Firefox + NoScript vs Clickjacking

In response to my story earlier on the cross-browser Clickjacking exploit/threat, I received the following e-mail from Giorgio Maone, creator of the popular Firefox NoScript plug-in: Hi Ryan, I’ve seen a lot of speculation and confusion in the comments to your Clickjacking article about NoScript not being able to mitigate [the issue]. I had [...]

Facebook Mystery Friend? No, Malware.

Cyber criminals continue to use the popular social networking site Facebook to bait users. A new threat follows the phishing operation that we blogged about just two weeks ago. This current Facebook threat begins with the following spammed email message:

This bogus message tells recipients that a friend has added them to their social [...]

UTM devices are making headway

Customers using unified threat management devices say the appliances represent a more streamlined way to provide multiple security functions and to track down security data, but don’t necessarily meet all gateway security needs adequately.

Read entire article

Memory exhaustion DoS vulnerability hits Google’s Chrome

Aditya K Sood from the EvilFingers community, which disclosed the first Chrome DoS vulnerability at the beginning of the month, has released a proof of concept demonstrating a memory exhaustion DoS vulnerability affecting Google’s Chrome versions Chrome/0.2.149.30 and Chrome/0.2.149.29 :“The Google chrome browser is vulnerable to memory exhaustion based denial of service which can [...]

[...]