Exploits / vulnerabilities - News, Features, and Slideshows

News

  • 'Night Dragon' attacks from China strike energy companies

    Chinese hackers working regular business hours shifts stole sensitive intellectual property from energy companies for as long as four years using relatively unsophisticated intrusion methods in an operation dubbed "Night Dragon," according to a new report from security vendor McAfee.

  • Oracle issues emergency Java patch

    Oracle has issued an emergency patch for a Java vulnerability that can cause systems to hang and that can be exploited by remote attackers without authentication.

  • Microsoft update offers an easier way to turn off autoruns

    Microsoft's latest round of patches released on Tuesday includes an optional update that will shut off the "autorun" capability for users of older Windows operating systems, a move the company has made to reflect the resurgence of worms carried on removable media.

  • ShmooCon: Eavesdropping easy on Evite

    Web service Evite offers more than a convenient way to send out e-mail invitations to events. For those with even a modest amount of malicious gumption, the site can also provide a treasure trove of personal information, at least according to one security researcher.

  • Carberp banking malware upgrades itself

    A piece of banking malware that researchers have been keeping an eye on is adding more sophisticated capabilities to stay hidden on victims' PCs, according to the vendor Seculert.

  • Coming soon: A new way to hack into your smartphone

    More than three years after the iPhone was first hacked, computer security experts think they've found a whole new way to break into mobile phones -- one that could become a big headache for Apple, or for smartphone makers using Google's Android software.

  • IBM DeveloperWorks site defaced

    An IBM site for developers was defaced over the weekend, with attackers replacing some of the Web pages on the site with ones containing their own messages, IBM confirmed Monday.

  • Is SAP afraid of a Stuxnet-style attack?

    Enterprise software provider SAP is stepping up its security stance as its once-isolated systems become increasingly connected to the Internet, posing new risks as hackers diversify their targets.

  • Trend Micro releases free Stuxnet detection tool

    Trend Micro has released a tool that administrators can use to scan dozens of computers at a time for Stuxnet, the malicious software program that has raised widespread concern for its targeting of industrial systems made by Siemens.

  • Antivirus software didn't help utility with malware attack

    When the zero-day attack known as the "Here You Have" virus hit about 500 PCs at the Salt River Project, a large public power utility and water supplier for Arizona, it turned out that the antivirus software in use provided no defense.

[]