also @ TechSpot: iTunes 11.0.3 delivers revamped MiniPlayer, security fixes

TechSpot News

vulnerability articles


Origin vulnerability lets attackers hijack gaming machines

Origin vulnerability lets attackers hijack gaming machines
  • Posted March 19, 2013, 2:00 PM by Matthew DeCarlo | Filed in IT Security, Software
  • Upwards of 40 million users of EA's Origin game platform could be open to a vulnerability that allows an attacker to remotely execute malicious code. Demonstrated by ReVuln on Friday at the Black Hat security conference in Amsterdam, the process requires Origin's client...

Microsoft to address four critical flaws on Patch Tuesday

Microsoft to address four critical flaws on Patch Tuesday
  • Posted March 8, 2013, 5:30 PM by Shawn Knight | Filed in IT Security, Microsoft
  • Patch Tuesday is once again upon us as Microsoft is preparing to push out a bundle of security fixes on March 12. The upcoming release will consist of seven fixes, four of which are deemed critical as they could allow…

Weekend tech reading: Hurried Java update plugs 50 holes

Weekend tech reading: Hurried Java update plugs 50 holes
  • Posted February 3, 2013, 11:53 AM by Matthew DeCarlo | Filed in NATW
  • Oracle has been under increasing pressure in recent months to finally fix the myriad of security flaws that have plagued Java. In an unexpected emergency out-of-band patch released Friday afternoon, Oracle has responded definitively to critics with a massive security patch...

Microsoft to fix critical Internet Explorer vulnerability today

Microsoft to fix critical Internet Explorer vulnerability today
  • Posted January 14, 2013, 12:00 PM by Shawn Knight | Filed in Software, Microsoft
  • Microsoft will be releasing an out-of band patch later today to fix a critical zero-day flaw affecting Internet Explorer versions 6,7 and 8. The vulnerability allows hackers to execute code remotely in the event that a user visits an infected website.

New zero-day vulnerability in Java being widely exploited (Updated)

New zero-day vulnerability in Java being widely exploited (Updated)
  • Posted January 14, 2013, 1:54 AM by Jose Vilches | Filed in IT Security
  • Three days after a critical Java vulnarability was widely reported, Oracle has issued an update to shut down the potential exploit and secure browsers using Java. You can update to Java SE 7u11 to secure your PC (or disable Java altogether). The security hole made browsers vulnerable to remote exploits when visiting a malicious website.

Hole in W3 Total Cache WordPress plugin exposes site database info

Hole in W3 Total Cache WordPress plugin exposes site database info
  • Posted December 27, 2012, 6:00 PM by Matthew DeCarlo | Filed in IT Security, The Web
  • Security researcher Jason A. Donenfeld has revealed a security hole in a popular WordPress plugin that could be used to obtain sensitive data from an affected site. The flaw was discovered in W3 Total Cache, which has been downloaded over a million times and is used by...

Android apps used by millions vulnerable to data theft

Android apps used by millions vulnerable to data theft
  • Posted October 22, 2012, 4:30 PM by Jose Vilches | Filed in Mobile Computing, IT Security Breaking News
  • Security researchers at the Leibniz University of Hanover have released a study showing that more than 1,000 legitimate Android apps, out of a sample of 13,500 popular apps from the Google Play market, contain inadequate SSL protections that could leave…

Security researchers discover vulnerability in Steam URL protocol

Security researchers discover vulnerability in Steam URL protocol
  • Posted October 18, 2012, 12:30 PM by Shawn Knight | Filed in IT Security, Gaming With Video
  • Security researchers from ReVuln have discovered a zero-day vulnerability in Valve’s Steam browser protocol. The exploit can allow an attacker to remotely exploit bugs in the Steam client or directly in games which can ultimately be used to run malicious…

Mozilla patches a security flaw introduced by Firefox 16

Mozilla patches a security flaw introduced by Firefox 16
  • Posted October 11, 2012, 4:30 PM by Matthew DeCarlo | Filed in Software, IT Security
  • Folks who installed Firefox 16 on Tuesday may want to ensure that they've received an update released this afternoon (16.0.1) which addresses a security flaw. On Wednesday, Mozilla halted distribution of Firefox 16 after learning about a vulnerability that could…

Researcher uncovers new Java exploit, 1 billion Macs and PCs at risk

Researcher uncovers new Java exploit, 1 billion Macs and PCs at risk
  • Posted September 26, 2012, 1:30 PM by Shawn Knight | Filed in IT Security, Software
  • Security researcher Adam Gowdiak has uncovered a new zero-day vulnerability in Oracle’s Java software. The bug is said to be present in currently-supported versions including Java 5, Java 6 and Java 7 and has the potential to allow attackers to…

Internet Explorer hit by zero-day exploit, temporary fix issued

Internet Explorer hit by zero-day exploit, temporary fix issued
  • Posted September 18, 2012, 10:30 AM by Lee Kaelin | Filed in Microsoft, IT Security
  • Microsoft is urging users of Internet Explorer to download a free security tool, enhanced Mitigation Experience Toolkit (EMET), as an interim measure against a previously unknown zero-day exploit in its web browser software that is under active malware attack by hackers. …

SMS spoofing vulnerability exposed in Apple's iOS

SMS spoofing vulnerability exposed in Apple
  • Posted August 17, 2012, 1:30 PM by Jose Vilches | Filed in Apple, IT Security
  • A prominent jailbreaker that goes by the handle Pod2g has exposed a vulnerability in the way iOS interprets key SMS data that could allow scammers to gain sensitive information from iPhone users. Essentially, the flaw makes it possible to change…

Microsoft and Adobe release a slew of critical security updates

Microsoft and Adobe release a slew of critical security updates
  • Posted August 14, 2012, 6:00 PM by Matthew DeCarlo | Filed in Microsoft, Software
  • Microsoft and Adobe have unleashed a series of software updates today, plugging a ton of security holes. The latest Patch Tuesday consists of nine bulletins including five rated as critical and four deemed important. One of the bulletins, MS12-060, addresses a flaw in all...

Critical vulnerabilities in Huawei routers laid bare at Defcon

Critical vulnerabilities in Huawei routers laid bare at Defcon
  • Posted July 31, 2012, 4:30 PM by Lee Kaelin | Filed in Hardware, IT Security
  • A security researcher for German security firm Recurity Labs has disclosed several critical vulnerabilities in router products made by Huawei at the annual Defon hackers conference on Sunday. 

Microsoft urges Windows Vista, 7 users to disable desktop gadgets

Microsoft urges Windows Vista, 7 users to disable desktop gadgets
  • Posted July 11, 2012, 1:30 PM by Matthew DeCarlo | Filed in Microsoft, IT Security
  • In a security advisory Tuesday, Microsoft urged Windows Vista and 7 users to download a tool that disables the operating system's sidebar and gadgets. The company warned that insecure gadgets could be used to run arbitrary code on a computer...

Internet Explorer zero-day flaw being used to target Gmail accounts

Internet Explorer zero-day flaw being used to target Gmail accounts
  • Posted June 14, 2012, 9:30 AM by Shawn Knight | Filed in IT Security
  • A new zero-day exploit in Internet Explorer making the rounds has security experts from Microsoft and Google on their heels. The drive-by flaw is being used to gain access to Gmail accounts and remains unpatched as of writing, although Microsoft…

Max Payne 3 multiplayer cheaters forced to play with each other

Max Payne 3 multiplayer cheaters forced to play with each other
  • Posted June 13, 2012, 3:30 PM by Matthew DeCarlo | Filed in Gaming
  • Given the complexity of modern games, they inevitably ship with glitches and vulnerabilities. Such is the case with Max Payne 3, which has a problem with multiplayer cheaters using invincibility hacks, infinite adrenaline exploits and more. Although most people are honest...

Microsoft patches zero day password reset bug in Hotmail

Microsoft patches zero day password reset bug in Hotmail
  • Posted April 30, 2012, 9:30 AM by Lee Kaelin | Filed in IT Security, Microsoft
  • Microsoft has rushed out a fix for a critical zero day bug on their popular Hotmail service after it was discovered by a security researcher earlier in the month. Although it was reported to Microsoft in a timely manner, details…

Google wants hackers to hammer on Chrome for $1 million

Google wants hackers to hammer on Chrome for $1 million
  • Posted February 28, 2012, 6:30 PM by Matthew DeCarlo | Filed in IT Security, Software
  • Google has withdrawn support for TippingPoint's annual Pwn2Own hacking competition following rule changes. Previously, entrants were required to reveal all the details about exploits used to compromise security. That stipulation no longer exists and folks are allowed to enter 2012's…

Swagg Security hackers hit Foxconn, release usernames and passwords

Swagg Security hackers hit Foxconn, release usernames and passwords
  • Posted February 9, 2012, 11:00 AM by Lee Kaelin | Filed in IT Security
  • Foxconn, the enormous manufacturing supplier to some of the world's largest technology firms has been hit by a new group of hackers looking to make a name for themselves. On Wednesday evening, a team calling themselves Swagg Security claimed they…

GSM security vulnerability affects 80 percent of mobile phones worldwide

GSM security vulnerability affects 80 percent of mobile phones worldwide
  • Posted December 27, 2011, 11:00 AM by Shawn Knight | Filed in IT Security, Mobile Computing
  • A new flaw in the GSM (Global System for Mobile Communications) cellular network technology could potentially allow a hacker to gain control of a phone and force the device to send text messages or place phone calls. Criminals could use…

SMS flaw discovered in Windows Phone 7.5

SMS flaw discovered in Windows Phone 7.5
  • Posted December 13, 2011, 8:39 AM by Lee Kaelin | Filed in Mobile Computing, Software With Video
  • Microsoft's mobile platform is coming under increased scrutiny after it was revealed that smartphones running Windows Phone 7.5 are at risk of denial-of-service (DoS) attacks that can disable their messaging functions.

HP sued over LaserJet printer security flaw

HP sued over LaserJet printer security flaw
  • Posted December 9, 2011, 2:00 PM by Lee Kaelin | Filed in Industry News, IT Security
  • Last week researchers at Columbia University demonstrated a security flaw in certain Hewlett Packard LaserJet printers that, if exploited, could lead to them catching fire. The team also pointed out that the flaw might not be limited to just HP branded…

Hackers exploit zero day vulnerability in Adobe Reader and Acrobat

Hackers exploit zero day vulnerability in Adobe Reader and Acrobat
  • Posted December 7, 2011, 9:30 AM by Lee Kaelin | Filed in IT Security
  • Adobe confirmed yesterday that its Adobe Reader software contains a zero-day vulnerability, crediting the security team at Lockheed Martin, which itself was a victim of an attack through the exploit, and members of the Defense Security Information Exchange for discovering…

1the archive »

TechSpot on:

Subscribe to TechSpot

Get free exclusive content, learn about new features and breaking tech news.