Showing only posts by Thomas Claburn. Show all posts.

NSA helps out Microsoft with critical Exchange Server vulnerability disclosures in an April shower of patches

Source

114 fixes for the Windows world – plus fixes from SAP, Adobe, FreeBSD, etc Patch Tuesday April showers bring hours of patches as Microsoft delivers its Patch Tuesday fun-fest consisting of over a hundred CVEs, including four Exchange Server vulnerabilities reported to the company by the US National Security Agency …

Intel accused of wiretapping because it uses analytics to track keystrokes, mouse movements on its website

Source

Session monitoring scripts prompt dozens of privacy lawsuits against Big Biz, mainly in California and Florida Intel is among the growing list of companies being sued for allegedly violating American wiretapping laws by running third-party code to track interactions, such as keystrokes, click events, and cursor movements, on its …

Microsoft's GitHub under fire after disappearing proof-of-concept exploit for critical Microsoft Exchange vuln

Source

Funny how code that targets Redmond vanishes while tons of others menacing other vendors remain On Wednesday, shortly after security researcher Nguyen Jang posted a proof-of-concept exploit on GitHub that abuses a Microsoft Exchange vulnerability revealed earlier this month, GitHub, which is owned by Microsoft, removed code, to the …

Google engineer urges web devs to step up and secure their code in this data-spilling Spectre-haunted world

Source

'This is going to be a lot of work... a reasonable set of mitigation primitives exists today, ready and waiting for use' After the disclosure of the 2018 Spectre family of vulnerabilities in modern microprocessor chips, hardware vendor and operating system makers scrambled to reduce the impact of data-leaking …

Google looks at bypass in Chromium's ASLR security defense, throws hands up, won't patch garbage issue

Source

Engineers write off GC abuse because Spectre broke everything anyway In early November, a developer contributing to Google's open-source Chromium project reported a problem with Oilpan, the garbage collector for the browser's Blink rendering engine: it can be used to break a memory defense known as address space layout …

« newer articles | page 17 | older articles »