All TechBlog Health Electronics Cozy Corner

Adobe fixes ColdFusion security vulnerability

Author: Omid Farhang Published: September 12, 2012 Reading Time: 1 min

h-Online: On the same day as Microsoft’s September Patch Tuesday, Adobe released an update for ColdFusion to close a security hole in its rapid web application development software. The hotfix for ColdFusion addresses a vulnerability (CVE-2012-2048), which the company rates as important, that could be exploited by a remote attacker to cause a denial-of-service (DoS) condition. According to Adobe, the unspecified error affects versions 8.0, 8.0.1, 9.0 to 9.0.2, and 10 of ColdFusion for Windows, Mac OS X and UNIX. Installing the provided hotfix corrects the problem; download links and installation instructions for each affected version are provided on the APSB12-21 technote page. All users are advised to download and apply the hotfix. Adobe credits UK developer David Boyer for finding and reporting the problem. ...

Continue Reading Adobe fixes ColdFusion security vulnerability

Microsoft to patch Flash hole in Windows 8 shortly

Author: Omid Farhang Published: September 12, 2012 Reading Time: 2 min

h-online: Microsoft has confirmed that it will deliver a security update for the bundled version of Flash Player used by Internet Explorer 10 (IE10) sooner than previously planned. In a statement sent to ZDNet, Yunsun Wee, Trustworthy Computing Director at Microsoft, said that the company is working closely with Adobe on an updated version of the Flash plugin which “will be available shortly”. The forthcoming Windows 8 comes with Internet Explorer 10, which, in turn, includes its own version of Flash Player. This arrangement relies on Microsoft’s automatic updates system, Windows Update, for updating the version of Flash included in the web browser. ...

Continue Reading Microsoft to patch Flash hole in Windows 8 shortly

Google Acquires VirusTotal

Author: Omid Farhang Published: September 7, 2012 Reading Time: 1 min

This is what we read in latest post from VirusTotal in their blog: Our goal is simple: to help keep you safe on the web. And we’ve worked hard to ensure that the services we offer continually improve. But as a small, resource-constrained company, that can sometimes be challenging. So we’re delighted that Google, a long-time partner, has acquired VirusTotal. This is great news for you, and bad news for malware generators, because: ...

Continue Reading Google Acquires VirusTotal

Symantec releases Norton 2013 security suites

Author: Omid Farhang Published: September 7, 2012 Reading Time: 3 min

BetaNews: Symantec has released brand new versions of its Norton security packages for Windows, Norton Anti-Virus 2013, Norton Internet Security 2013 and Norton 360 2013. It’s the first time all three packages have been updated simultaneously, while the branding has also been amended to remove all references to a date, simply naming each Norton Anti-Virus, Norton Internet Security and Norton 360, respectively. The 2013 versions come with what Symantec describes as “five layers of patented protection”, which include stronger social networking and anti-scam protection. There’s also full, certified support for Windows 8 and the promise of better performance on multi-core CPUs. ...

Continue Reading Symantec releases Norton 2013 security suites

Symantec claims losses from cybercrime exceed $100 billion

Author: Omid Farhang Published: September 7, 2012 Reading Time: 2 min

h-Online: According to Symantec’s 2012 Norton Cybercrime Report, worldwide, private individuals have suffered approximately $100 billion (more than £69 billion at the current exchange rate) in financial losses as a result of cybercrime. In the period from July 2011 to July 2012, losses averaged $197 (£124) per victim. A total of 556 million adults are reported to have fallen victim to malware, phishing or similar virtual crimes. The report claims that there are 1.5 million victims of cybercrime each day, or about 18 per second. The security specialist’s report also states that two-thirds of internet users have been caught out by cybercriminals at some point in their lives, and almost half (46%) were victims during the period covered by the report. The results reveal that many of those affected are victims of their own carelessness. Around 40% of people don’t use complex passwords or don’t change their passwords regularly. ...

Continue Reading Symantec claims losses from cybercrime exceed $100 billion

1 million Apple Device IDs leaked, claim hackers

Author: Omid Farhang Published: September 4, 2012 Reading Time: 2 min

According to the AntiSec hacker group, they claim to hold more than 12 million Apple iOS Unique Device IDs, in addition to other personal information from device owners. As a move to back up such a claim, the AntiSec hacker group is said to have released slightly more than a million Apple Device IDs to the masses. This particular expose was unveiled on Pastebin, which is said to hold a detailed description of the method that the hacking group were said to have obtained the IDs from the FBI. ...

Continue Reading 1 million Apple Device IDs leaked, claim hackers

I want, I don’t want

Author: Omid Farhang Published: September 2, 2012 Reading Time: 2 min

I never could understand those people that afraid everything and everyone, why people don’t live in a normal and easy world? Why take it so hard? I’m talking of the moment when I respect a boy and he behaves defensive because he thinks I’m looking for his money… I’m talking of the moment when I respect a man and he behaves defensive because he thinks I’m looking to use his position… ...

Continue Reading I want, I don’t want

Oracle rushes out patch for critical 0-day Java exploit

Author: Omid Farhang Published: August 31, 2012 Reading Time: 2 min

TheRegister: In an uncommon break with its thrice-annual security update schedule, Oracle has released a patch for three Java 7 security flaws that have recently been targeted by web-based exploits. “Due to the high severity of these vulnerabilities, Oracle recommends that customers apply this Security Alert as soon as possible,” Eric Maurice, the company’s director of software security assurance, said in a blog post published on Thursday. Maurice said that the vulnerabilities patched only affect Java running in browsers, and not standalone desktop Java applications or Java running on servers. According to Oracle’s official advisory on the flaws: ...

Continue Reading Oracle rushes out patch for critical 0-day Java exploit

Download Firefox 15 and Thunderbird 15!

Author: Omid Farhang Published: August 28, 2012 Reading Time: 3 min

Cross-copied from BetaNews: Mozilla has quietly placed major new versions of its open-source, cross-platform web browser and email client onto its download servers ahead of an official release. Firefox 15 FINAL benefits largely from behind-the-scenes performance tweaks, while Thunderbird 15 FINAL introduces a few new features, including a new curvy user interface. Firefox 15 FINAL’s most notable changes are performance-based. There’s faster startup on Windows PCs, plus incremental garbage collection and better management of plugins to prevent memory leaks. Other performance improvements surround WebGL enhancements. ...

Continue Reading Download Firefox 15 and Thunderbird 15!

Java zero day vulnerability actively used in targeted attacks

Author: Omid Farhang Published: August 27, 2012 Reading Time: 1 min

ZDNet: Security researchers from FireEye, AlienVault, and DeependResearch have intercepted targeted malware attacks utilizing the latest Java zero day exploit. The vulnerability affects Java 7 (1.7) Update 0 to 6. It does not affect Java 6 and below. Based on related reports, researchers were able to reproduce the exploit on Windows 7 SP1 with Java 7 Update 6. There’s also a Metasploit module available. Upon successful exploitation, the campaign drops MD5: 4a55bf1448262bf71707eef7fc168f7d – detected by 28 out of 42 antivirus scanners as Gen:Trojan.Heur.FU.bqW@a4uT4@bb; Backdoor:Win32/Poison.E ...

Continue Reading Java zero day vulnerability actively used in targeted attacks