Attack code posted for unpatched Firefox 3.5 flaw

Mozilla’s security response team is scrambling to respond to the release of exploit code for a gaping hole in the latest version of its flagship Firefox browser. The flaw, rated “highly critical by Secunia, puts millions of Firefox users at risk of remote code execution attacks.

The vulnerability is caused due to an error [...]

Patch Day double-whammy: Oracle plugs 33 database holes

For businesses, today is a Patch Tuesday double-whammy. Just hours after Microsoft shipped six bulletins to cover multiple flaws in Windows and Internet Explorer, Oracle is getting set to release its quarterly batch of Critical Patch Updates with fixes for at least 33 security vulnerabilities.

According to Oracle: This Critical Patch Update contains 33 [...]

Remote code execution exploit for Firefox 3.5 in the wild

A zero day exploit (Firefox 3.5 Heap Spray Vulnerability) affecting Mozilla’s latest Firefox release has been published in the wild. Through an error in the processing of JavaScript code in ‘font tags’ malicious attackers could achieve arbitrary code execution and install malware on the affected hosts. There’s no indication of its use on a [...]

Does free antivirus offer a false feeling of security?

Earlier this month, Symantec’s product manager David Hall dismissed free security software as equal alternative to the paid versions, and also described  Microsoft’s free “Microsoft Security Essentials” as “a stripped down version of the OneCare product Microsoft pulled from retail shelves“. Needless to  say that such statements from a competing vendor often come as a [...]