Security News


First Instance of New DNS Exploit Reported

Reports are coming in that an AT&T Domain Name System (DNS) server may have been compromised with malicious code that exploits a vulnerability reported earlier this month. This apparently is the first instance of the exploit in the wild.

WebLogic Security Hole Found

A recently uncovered flaw with the Oracle WebLogic server allows users to gain entry to the software's server without a user name or password.

DNS Problem Is 'Important' To Patch, Microsoft Says

The company issued a reminder to patch a Domain Name System flaw affecting some Windows products.

Most Malware Found on Trusted Web Pages, Report Says

Sites such as Facebook, LinkedIn and Blogspot.com represent vectors for attack.

DNS Flaw Unfixed as Experts Argue Protocol

Speculation continues as to what the ultimate systemic Domain Name System (DNS) flaw could be.

Microsoft's DNS Fix Leads to More Problems

The blogosphere is awash with talk about the possible overall weakness of the Domain Name System (DNS) architecture.

Open Source Needs Better Security Focus, Study Says

The open source software community lags behind the commercial software sector in secure code development, according to a recent study of some commonly used open source packages.

Compliance, New Threats Drive Security Spending

Enterprise security is an expensive proposition, one that's likely to get even more expensive as organizations take further steps to protect themselves.

Microsoft's $60B Year-End Revenue Dogged by Search Costs

Microsoft's fiscal fourth-quarter and 2008 year-end financial results were announced in a Webcast on Thursday.

Oracle Releases Critical Updates

Oracle databases 9i through 11g, Oracle Application Server, Oracle PeopleSoft Enterprise CRM among products patched.

Government, Health Care Web Sites Attacked

A scan of Web servers by Internet security company Finjan Inc. has found more than 1,000 legitimate Web sites that had been compromised by a new wave of attacks in recent weeks.

Sentrigo Offers Help for Database Patching Woes

Security layer product is designed to help database administrators when databases go unpatched.

Massive Patch Coming for DNS Vulnerability

Major vendors of domain name system (DNS) servers are making an unprecedented coordinated release of patches for what is being called a fundamental flaw in DNS, a core element of the Internet.

Microsoft Talks Up SDL

Redmond’s Secure Development Lifecycle requirements aim to counter security defects in the face of recent SQL attacks.

Citibank Hack Shines Light on PCI Compliance

Just two days after the Payment Card Industry (PCI) Security Standards Council announced the deadline for application security compliance and said it would be issuing guidelines for PIN entry devices, court documents have emerged detailing an elaborate plot to hack Citibank's ATM network architecture.

Data Breaches Up in First Half of 2008

Reported data breaches increased sharply in the first six months of 2008, jumping 69 percent compared to the same period last year, according to a study by the Identity Theft Resource Center (ITRC).

IE Is Least-Patched Browser, Report Says

More than 40 percent of Internet surfers don't use browsers with up-to-date security patches -- and IE users are the biggest culprits.

Another Patch-Blocking Problem for Microsoft

Microsoft issued an advisory alerting users about a glitch that prevents security updates from being distributed through specific Windows Server Update programs.

Microsoft's XP SP3 Patch Fixes Antivirus Glitch

The hotfix addresses a registry corruption problem that was associated with PCs using Symantec's Norton Antivirus software.

Microsoft Advisory Targets SQL Injection Attacks

Company issues three tools to help Web developers with security.