Android has become an increasingly popular target for malware authors, a recent report (pdf) by NQ Mobile indicates. The security firm claims that it discovered over 65,000 types of malware -- more than double the amount from 2011 -- and bills…
Apple today released iOS 6.1.3, an update to its mobile OS which contains "improvements and bug fixes". Perhaps the most importantly though, Apple has finally fixed the lock screen (aka. passcode) bug which allowed potential miscreants to bypass lock screens…
Posted March 13, 2013, 4:30 PM by Rick Burgess | Filed in Microsoft, IT Security
Microsoft's Patch Tuesday yielded an interesting security fix for a glaring vulnerability in how the Windows kernel handles USB device enumeration. The critical vulnerability allowed potential hackers with physical access to a Windows PC to run arbitrary code with system…
Two newly-discovered Android apps found on Google Play were designed to spy on their users, claim security experts at Kaspersky. The apps, SuperClean and DroidCleaner, posed as innocuous Android clean-up utilities; however, each app could quietly copy photos, contacts and…
Posted January 29, 2013, 4:00 PM by Rick Burgess | Filed in IT Security, The Web
Several security vulnerabilities found within common UPnP implementations have prompted experts at Rapid 7 to recommend the public disable UPnP entirely. Research spanning several months in 2012 revealed that over 2 percent -- or about 50 million -- of all…
Spider.io reported today that Microsoft has no "immediate plans" to fix the potential Internet Explorer vulnerability which allows any website operator (or advertiser, hacker etc...) to track a visitor's mouse cursor movements. Microsoft's security team has acknowledged the issue but…
Microsoft says a crack which allows hackers to download paid-for Windows Store apps without spending a dime is the fault of insecure app code and not a Windows Store issue. Redmond is essentially placing the onus of protecting apps against…
A sophisticated, multi-layered trojan dubbed "Eurograbber" is estimated to be responsible for siphoning over €36 million -- or about $46.5 million -- from the bank accounts of unsuspecting Europeans. In a case study (pdf) performed by Versafe and Check Point Software Technologies, researchers reveal…
Posted December 4, 2012, 6:00 PM by Rick Burgess | Filed in The Web
Tumblr says it has addressed a vulnerability which allowed hackers to force visitors into unwittingly reposting an offensive, expletive-ridden message condemning the "tasteless" and "bourgeoisie" blog site. More than 8,600 users were affected -- Cnet, USA Today and The Verge were…
A tool of questionable ethical value has surfaced, allowing Windows 8 users to transform trial apps into their full-fledged, paid-for counterparts. Wsservice_crk has actually been available for at least a month -- most notably at the MyDigitalLife forums -- but only…
Posted November 14, 2012, 3:30 PM by Rick Burgess | Filed in Apple, Software
Google silently rolled out an update to Chrome which featured an unusual change, apparently one worthy of an announcement on the Chrome Blog: improved Adobe Flash plug-in sandboxing. The company claims its new method of fortifying Flash makes Adobe's plug-in…
Posted November 5, 2012, 7:00 PM by Rick Burgess | Filed in Microsoft, IT Security
Researchers at Vupen, a private security firm based in France, claim to have found multiple, critical vulnerabilities in Windows 8 and Internet Explorer 10. The team's exploits allow hackers to remotely execute code, allowing crafty individuals to potentially gain control…
The U.S. Department of Homeland Security has issued another industrial control warning (pdf) regarding critical vulnerabilities found across a number of solar panel systems. Affected systems can be easily exploited using "proof of concept" code developed by security researchers Roberto Paleari…
Posted October 11, 2012, 5:30 PM by Rick Burgess | Filed in IT Security, Software
For the second time this year, hacker "Pinkie Pie" gave Google a run for its money -- and won. The clever hacker exploited yet another vulnerability in Chrome during the second Pwnium conference this year, netting himself (or perhaps herself)…
TechSpot on: