MS Tuesday heads-up: Critical IE, Exchange flaws

Microsoft plans to ship four security bulletins next Tuesday with patches for a range of serious security vulnerabilities  affecting millions of Windows users. Two of the four bulletins will be rated “critical,” Microsoft’s highest severity rating.  Those will cover remotely exploitable flaws in the Internet Explorer browser and the Microsoft Exchange Server.

[ GALLERY: [...]

(Not so) Tiny Phishing

Phishers are now into TinyURLs, using the popular Web service to shrink long URL strings and hide destinations from users. Trend Micro Advanced Threats Researcher Joey Costoya discovered a malicious shortened link hidden in this spammed message:

Figure 1. Sample spam. The link may look legitimate but it masks a TinyURL that leads to [...]

Obama Worm: So Old, It’s New Again

After a malware dubbed as the “Obama worm” was found circulating within an Illinois elementary school’s network, security researchers traded opinions on the threat it brings about. Most reports mainly circulated on the issue of whether the file was malicious or not, considering that it has no malicious payload other than showing the following [...]

Fuzzing for Oracle database vulnerabilities

Database security vendor Sentrigo has released an open-source fuzz testing tool to help pinpoint security-related coding deficiencies in Oracle databases. The tool, called FuzzOr, runs on Oracle 8i and is aimed at PL/SQL programmers and DBAs looking to find and eliminate vulnerabilities that may be exploited via SQL injection and buffer overflow attacks — the [...]