SSL Website Hack

Saturday, February 21st, 2009

A researcher has found a convincing way to hack the SSL protocol used to secure logins to a range of Web sites, including e-commerce and banking sites. Using a specially-created app, 'SSLstrip', a researcher calling himself Moxie Marlinspike demonstrated to Black Hat Arlington, Va attendees, how vulnerable many SSL connections were ...