Robert Lemos

…articles and musings of a technology and science journalist

Robert Lemos header image 4

Entries Tagged as 'SecurityFocus'

Zero-day sales not “fair” — to researchers

June 1st, 2007 · No Comments

A security analyst tries his hand at selling two vulnerabilities and finds that economics and time are against him.
SecurityFocus

[Read more →]

Tags: Flaws and vulnerabilities · Government · Research · Security · SecurityFocus

Insecure plug-ins pose danger to Firefox users

May 30th, 2007 · No Comments

A security researcher warns that an insecure update mechanism for some of the open-source browser’s third-party add-ons could allow an attacker the ability to install malicious code.
SecurityFocus

[Read more →]

Tags: Flaws and vulnerabilities · Open Source · Research · Security · SecurityFocus

Peer-to-peer networks co-opted for DOS attacks

May 28th, 2007 · No Comments

Attackers compromise the hub servers of the DC++ peer-to-peer network, turning hundreds of thousands of clients into hard-to-stop distributed denial-of-service attacks.
SecurityFocus

[Read more →]

Tags: Critical infrastructure · Flaws and vulnerabilities · Security · SecurityFocus · Viruses and worms

“Data storm” blamed for nuclear-plant shutdown

May 18th, 2007 · No Comments

A Congressional committee calls for the Nuclear Regulatory Commission to further investigate the cause of excessive network traffic that shut down an Alabama nuclear plant.
SecurityFocus

[Read more →]

Tags: Critical infrastructure · Flaws and vulnerabilities · Government · Homeland Security · Security · SecurityFocus

Experts scramble to quash IPv6 flaw

May 9th, 2007 · No Comments

Only a few weeks after researchers raised the design issue in the next-generation Internet protocol, two drafts to the Internet Engineering Task Force propose different fixes.
SecurityFocus

[Read more →]

Tags: Critical infrastructure · Flaws and vulnerabilities · Research · Security · SecurityFocus

E-Gold charged with money laundering

April 30th, 2007 · No Comments

Federal prosecutors claim the company and its owners violated federal funds transfer laws, saying it knowingly served online scammers, identity thieves and child pornographers.
SecurityFocus

[Read more →]

Tags: Cybercrime · Government · Security · SecurityFocus

A Mac gets whacked, a second survives

April 21st, 2007 · No Comments

Researchers use a previously unknown flaw in Apple’s Safari browser to compromise a MacBook Pro and win the PWN to Own contest, but does the hack actually prove anything?
SecurityFocus

UPDATE: More on the vulnerability, which is a Java flaw in QuickTime.

[Read more →]

Tags: Consumer Tech · Flaws and vulnerabilities · Research · Security · SecurityFocus · Software

MacBooks withstand mild attacks on patch day

April 19th, 2007 · No Comments

On the same day that Apple releases an update for its Mac OS X, security professionals at a conference in Canada show little initial interest in attempting to crack the security of two MacBook Pros.
SecurityFocus

[Read more →]

Tags: Flaws and vulnerabilities · Research · Security · SecurityFocus · Software

Attackers improve on JavaScript trickery

April 18th, 2007 · No Comments

Latest malicious software throws in more obfuscation and works harder to foil defenders’ attempts at reverse engineering.
SecurityFocus

[Read more →]

Tags: Consumer Tech · Flaws and vulnerabilities · Research · Security · SecurityFocus

U.S. agencies get ‘C-’ for computer security

April 13th, 2007 · No Comments

In an annual report card mandated by federal law, two dozen federal agencies improve their average grade slightly from last year’s ‘D+’.
SecurityFocus

[Read more →]

Tags: Critical infrastructure · Government · Homeland Security · Security · SecurityFocus