2011 in Review: Exploits and Vulnerabilities

In recent years, we have seen client-side software heavily targeted by hackers in search of vulnerabilities. 2011 saw these threats become more complex and sophisticated. We saw attackers increasingly use zero-day vulnerabilities, some of which have been particularly critical. Examples of these include the vulnerability Duqu exploited (CVE-2011-3402); a Java vulnerability (CVE-2011-3544); or Adobe zero-day [...]

Emergency Adobe Flash Player patch coming today

Less than a week after warning that hackers were embedding malicious Flash Player files (.swf) into Microsoft Word documents to launch targeted malware attacks, Adobe plans to release an emergency Flash Player patch today to fix the underlying problem.The patch will fix a “critical” vulnerability in Flash Player 10.2.153.1 and earlier versions for Windows, [...]

Adobe warns of new Flash Player zero-day attack

Hackers are embedding malicious Flash Player files in Microsoft Word documents to launch targeted attacks against select businesses, according to a warning from Adobe.This latest Flash Player zero-day attack comes just weeks after EMC’s RSA Division was hit with a malware attack that used a rigged Flash (.swf) file embedded in a Microsoft [...]

Google Chrome gets last-minute bandaid before Pwn2Own

Google isn’t taking any chances with this year’s CanSecWest Pwn2Own hacker challenge.Just days before the annual contest where hackers are invited to break into the three main web browsers, Google pushed out another Chrome patch to fix a whopping 24 security holes.  The majority of these vulnerabilities are rated “high risk” and could lead [...]

From RSA 2011: Security, Social Media and Spies

Like my colleagues, I also attended RSA 2011 Conference in San Francisco last week. As they have shared in their posts on the hackers and threats sessions, I would like to share some of my experiences and learnings on sessions involving social media, spies and security. Mapping an Organization’s DNA Using Social Media Abhilash Sonwane [...]