In association with heise online

    Top News

    PHP 5.5.0 adds optimizer and drops Windows XP support

    PHP icon Among other new features, the new version of the open source scripting language brings performance optimisations thanks to the opcode cache and code optimiser Zend Optimizer+ and introduces an easy-to-use secure password API more »

    Top Feature

    Content Security Policy halts XSS in its tracks

    Content Security Policy halts XSS in its tracks Cross-site scripting (XSS) is one of the biggest problems faced by webmasters. The new Content Security Policy standard should finally provide some relief more »

    Top Open News

    Xiph unveils "next-next-generation" video codec

    Xiph logo The Xiph.Org Foundation has taken the wraps of a new video codec, code-named Daala, which it says is a significant departure from how current next generation codecs such as VP9 and HEVC work more »

    Top Open Feature

    The trouble with "Business Source"

    Business Source? The problem of creating funding in a new software business is a major one, and doubly so for open source based companies. Michael Widenius recently described his solution to the problem, "Business Source", claiming it delivers "most of the benefits of open source". The H took a look to see how that held up more »

    Top Security News

    DNS provider's error caused LinkedIn "hack" and affected 5,000 more

    LinkedIn logo In all, around 5,000 sites, including LinkedIn, were affected by a configuration error at DNS provider Network Solutions; this sent traffic to an IP range run by a network services company more »

    Top Security Feature

    Content Security Policy halts XSS in its tracks

    Content Security Policy halts XSS in its tracks Cross-site scripting (XSS) is one of the biggest problems faced by webmasters. The new Content Security Policy standard should finally provide some relief more »

    Top Developer News

    Developer Break: Lucene, Solr, Spring Roo, Node.js, PyQt 5 and more

    Developer Break In this edition: Updates for Lucene, Solr, Spring Roo and Node.js, Lua in a browser, Python and Qt 5.0, code recommendations, ARM CUDA, Codegeist winners, Google interviews and NHibernate's future more »

    Top Developer Feature

    Java EE 7 at a glance

    Java EE 7 The next step for Java EE 6 was planned to be cloud support but the collapse of ambitious developer plans has meant Java EE 7 arrived with few fundamentally new aspects, representing more a consistent effort to round off existing features more »

    Security news and features

    News & Features

    Friday, 21 Jun 2013

    Google must delete last of UK Street View data

    Google logo While ICO only threatens increased focus on Google's operations, it serves an enforcement order on the company to destroy hard disks of sniffed Wi-Fi data it still retains more »

    CMSs mostly vulnerable through addons says German security agency

    Magnifying glass icon Germany's Federal Office for Information Security (BSI) has conducted a study to analyse how secure some of the most popular content management systems are. Add-ons, they say, can contribute as much as 95 per cent of the problems more »

    Thursday, 20 Jun 2013

    Mozilla checks in with Cookie Clearinghouse for better cookie handling

    Cookie Clearinghouse logo A new user privacy initiative from Stanford Law School called Cookie Clearinghouse will maintain block and allow lists of cookie creators. Mozilla has put its cookie patch on hold while it works with the group more »

    US and Russia install red telephone for cyber-threats

    Telephone icon Russia and the US plan to improve communication in the fight against cyber-threats in order to minimise the risk of a bilateral crisis. Lines of direct communication between Moscow and Washington are being expanded more »

    Microsoft kicks off its own bug bounty programme

    Microsoft icon Microsoft has announced that it is launching a bug bounty programme for upcoming versions of Windows and Internet Explorer. Researchers will be able to earn up to $150,000 for vulnerabilities reported to the company more »

    Wednesday, 19 Jun 2013

    German company will continue to update Ruby on Rails 2.3

    Rails logo Makandra plans to continue providing security updates for the old 2.3.x branch once Ruby on Rails 4.0 is released and official support is ended more »

    NetTraveler using PRISM phishing lures

    Spear Phishing A recently discovered email indicates that the spear phishing campaign from the group behind NetTraveler is still operating, despite being exposed by Kaspersky more »

    Security issue in iOS Personal Hotspot

    iPhone icon iOS's choice of password for mobile tethering is not genuinely random. Passwords for mobile hotspots can be cracked in just a few seconds more »

    Alert!Oracle releases fixes for 40 Java holes

    Oracle Java logo Oracle's latest critical patch update addresses 37 vulnerabilities in all versions of Java that can be exploited without authentication over a network. Free updates are only available for Java 7 users more »

    EMET 4.0 catches SSL spies

    Windows icon As well as offering better protection from cyber-attacks, version 4.0 of EMET, Microsoft's mitigation tool, has been made much more user friendly. The recommended protection settings can now be set up with just a few mouse clicks more »

    Tuesday, 18 Jun 2013

    Spycam vulnerability reappears in Google Chrome's Flash

    Adobe Flash logo It's possible to trick users into activating their webcams through clickjacking trickery and transparent Flash apps in the page. The problem was allegedly fixed in 2011 but is back again in the latest Chrome browser more »

    37 critical Java holes to be fixed today

    Java icon Java users should be prepared to update their installations later today as Oracle's latest Java update will fix 40 security vulnerabilities, 37 of which can be exploited over the network more »

    Monday, 17 Jun 2013

    Alert!Critical vulnerability in BlackBerry 10 OS

    BlackBerry logo If attackers can get the user to install a malicious app and convince the user to reset their password using BlackBerry Protect, it is possible to take complete control of a BlackBerry Z10 more »

    ICS-CERT issues warning about unsafe medical devices

    Medical Device Patient monitors, medical pumps, and analysis devices – like industry control systems, the equipment used in hospitals is increasingly connected to networks. Now, ICS-CERT says that some 300 devices from 40 manufacturers have backdoors more »

    Microsoft denies providing US government with vulnerabilities

    Microsoft icon Media reports have suggested that Microsoft has been supplying the US government with Windows security vulnerabilities for uses related to the PRISM programme. Microsoft has now released a statement denying all such allegations more »

    Multi-factor authentication for Microsoft cloud

    Password icon Initially as a preview only, Microsoft is offering Azure customers the facility, after entering their username and password, to authenticate via a smartphone app or over the phone. This option does not, however, come cheap more »

    Saturday, 15 Jun 2013

    The H Roundup - Classic Mode for RHEL 7, Business Source & BrickPi

    The H Roundup logo In the week ending 15 June – Business Source, GNOME Classic Mode in RHEL 7, users warned to remove the Debian Multimedia repository, Hetzner hacked, GlassFish 4.0, the BrickPi, and a sophisticated Android trojan more »

    Friday, 14 Jun 2013

    The end for Google's Chrome Frame

    Chrome Frame logo Google plans to retire its extension for older versions of Internet Explorer next January and recommends users switch to a modern version of IE or make the jump to Chrome in earnest more »

    Users warned to remove Debian Multimedia repository

    Debian logo The Debian project is warning users that the unofficial Debian Multimedia repository has to be considered unsafe as its domain has switched hands and is now under the control of an unknown party more »

    Thursday, 13 Jun 2013

    Snowden: US has been hacking Hong Kong and China for years

    Spying icon Over the past few months, the US government has generated increasing amounts of publicity around alleged hacker attacks from China. The Mandiant report on the ATP1 group appeared to provide plenty of evidence. However, the US aren't the only victims more »

    Google warns of increased Iranian phishing

    Phishing icon Google is warning Iranian internet users to be on the look out for phishing emails which attempt to compromise their Google accounts. It believes the emails are from the same group behind the DigiNotar compromise in 2011 more »

    OWASP top ten of web application security risks released

    OWASP logo The Open Web Application Security Project (OWASP) has published its latest top ten of web application security risks. Both cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks lost in importance in favour of other threats more »

    Wednesday, 12 Jun 2013

    Alert!HP's "System Management Homepage" web interface vulnerable

    HP logo The web management interface of ProLiant and Integrity servers contains a critical vulnerability more »

    Citadel takedown took down security researchers too

    Botnet icon In the process of taking down 1462 botnets last week, it appears that Microsoft failed to take down over a third of the domains it was targeting and that an estimated 25% of the domains were being run by security researchers more »

    CyanogenMod is working on privacy mode for apps

    CyanogenMod logo CyanogenMod founder Steve "Cyanogen" Kondik is working on privacy mode implementation for the open source third party firmware for Android devices. The per-app setting will allow users to not share their private data with apps more »

    Got news? Let us know!


    • June's Community Calendar






    The H Open

    The H Security

    The H Developer

    The H Internet Toolkit