A vulnerability in Microsoft Internet Explorer (IE) browser is leaving thousands of businesses open to targeted attacks. Microsoft group manager of response communications Dustin Childs revealed the threat in a security advisory, confirming that hackers are actively exploiting a weakness in the browser. "Today we released Security Advisory 2887505 regarding an issue that affects IE. There are only reports of a limited number of targeted attacks specifically directed at IE8 and 9, although the issue could potentially affect all supported versions," Childs said. "This issue could allow remote code execution if an affected system browses to a website containing malicious content directed towards the specific browser type. This would typically occur when an attacker compromises the security of trusted websites regularly frequented, or convinces someone to click on a link in an email or instant message." Since being revealed numerous security vendors have released their own advisories warning of the potential damage an attack targeting the vulnerability could do. noted the vulnerability could be used for a variety of purposes by hackers. <more>
Saturday, September 21, 2013
Self-healing BIOS for HP Systems
HP has released a self-healing computing startup software that can repair a PC from a malware attack. HP BIOSphere with SureStart technology is a new kind of startup software that runs when a PC is turned on. The BIOS, basic input output software, runs on every PC and loads before even the operating system. HP has created its own BIOS software because hackers have been able to get around other BIOS software underneath the OS or gain root access to compromise OS security protections. The new HP BIOS makes it so the PC can heal itself by comparing the BIOS attempting to load against an image of the BIOS that is supposed to run on the PC. <more>
Saturday, September 14, 2013
Microsoft issued 13 bulletins in September's Patch Tuesday
Microsoft has dispatched 13 patches for 47 bugs in its Windows, Office, Internet Explorer and SharePoint Server products. The Patch Tuesday release includes four critical patches, or Microsoft "bulletins," with the bug of utmost concern being a privately reported vulnerability in Microsoft Outlook. The bug could allow a remote attacker to execute code if a user merely previews a malicious email message in Outlook or opens it, a Tuesday bulletin summary said. On Tuesday, Dustin Childs, group manager of response communications for the Microsoft Trustworthy Computing team, wrote in a blog post that the patch for Outlook was the "first bulletin that caught [his] attention." <more>
Subscribe to:
Posts (Atom)