More Zero-Day Exploits for Firefox and IE Flaws

Earlier today, Senior Threat Researcher Joseph Reyes spotted several malicious script files that exploited Mozilla Firefox and Microsoft Internet Explorer vulnerabilities:

JS_DIREKTSHO.B exploits a vulnerability in Microsoft Video Streaming ActiveX control to download other possibly malicious files. JS_FOXFIR.A accesses a website to download JS_SHELLCODE.BV. In turn JS_SHELLCODE.BV exploits a vulnerability in Firefox 3.5 to [...]

Adobe ships insecure version of Reader from official site

Following reports by users of Secunia’s Personal Software Inspector on a potential false positive for an insecure version of Adobe Reader, the company has found that Adobe is surprisingly shipping the insecure Adobe Reader 9.1.0 version from its official site, potentially exposing users to previously fixed flaws in the latest 9.1.2 version. Adobe’s comment [...]

McAfee updates managed cloud security service

McAfee’s latest version of its managed security service includes new features that let companies scan their Web sites for vulnerabilities as well as check for compliance with payment-card industry standards for handling financial data.

Read entire article

OWC ActiveX Exploit Follows MPEG2TuneRequest’s Lead

Barely a few days after the last Microsoft zero-day exploit and out comes another, this time attacking vulnerabilities in the OS’s Office Web Components Spreadsheet ActiveX control (OWC 10 and OWC 11). As if on cue for the next round of Patch Tuesday releases, the cybercriminals also released their own “updates” with this attack. ““This [...]