Apple warns of Mac attack risk via image files

Apple today warned that opening or viewing image files could lead to remote code execution attacks against Mac OS X users. In an update that contains fixes for a total of 19 documented vulnerabilities, Apple said malicious hackers could rig PNG (Portable Network Graphics) and other images to take complete control of unpatched Mac [...]

Mozilla shuts online store after security breach

The Mozilla Foundation has shuttered its e-commerce store after confirming a security breach at GatewayCDI, the third-party vendor that handles the store’s backend operations. The open-source groups said it has asked Gateway CDI to quickly notify individuals who had their sensitive data compromised.  Mozilla did not elaborate on the extent of compromised customer data.

[...]

Absolute Software downplays BIOS rootkit claims

Following a flood of calls from customers, the company behind the LoJack anti-theft service which researchers from Core Security Technologies recently portrait as a security threat, issued a statement downplaying the researchers’ claims. According to the statement, LoJack is neither a rootkit, nor does it behave in such a way. Moreover, the company insists [...]

Fake Microsoft patch malware campaign makes a comeback

During the last couple of hours, a fake Microsoft patch themed malware campaign was restarted by its botnet masters, once again spamming a  non-existent Update for Microsoft Outlook / Outlook Express (KB910721) as officexp-KB910721-FullFile-ENU.exe detected as VirTool:Win32/Obfuscator.FO.

Some of the subjects used in the campaign include Microsoft has released an update for Microsoft Outlook; Install [...]

Plugins compromised in SquirrelMail’s web server hack

According to a recently posted update by SquirrelMail’s Jonathan Angliss, the source code of three plugins was backdoored during the web server compromise of the popular web-based email application which took place last month. The compromised plugins were embedded with code that was forwarding accounting data to a server maintained by the people behind the [...]