18 months' porridge for banking malware-spreader
A Brit who distributed a Trojan horse that posed as a patch for popular shoot-em-up game Call of Duty has been jailed for 18 months.…
A Brit who distributed a Trojan horse that posed as a patch for popular shoot-em-up game Call of Duty has been jailed for 18 months.…
Apple released Safari 5.1.7 addressing multiple cross-site scripting, remote code execution, crashes and other vulnerabilities. Also notable is the automatic deactivation of Adobe Flash Player if it is older than 10.1.102.64 by moving its files to a new directory. This update presents the option to install an updated version of Flash Player from the Adobe website.
Safari 5.1.7 is available via the Apple Software Update application, or Apple’s Safari download site at: http://www.apple.com/safari/download/.
OS X Lion v10.7.4 and Security Update 2012-002 is now available and addresses a multitude of vulnerabilities. For more information visit the dedicated Apple KB article.
OS X Lion v10.7.4 and Security Update 2012-002 may be obtained from the Software Update pane in System Preferences, or Apple’s Software Downloads web site: http://www.apple.com/support/downloads/. The Software Update utility will present the update that applies to your system configuration. Only one is needed, either Security Update 2012-002 or OS X v10.7.4.
Sorin Mustaca
Apple released security updates yesterday that fix various vulnerabilities in Mac OS X and the Safari browser.
The developers of PHP have released updates to thwart fresh attacks against systems that use the scripting language to dynamically generate web pages.…
Microsoft released seven bulletins fixing 23 vulnerabilities in their patch Tuesday announcement today. The Redmond, Wash., software giant rated three of the bulletins as ‘critical,’ all of which could lead to remote code execution, and the remaining four as ‘important.’
UPDATE--The developers of PHP have released new versions of the scripting language to fix a remotely exploitable vulnerability announced earlier this week that enables an attacker to pass command-line arguments to the PHP binary. The flaw has been in the code for more than eight years and The PHP Group was working on a patch for it when the bug was disclosed accidentally on Reddit. However, the team that found the bug says the new versions of PHP don't actually fix the vulnerability.