Welcome back to Security 101. Our New Year’s recess is over, and it’s time to offer another lesson. So far we have discussed vulnerabilities and some types of low-interaction attack vectors. In this lesson we shall continue with attack vectors that require medium or high levels of user interaction to succeed. These attack vectors are Read more…
Tags: online security, online threats, vulnerability, web security
In my last post we discussed the most dangerous kind of vulnerabilities that we classify at McAfee Labs: remote code execution and denial of service. Today, we’ll talk about vulnerabilities that are not so dangerous, those we classify as Medium or Low Risk. These threats still require our attention because they can create a chain Read more…
Tags: attack, malware, security, Security 101, vulnerability
Welcome back to Security 101. The topic of today’s blog is vulnerabilities. In our frequent McAfee Labs Threat Advisories you see the term vulnerability in almost every item. “A vulnerability has been found…” or “A vulnerability in some versions of…” are commonplace. What is a vulnerability? A vulnerability is a program bug that under certain Read more…
Tags: attack, malware, security, Security 101, vulnerability
When I started working at McAfee, I noticed that many of the terms commonly used here were completely unknown to me. Fortunately I had no problems understanding them, but I’m sure that more than one person has read a McAfee security update and thought “What does this mean?” This question is more likely when a Read more…
Tags: attacks, malware, security, Security 101, vulnerability
This month, Apple published seven security updates resolving around 250 issues. The last patch is arrived yesterday; it addressed Mac OS X 10.6.7. Adding the CVE IDs (for Common Vulnerabilities and Exposures) listed in each patch does not give us accurate view of the number of vulnerabilities involved. Several appear in more than one patch: Read more…
Tags: Apple, Microsoft, patch, vulnerability
BlackEnergy was a very popular DDoS bot a couple of years back. This bot has been under development and has evolved quite a bit over toward its more current successor, the Darkness bot. This Bot has evolved with new features continuously added to extend its malicious capabilities. Researchers have been keeping an eye on it Read more…
Tags: critical infrastructure, Cybercrime, Data Protection, Endpoint Protection, global threat intelligence, malware, Network Security, vulnerability, Web 2.0
Jailbreaking your iOS device used to simply be about gaining some freedom–getting root access, installing native apps, and adding or modifying themes. The worst that could happen would be running into a slightly malicious installation package. Then we met the OSX/RRoll family of worms that actively went after jailbroken devices. Part of the risk came from insecure defaults Read more…
Tags: exploit, iphone, mobile devices and security threats, mobile security, vulnerability
In the last week there have been a few vulnerability disclosures for mobile web browsers. These threats affect a number of smart-phone platforms: Android (Google), WebOS (Palm), and iOS (Apple). Although all three platforms have their own apps and environments, it’s interesting that they’re all vulnerable through the same entry point of the mobile browser. Data stealing: Android Read more…
Tags: Android, iphone, mobile security, personal information over mobile phones, vulnerability, web security
Yesterday I presented on Cybercrime, Hacktivism and Cyberterrorism with one of McAfee Labs’ most senior and well respected researchers, Francois Paget. This was a very different session in a number of ways. First, of all it was completely unrelated to product or technology–there really are no Anti-Hacktivism or Anti-Cyberterrorism plug-ins. OK, cybercrime takes many threat Read more…
Tags: critical infrastructure, Cybercrime, Data Protection, global threat intelligence, government, malware, Operation Aurora, Public Sector, Risk and Compliance, vulnerability
Looking at computer threats from quarter to quarter remains a busy experience for us at McAfee Labs. Through the first three quarters of the year we have analyzed and cataloged more threats than in all other years combined, and the growth in both volume and sophistication of malware and attacks shows no signs of slowing. Read more…
Tags: botnet, critical infrastructure, Cybercrime, data breach, Data Protection, Email & Web Security, encryption, Endpoint Protection, facebook, global threat intelligence, Hacktivism, malware, Mobile, Operation Aurora, phishing, privacy, seo abuse, social networking, social networks, spam, sql attacks, Stuxnet, twitter, vulnerability, Web 2.0, zeus
Posts tagged under vulnerability