HomeBlogsSecurity Watch

Security Watch

Obama Site Hacked, Redirected to HillaryClinton.com

Hackers are having fun exposing security holes in Barack Obama's official campaign site.According to a post over at XSSed.com, a site that catalogs cross-site...

Windows XP SP3: NAP Among Security Goodies

Microsoft's Windows XP SP3 (Service Pack 3) is finally here, offering several subtle security goodies alongside thousands of bug fixes.The biggest security feature in...

Microsoft Picks New Song for Hacker Slow Dance

Microsoft has chosen a new song to continue its public slow dance with the white hat hacking community: online properties like *.microsoft.com, *.msn.com and...

Rock Phish Gang Adds Crimeware Trojan to Arsenal

The notorious Rock Phish gang is pushing the envelope again, adding a sophisticated crimeware Trojan to its identity theft arsenal.The Russian group, which is...

Chinese Hackers Knock SportsNetwork Offline; CNN.com Survives

A planned cyber-attack against CNN.com fizzled over the weekend, but The Sports Network did not survive the DDoS (distributed denial-of-service) assault by Chinese hackers.At...

OpenOffice Bitten by Code Execution Bugs

OpenOffice has issued a high-priority update to fix at least six vulnerabilities affecting users of its free desktop productivity suite.The open-source group said the...

PayPal: Safari Not Among ‘Unsafe Browsers’

Over on Twitter, during a discussion on PayPal's plan to ban "unsafe browsers," I suggested there was no way the company would risk blocking...

Major ISPs Injecting Ads, Vulnerabilities into Entire Web

DNS security guru Dan Kaminsky says the practice by major ISPs to deploy advertising servers within trademarked domains (on error pages, for example) can...

Microsoft (Belatedly) Admits to Windows Server 2008 Token Kidnapping

]Last month, when I wrote about hacker Cesar Cerrudo's (left) plans to punch holes in the security model of Microsoft's brand-new Windows Server 2008,...

Cisco NAC Can’t Keep a Secret

A serious security flaw in the Cisco NAC (Network Admission Control) appliance can allow an attacker to obtain the shared secret that is used...