Pwn2Own 2012: Google Chrome browser sandbox first to fall

Exploit writers at VUPEN take special pleasure in attacking Google’s Chrome browser, using a pair of zero-day flaws to defeat the browser’s heralded sandbox.

A Special Offer From Our Sponsor Join a Cisco Webcast March 8, 9:00 am PT    Find out how to realize the full potential of your data center [...]

Flashback Mac OS X malware exploiting (old) Java security holes

If a Mac OS X user visits a web page, and their Java is not up to date, the malware infection will occur without their intervention.

A Special Offer From Our Sponsor Join a Cisco Webcast March 8, 9:00 am PT    Find out how to realize the full potential of your [...]

Malware Leveraging MIDI Remote Code Execution Vulnerability Found

Earlier today, we encountered a malware that exploits a recently (and publicly) disclosed vulnerability, the MIDI Remote Code Execution Vulnerability (CVE-2012-0003). The said vulnerability is triggered when Windows Multimedia Library in Windows Media Player (WMP) fails to handle a specially crafted MIDI file, consequently allowing remote attackers to execute arbitrary code. In the attack that we [...]

‘Remove Facebook Timeline’ themed scam circulating on Facebook

According to InsideFacebook, scammers are exploiting the negative sentiments surrounding Facebook’s Timeline, and are currently spamvertising bogus pages attempting to trick end users into removing their Timeline profile.More from InsideFaacebook.comWe have found 16 Timeline-related scam pages, which have collectively gained more than 71,000 likes. The largest, with nearly 19,000 likes, has been around for [...]

2011 in Review: Exploits and Vulnerabilities

In recent years, we have seen client-side software heavily targeted by hackers in search of vulnerabilities. 2011 saw these threats become more complex and sophisticated. We saw attackers increasingly use zero-day vulnerabilities, some of which have been particularly critical. Examples of these include the vulnerability Duqu exploited (CVE-2011-3402); a Java vulnerability (CVE-2011-3544); or Adobe zero-day vulnerabilities, which [...]