In association with heise online

Top News

Microsoft anti-virus software dawdles over updates

Windows flag Tests by heise Security have show that in some situations Microsoft Security Essentials fails to download updates for a whole week, despite new anti-virus signatures being available to download from Microsoft's servers more…

Top Feature

Testing email with encryption

SSL plumbing It can be very useful to be able to talk directly with your SMTP or IMAP server for diagnostic purposes. Things get a bit more complicated when encryption rears its ugly head, but with the right tools, it doesn't have to be a black art more…

IT security news and features

News & Features

23 October 2009
Typo3 update closes numerous critical holes

The problems include cross-site scripting vulnerabilities, SQL injection holes and the possibility to submit and run commands on the system shell more…

23 October 2009
US report: China is expanding its corporate cyber espionage

China is reportedly expanding its cyber espionage in increasingly targeted and successful ways more…

22 October 2009
RSA and Trend Micro to co-operate

RSA logo RSA's FraudAction service is to be linked with Trend Micro's "Smart Protection Network" infrastructure to obtain information about current threats more…

22 October 2009
Mozilla confirms Firefox updates and beta delayed

Firefox logo Mozilla has confirmed that Firefox 3.0.15, 3.5.4 and the first beta for Firefox 3.6 have all been delayed. The fifth beta of Mozilla's Fennec mobile web browser has a release date and the final version of SeaMonkey 2.0 is on schedule more…

22 October 2009
Rapid7 acquires the Metasploit project

Metasploit, a major exploits site and exploit framework project, has been acquired by commercial security company Rapid7 more…

22 October 2009
TrueCrypt 6.3 released

TrueCrypt key logo Version 6.3 of TrueCrypt adds full support for Windows 7 and Mac OS X 10.6 Snow Leopard more…

21 October 2009
Researchers read the cryptographic keys of mobile phones

H generic mobile icon By analysing the fluctuations in re-radiated signals from mobile phones caused during cryptographic operations, researchers have been able to crack mobile phone keys more…

21 October 2009
WordPress 2.8.5 offers improved security

WordPress logo The 'hardening release' contains a number of functions back ported from version 2.9 beta which should make the blogging system more resistant to attack more…

21 October 2009
Security specialist Finjan to offer cloud products

Finjan logo Finjan's Vital Cloud and Vital Cloud Hybrid are to provide businesses with secure cloud computing facilities more…

21 October 2009
VMware patches vulnerabilities in its products

VMware logo The VMware security announcement lists a total of 48 CVE entries. Updates are already available for some of its products more…

20 October 2009
AVG Free 9.0 released

AVG logo As previously announced, AVG Technologies has made the free AVG Free 9.0 for home users available to download. However, the free version lacks several features that are present in the commercial products more…

19 October 2009
Vulnerabilities in several PDF applications

Security holes in numerous PDF applications allow attackers to infect systems with malware. Affected applications include Xpdf and the Foxit plug-in for Mozilla's Firefox web browser more…

19 October 2009
Oracle to patch 38 vulnerabilities

Oracle logo Oracle has confirmed that on Tuesday, it plans to release updates for 21 of its products to address 38 security vulnerabilities on Tuesday, some of which scored a 10, the highest possible, in the Common Vulnerability Scoring System more…

19 October 2009
Tool to fool TrueCrypt published

TrueCrypt logo Security expert Joanna Rutkowska has developed a tool that attackers can use to get access to hard drives encrypted with TrueCrypt more…

19 October 2009
Firefox blocks, then unblocks, Microsoft add-on

Firefox 3.5 started to block a Microsoft plug-in that can be used to exploit a security hole in .NET Framework 3.51. But now Mozilla is unblocking it after confusion over the vulnerability more…

17 October 2009
Microsoft has known of the SMB2 hole for some time

A company blog post reveals that Microsoft was aware of the SMB2 security hole long before it was publicised by an independent security expert more…

17 October 2009
Trojans on Facebook

A number of Facebook apps specifically target security holes in Adobe Reader to inject scareware on users' systems. It seems that the application providers themselves have become the victims of attacks more…

16 October 2009
New versions of phpMyAdmin close security holes

The previous versions of the MySQL administration system were potentially vulnerable to cross-site scripting attacks and the injection of arbitrary SQL commands more…

15 October 2009
Report: German Federal Criminal Police Office has not yet conducted any online searches

Although the Wiesbaden-based police authority has never used the option of using secret online searches, which has been available in Germany since the 1st of January 2009, the authority continues to consider online searches an indispensable tool for police investigations more…

15 October 2009
Security vulnerabilities fixed in multiple CA products

Unpatched, 13 CA products allow malicious code injection on unpacking RAR archives more…

15 October 2009
Microsoft restores Sidekick customer data

A little under two weeks after a server failure at the company's Danger subsidiary, Microsoft has reported that it has been able to restore "most, if not all," of the lost data more…

14 October 2009
Adobe closes 29 vulnerabilities in Acrobat and Reader

Adobe has released updates for its Acrobat and Reader products, closing 29 security vulnerabilities, including a previously reported critical hole that is already being exploited by attackers more…

14 October 2009
Google highlights malicious code

Google is to assist web page operators with cleaning up and optimising their web presence by providing views of web pages as they appear to the Google bot, including information about malicious code more…

14 October 2009
Microsoft Patch Tuesday - 34 security vulnerabilities addressed

The company has released 13 update packages which fix a total of 34 security vulnerabilities - there really is something for everyone. Patch day also for the first time includes patches for the forthcoming Windows 7 more…

13 October 2009
TeleTrusT awards prize for manual digital signature

TeleTrusT The association of German IT security firms has awarded its annual innovation prize to a Spanish banking group. The group intends to save paper by using biometric digital signatures more…

Got news? Let us know!




The H open source

The H Security

The H Internet Toolkit