QuickTime 0day for Vista and XP

Friday, April 25th, 2008

A remote vulnerability exists in the QuickTime player for Windows XP and Vista (latest service packs). Other versions are believed to be affected as well. For now, no details will be released regarding the method of exploitation. Because we are an information security think tank and because we encounter some very ...

Between black and white: the state of grayware on the PC

Friday, April 25th, 2008

In the old days, as our parents frequently love to remind us, life was much simpler. You bought a computer, and when you finally figured out what you wanted to do with it, you assembled a list and went down to your local Egghead for some software. It was straightforward, ...

Twitter meets manunkind

Thursday, April 24th, 2008

Well, I finally jumped on that social networking bandwagon called Twitter.  I signed up for Twitter about an hour or so ago just to check it out and see what all the hype was about.  I know, I'm slow.  But they always say that a person hears or sees something ...

Securing the Internet’s DNS

Thursday, April 24th, 2008

The Internet is slowly inching closer to ratcheting up the security of its Domain Name System (DNS) server architecture: The Internet Corporation for Assigned Names and Numbers (ICANN) plans to go operational with the secure DNS technology, DNSSEC, later this year in one of its domains. ICANN officials said the organization ...

Targeted attacks using malicious PDF files

Thursday, April 24th, 2008

Dating back to the end of February, we have been tracking test runs of malicious PDF messages to very specific targets. These PDF files exploit the recent vulnerability CVE-2008-0655. Ever since the end of March, beginning of April, the amount of samples seen in the wild has significantly increased. Interestingly enough, ...