Security


Google Offers $20,000 To Hack Chrome

Google is looking to reward those who can find a vulnerability in its Chrome browser.

Microsoft Preparing Hefty 12-Item Security Patch on Tuesday

Microsoft began 2011 with a light touch, but IT pros can expect a decidedly heavy February security update next Tuesday.

Messing With Web Components

Hackers go after your browsing sessions. Plus: Conficker worm is gone, but not forgotten; unrest in Egypt worries Microsoft, Cisco.

Microsoft Investigating MHTML Vulnerability in IE

Microsoft released Security Advisory 2501696 in response a scripting vulnerability in Internet Explorer that affects all versions of Windows.

Browsers, Browsers, Browsers!

IE still vulnerable, but hackers are heat-seeking on other browser targets. Plus: Browser makers making "no tracking" a feature priority; Wordpress plug-in threatened by SQL injection attack.

Black Hat: Will New Breed of DOS Attacks Make Cloud Unaffordable?

The cloud is the current Next Big Thing in computing, and the Next Big Thing in attacks could be a new breed of economic denial-of-service attacks intended to use up resources and drive up the cost of cloud computing, warns a senior security researcher at Adobe Systems.



Report: Hackers Shifting Attention to Mobile Devices

Scammers have set their sights on tablets and smartphones, and away from Windows desktops, in response to rising consumer demand for mobile devices.

Stuxnet Is Not Superworm, Researcher Says

An analysis of the Stuxnet worm shows it to be a combination of sophisticated and flawed work, most likely the product of a partnership between several entities with varying levels of expertise and resources.

Microsoft Security Goes on Offensive

Company adds new tools to SDL for developers. Plus: Windows Live Messenger update is mandatory; researchers says third-party vulnerabilities, attacks to outpace Windows attacks.

A 'Hurry Up and Wait' Security Strategy

Security experts have yet to get the edge on hackers. Plus: Unpatched IE bugs likely to be fixed post-Patch Tuesday; smartphones all the rage -- with hackers.

January Windows Security Patch Lacks IE Fix

As expected, Microsoft today released two security bulletins in its January security update.

Light Microsoft Patch Expected Tuesday, Despite Threats

Microsoft plans to start the year with a light count of just two security bulletins in its January patch.

More IT Grief: Office Exploit Broadly Released

Code that can exploit a Rich Text Format flaw in Microsoft Office has been published, according to a Microsoft announcement late last month.

Windows Graphics Engine Contains Security Flaw

Microsoft released a security advisory today concerning Windows Vista, Windows XP and Windows Server 2003.

Security Flaws: Old News in a New Year

It's like 2010 all over again with security. Plus: Microsoft admonishes Google for its security policies; fake updates in your inbox.

Microsoft Investigating IE and FTP Security Flaws

Microsoft's security team announced late last month that it is investigating two proof-of-concept flaws in Microsoft's Web-related software.

Forefront Endpoint Protection 2010 Now Available

Microsoft today announced that its Forefront Endpoint Protection (FEP) 2010 product is available for evaluation.

Study: IE Scores Highest Against Social Malware

Microsoft's Internet Explorer 8 and 9 Web browsers demonstrated better protection against socially engineered exploits than other browsers, as described in a September NSS Labs report.

Microsoft Closes a Record-Patch Year with 17 for December

Windows IT pros this December find themselves unwrapping a huge package of security updates ahead of Christmas directly from Microsoft.

Microsoft's Holiday Present Includes 17 Patches

Plus: Hackers compromise Gawker media sites; Google and Redmond ad malware investigated; Symantec takes a look at the problems you'll be facing in 2011.