Security


UPDATED: Microsoft Tool Helps Filter SQL Injection Attacks

Microsoft on Thursday released an improved security filter for its Internet Information Service (IIS) Web server that is designed to help thwart SQL injection attacks.

Vulnerability Management Needed for Security, Study Says

Companies can avoid attacks and minimize security cost overruns by practicing IT vulnerability management, according to a July study published by the Aberdeen Group.

Who Stole My RunAs?

It's still there. Here are two approaches to running it.

Microsoft Unveils 'Ultimate' Support Service

Microsoft rolled out the highest level of its enterprise support programs to date, adding a new offering called "Microsoft Services Premier Ultimate."

SQL Injection Attacks on the Rise

MessageLabs reports that the number of SQL injection attacks spiked sharply last month.

WSUS Blocking: A Real Problem, Microsoft Says

Microsoft closed its investigation into an update blocking issue that affected users of Windows Server Update Service 3.0 or WSUS 3.0 Service Pack 1.

VMware's Updates Cause Problems, CEO Apologizes

Yesterday, August 12, was a blow-out day for some users of VMware's ESX 3.5 and ESXi 3.5 virtualization products, especially if they had applied the latest product updates called "Update 2."

Microsoft's August Patch Brings 11 Security Fixes

Microsoft's August patch, slated to be the largest patch rollout since 12 bulletins hit users in February of 2007, came up short by one.

Microsoft Ships Visual Studio 2008 and .NET SP1

Microsoft released to manufacturing its widely touted first service pack (SP) of Visual Studio 2008 and .NET Framework 3.5.

Seven Critical Fixes Expected on Tuesday

IT Pros and system administrators will be mighty busy this month as Microsoft announced plans to release 12 patches.

Analyst: Beware of the Google Gadgets

One fun thing about the interactive world of Web 2.0 is the online applications you can take advantage of, such as Google Gadgets.

DNS May Be Patched, but Danger Still Lurks

We dodged a bullet last month -- the discovery of a fundamental flaw in the Domain Name System, Dan Kaminsky told a standing-room only (and some sitting on the floor) crowd at the Black Hat Briefings Wednesday.

Coreflood Trojan Stole 500G of Personal Financial Data

A cache of stolen data gathered from a botnet that has been quietly sweeping up information for years contained the user names and passwords for 8,485 bank accounts.

Tuesday Patch Cycles To Include Risk Assessments

Microsoft is initiating a new security notification approach, the company announced on Tuesday at the Black Hat security conference.

Data Thefts Show Need for Comprehensive Security

On Tuesday, the U.S. Department of Justice charged 11 hackers with allegedly hitting the computer records of as many as nine major retail companies and selling more than 40 million credit and debit card numbers.

Black Hat Researchers Overcome Security Learning Curve

The Black Hat Briefings return to Caesars Palace this week with a new batch of hands-on security research for a crowd of 4,000 IT administrators, hackers, industry experts and government officials.

Collaboration Key to Security, Microsoft Says

Microsoft ratcheted up its PR and client communications efforts to demonstrate that it's serious about security.

Security Woes Up, as PHP and OSS Make the List

Software vulnerabilities are up this year, especially Web browser-based ones, according to a new report from IBM Internet Security Systems.

Apple Reacts to Spoof Threats, Issues DNS Hotfix

Apple Inc. took action on Friday to address the infamous Domain Name System (DNS) problem. And none too soon.

First Instance of New DNS Exploit Reported

Reports are coming in that an AT&T Domain Name System (DNS) server may have been compromised with malicious code that exploits a vulnerability reported earlier this month. This apparently is the first instance of the exploit in the wild.

Most   Popular