Google has begun testing a new distributed denial of service (DDoS) protection service, codenamed Project Shield, to help fight back against this growing cyber threat facing digital businesses. Google confirmed Project Shield is currently running on a trial basis and is open for use on an invite-only basis. "Project Shield is an initiative to expand Google's own distributed denial of service (DDoS) mitigation capabilities to protect free expression online. The service is currently invite-only. We are accepting applications from websites serving news, human rights or elections-related content." The service works using a variety of existing Google technologies, the firm explained: "Project Shield is a service that currently combines Google's DDoS mitigation technologies and Page Speed Service (PSS) to allow individuals and organisations to better protect their websites by serving their content through Google's own infrastructure, without having to move their hosting locations." <more>
Saturday, October 26, 2013
Oracle Quarterly Patch Update Fixes 127 Security Bugs
Oracle has released a whopper of a critical patch update for October, with 127 security fixes across several of the company's products. Of these, 51 are fixes for Java SE, and all but one of those will allow remote exploitation of a computer without authentication. Oracle recommends the patch be applied as soon as possible, as many of the vulnerabilities cross product family lines, and its products are interdependent. However, the patch applies only to products whose licensees have premier support or extended support. 40 of the 51 Java vulnerabilities apply to client deployment of Java. Of these, one is exploitable only during the act of deploying Java clients; the rest apparently can be exploited on Java clients at other times. Eight of the Java flaws impact both client and server-side implementations. Of the remaining three, one applies to the Java Heap Analysis, and two apply to sites that run the Javadoc Tool as a Service. <more>
Saturday, October 12, 2013
October's Patch Tuesday fixes IE, Word and Excel vulns
The monthly security update, which also marked the 10th anniversary of Microsoft's Patch Tuesday releases, included eight patches: four deemed "critical" and four ranked "important." In total, the patches addressed 28 vulnerabilities in the company's products, including two zero-day flaws affecting Internet Explorer: CVE-2013-3893 and CVE-2013-3897. Security bulletin MS13-080 fixed both remote code execution bugs in IE, along with eight other privately reported bugs. <more>
Subscribe to:
Posts (Atom)