Ryan Naraine

Microsoft Withdraws 4 Patch Day Bulletins

Microsoft has suddenly yanked four bulletins from next Tuesday’s Patch Day batch, a surefire sign that the company continues to struggle with the patch testing process.

Apple Flaw Project Odds and Ends

MoAB update: An official patch from VideoLAN, hidden taunts and heated verbal punditry.

Where’s Microsoft on CVSS Support?

Cisco has joined Oracle and others supporting the Common Vulnerability Scoring Standard, but unless Microsoft joins the party, the flaw rating scheme will continue to flounder.

Can Apple Overcome Latest Security Backlash?

A pair of renegade hackers has launched a project aimed at embarrassing Apple Computer into fixing software vulnerabilities in a timelier manner, prompting new calls for the Cupertino, Calif. company to hire a security czar to head off a growing crisis. The MoAB (Month of Apple Bugs) launched on New Years day with technical details […]

Security Flaws Haunt PDF, OpenOffice Users

Serious security vulnerabilities in two desktop applications could allow malicious hackers to plant malicious code on millions of computers, according to warnings from the U.S. governments computer emergency response team. The more serious of the two is a cross-site scripting bug in Adobes ever-present Acrobat Plug-In, which fails to properly validate user-supplied data. The issue, […]

Patch Tuesday: Critical MS Office Fixes Coming

Microsofts security response team has announced plans to release eight security bulletins Jan. 9 with patches for a slew of Windows and Office vulnerabilities. Four of the bulletins will deal directly with the Microsoft Office desktop suite, which includes the Microsoft Word software that has been the target of zero-day malware attacks. During December 2006, […]

Cisco + IronPort = Done Deal

The rumor mill is buzzing tonight about an $825 million merger between Cisco and IronPort.

Flash Phishing, MySpace Passwords and Hacking PDFs

LINKS DU JOUR: Google’s blacklisted URL database is chock-full of MySpace log-in credentials; Who knew Symantec had a full-fledged rock band?

VLC Media Player Bug Bites at Apple

UPDATE: The second flaw warning in the Month of Apple Bugs project is for a remote code execution issue affecting the cross-platform VLC media player distributed by VideoLAN.

Month of Apple Bugs, Meet Month of Patches

Its officially a cat-and-mouse race to exploit—and fix—security vulnerabilities affecting Apple Computers Mac operating system. Less than 24 hours after the release of working exploits for two critical media player flaws—QuickTime and VLC—a former engineer in Apples BSD Technology Group has launched an effort to provide run-time fixes for each flaw released during the Month […]