Rather than wait for August's Patch Tuesday, Microsoft has rushed out a pair of security bulletins ahead of the Black Hat and Defcon security conferences.
A critical vulnerability has been discovered in Adobe Reader, Acrobat and Flash Player. The vulnerability is being actively exploited against Reader 9 on Windows.
Indian techie, Atul Dwivedi, defaced the Royal Australian Air Force website this week, posting a message on the front page as a warning to Prime Minister Kevin Rudd. How did he do it?
At least two of the security flaws addressed in the release version of Safari 4.0 can be used to attack Safari 3.x. Proofs of concept are in circulation.
The latest wave of updates from Apple include security fixes. The iTunes update also provides compatibility with iPhone 3.0, and there are also QuickTime and GarageBand updates.
Hacker groups have reported that man-in-the-middle attacks can be used to strip away the benefits of SSL security when transacting online. However, says the inventor of SSL, these are a browser problem and, moreso, they're not so black and white.
Yet another critical cross-site scripting vulnerability has been reported, this time impacting those using Sun's Java System Communications Express application.