HP has released firmware updates for some of its LaserJet printer models that aims to mitigate a security vulnerability discovered in November. Researchers at Columbia University discovered that some HP LaserJet printers can be manipulated into accepting a modified firmware. The modified firmware can then be used to steal information, run network attacks or even [...]
- Author: Martin Brinkmann
- Comments: 3
Skype Update 5.5 With Critical Security Vulnerability
It does not happen often that software updates ship with critical security updates. But that’s exactly the case with the Skype 5.5 release for Windows. Skype 5.5 is the first version with Facebook integration. Skype users with a Facebook account can now use some of Facebook’s functionality right in the voice over IP software. This [...]
- Author: Martin Brinkmann
- Comments: 5
New Critical 0-day Flash Vulnerability Exploited Via Excel Attachments
Adobe today has released a new security advisory for Adobe Flash Player, Adobe Reader and Acrobat. All three applications are affected by a critical 0-day vulnerability that is exploited via Excel email attachments. Vulnerable versions are Adobe Flash Player 10.2.154.33 and earlier for all supported desktop operating systems, Adobe Flash Player 10.1.106.16 and earlier for [...]
- Author: Martin Brinkmann
- Comments: None
LastPass Fixes XSS Vulnerability, Improves Security
Ghacks regulars know that I’m a big supporter of the free cloud based password manager LastPass. The program is available for popular web browsers and mobile devices, and offers many comfortable password and login related features. This includes online password management, one-click log ins, user profiles to fill out forms faster, a secure password generator [...]
- Author: Martin Brinkmann
- Comments: 3
Microsoft Updates Latest Security Advisory, Adds Fix-It Solution
A new Windows security vulnerability was disclosed a few days ago. The Windows Shell Vulnerability allows attackers to execute code with specifically prepared .lnk or .pif files. The security issue can be exploited automatically, by connecting a removable storage device to a Windows computer. It is also possible to exploit the issue through WebDav or [...]
- Author: Martin Brinkmann
- Comments: 1
Opera 10.50 Security Vulnerability
A security vulnerability in Opera 10.50 and previous versions of the web browser was uncovered by security research company VUPEN Security. The issue is caused by a buffer overflow error when the user visits a website with malformed HTTP headers. The security vulnerability has been confirmed to be working on Opera 10.50 for Windows XP [...]
- Author: Martin Brinkmann
- Comments: 4
New Internet Explorer Vulnerability Confirmed
Microsoft have confirmed a new Internet Explorer security vulnerability which is affecting only pre-Windows Vista operating systems like Windows XP meaning that users running Windows 7, Windows Vista, Windows Server 2000 and Server 2008 R2 are not affected by the issue. The vulnerability is not exploited currently according to Microsoft’s information and it is not [...]
- Author: Martin Brinkmann
- Comments: 4
Adobe Fixes Adobe Download Manager Vulnerability
A security vulnerability in Adobe Download Manager was discovered this month besides the recently discovered security vulnerabilities in Adobe Reader, Adobe Acrobat and Adobe Flash which had also been discovered and fixed by Adobe. We have posted information about the security vulnerability in the forum but not here on the blog. Adobe has now updated [...]
- Author: Martin Brinkmann
- Comments: 12
Adobe Fixes Critical Shockwave Vulnerability
Adobe has issues a security patch for the Adobe Shockwave software program that fixes one vulnerability that has been rated critical by Adobe Software. The vulnerability gives attackers, who can attack systems remotely, control over affected computer systems. The interesting aspect of the issued patch is that Adobe recommends to completely uninstall Adobe Shockwave 11.5.0.596 [...]
