Microsoft: ‘Consistent exploit code likely’ for IE vulnerabilities

Microsoft today shipped four bulletins with patches for at least 8 documented security vulnerabilities affecting Windows users and warned that “consistent exploit code could be easily crafted” to launch attacks via the Internet Explorer browser. The Patch Tuesday batch includes fixes for a pair of code execution holes in IE, two bugs in the [...]

Report: 92% of critical Microsoft vulnerabilities mitigated by Least Privilege accounts

A recently released report by BeyondTrust entitled “Reducing the Threat from Microsoft Vulnerabilities” indicates that that according to the company’s analysis of all the security bulletins Microsoft published in 2008, 92% of the critical vulnerabilities could have been mitigated by the principle of the least privilege. Despite the fact that Microsoft’s products continue topping [...]

Fake Antivirus XP pops-up at Cleveland.com

Have we reached the phrase when targeted advertising would equal evasive malware campaigns pushed through third-party ad networks, to a geolocated set of visitors only? Could be. During the weekend, rogue antivirus XP pop-ups were served to visitors of Cleveland.com, according to visitors’ complaints which I also managed to verify. Investigating further reveals that [...]

Political Issues Bleed Through the Web

Political spats and issues are once again seen bleeding into cyberspace as notable attacks related to politics were seen today. The Israeli Legislative Election for 2009 to be held on February 10 was used by spammers as bait for users to download malware on their systems. The election is supposedly to be held in 2010. [...]

Kaspersky suffers attack on support site, no apparent data breach

Word came out this weekend that the U.S. support site for the AV Vendor Kaspersky Labs was compromised by attackers.

Earlier this week an attacker used a SQL Injection attack to compromise a section of the usa.kaspersky.com website and posted a list of database tables fetched via the compromise on the hackersblog.org website. According to [...]