Security News


August Patch Brings Windows ATL Fixes, and More

Tuesday's nine security patches are all about networking, the Internet, servers and interoperable components that tie everything together.

Twitter Attack May Have Its Origins in Malware

System administrators might be more pleased than dismayed when a social networking site such as Twitter locks out millions of users.

Nine Security Patches To Come on Tuesday

Expect nine patches in Microsoft's August security update, five "critical" and four "important," according to an advanced notification from Redmond.

Serious Price Tag Overshadows Cloud Computing

Cloud computing promises cost savings, increased flexibility and improved remote access to resources, but these advantages come at a cost.

Adobe Bugs Linked to Microsoft ATL Flaw

When Adobe announced that it would periodically have Patch Tuesday releases of its own to coincide with Microsoft's, it became clear that Windows plays a vital role in the third-party software firm's security repertoire.

Off-Cycle Patches Issued for Visual Studio and IE

Redmond on Tuesday released a security advisory concerning its Active Template Library technology, accompanied by two out-of-band application patches.

Microsoft Rolls Out New Security Initiatives

The Black Hat security conference continues this week in Las Vegas and Microsoft is once again rallying its industry allies, and even its competitors, to a common cause.

Microsoft Renames 'Geneva' ID Management Solutions

Microsoft announced product names for its latest claims-based identity management server platform, dropping the "Geneva" code name.

Microsoft Office ActiveX Security Flaws Disclosed

On the eve of its July security patch release, Redmond issued a security advisory on flaws in the ActiveX control function -- the second such advisory in as many weeks.

Microsoft Probing ActiveX Bug in Internet Explorer

Microsoft continues to investigate a new vulnerability revealed at the top of the week regarding an ActiveX control component in Internet Explorer.

Microsoft Ends Java Virtual Machine Support

Microsoft gave notice on Thursday that it removed 10 security patch downloads, all associated with Microsoft Java Virtual Machine technology

Heavy Security Patch Coming on Tuesday

June may prove to be a busy month for IT pros, with Microsoft planning to release 10 fixes in its next security patch.

Cybersecurity Policy Will Pose Challenges, Security Pros Say

Now that there's some movement toward a U.S. cybersecurity policy, it's time to roll up the sleeves and get to work, and that task won't be easy, software security experts suggested on Friday.

DirectShow Subject to Attacks, Microsoft Warns

Microsoft issued a security advisory on Friday describing a newly disclosed bug in Microsoft DirectShow that could enable remote code execution attacks.

Private Clouds Better for Security, Red Hat CEO Says

A private cloud could offer almost all the benefits of a public cloud, but without the attendant security and privacy headaches, said Jim Whitehurst, president and chief executive officer of enterprise open source software vendor Red Hat.

Microsoft Offers Security Lifecycle Tool for VSTS

Teams developing applications using Microsoft Visual Studio Team System 2008 (VSTS 2008) can now better implement Microsoft's security development lifecycle (SDL) process using a new template addition.

Microsoft Issues Security Alert on IIS Web Server

Responding to public reports of a wild bug, late Monday Microsoft issued a security advisory to address a potential vulnerability in its Internet Information Services (IIS) Web server software.

Adobe's Reader Fix: Disable JavaScript, For Now

How Adobe is handling critical vulnerability discovered in its Reader software gets mixed reaction from IT security experts.

Reporter's Notebook: Cloud Security a Key Focus at RSA

Concerns about the security implications of evolving cloud computing technologies dominated last week’s annual RSA Conference.

RSA: Hackers Shifting Focus to App Software

Writing more secure software is not a simple task, but it can and should be done for applications, experts say.