In association with heise online

Top News

Firewalls as hacking aids

Firewall examination icon Researchers have succeeded in manipulating mobile data connections. They did so with the help of feedback from the network operator's firewall more »

Top Feature

Microsoft's struggle against bugs

Microsoft's struggle against bugs It has been ten years since Bill Gates famously emailed all Microsoft's employees declaring that data protection and system security should be the company's top priorities. Uli Ries describes the subsequent progress Microsoft has achieved in making its software more secure more »

IT security news and features

News & Features

28 May 2012
Critical hole in Seagate BlackArmor NAS

Open Padlock icon Seagate's BlackArmor NAS server is vulnerable to having its administrative password reset by anyone with access to it and a particular URL more »

28 May 2012
Text message provider to pay out for Android malware

Money icon Using fake applications, fraudsters have used premium rate text services to pick Android users' pockets. The UK-based company which provides the phone numbers used will now have to reimburse all losses and will face a fine more »

26 May 2012
The H Roundup for the week ending 26 May

The H Roundup icon In the last seven days: Linux 3.4 released, Chrome browser passed milestone, this year's Perl 5.16.0 arrived, and Linux Mint 13 "Maya" was published. Also, Glyn Moody looked at monopolies and open source, and The H spoke to Scala creator Martin Odersky more »

25 May 2012
Worth Reading: Passwords, guessed, replaced, still with us

Book icon Two papers from University of Cambridge security researchers provide insights into the guessing of passwords and what is needed to replace passwords in the future more »

25 May 2012
Botnet operator sentenced to four years in prison

Botnet icon The 27-year-old operator of the Bredolab botnet has been sentenced to four years in prison. At its peak, the botnet was estimated to have infected more than 30 million Windows PCs and was capable of infecting three million new PCs a month through infected emails more »

24 May 2012
Android Malware Genome Project launched

Android icon Security researchers from North Carolina State University announced the launch of a new initiative – the Android Malware Genome Project – to find, collect and analyse Android malware and share it with researchers around the world more »

24 May 2012
McAfee: malware increasing across all platforms

McAfee logo According to a new report from McAfee, malware has seen significant increases across all platforms in recent months, especially on mobile where threats targeting Android have increased by 1,200 per cent compared to the last quarter more »

24 May 2012
Yahoo released private certificate with new extension

Yahoo Axis icon Yahoo's launch of Axis, a new browser and extensions for desktop browsers, was marred when a blogger found that Yahoo had included its private certificate, used for signing the Chrome version of the extension, in the extension more »

24 May 2012
Google releases security update for Chrome 19

Google Chrome logo Google has patched several security holes in its Chrome browser. The update brings the browser's version up to 19.0.1084.52 and fixes two critical vulnerabilities, one of which was discovered by an external researcher more »

23 May 2012
Google warns DNSChanger victims

Google logo A visit to Google will warn users who have been infected with the DNSChanger malware. Those who do nothing about the warning will most likely not be able to access the internet from 9 July more »

23 May 2012
Billing company targeted in social engineering attack - Update

WHMCS logo Australian billing and services provider WHMCS was attacked using standard social engineering techniques by a group calling itself UGNazi. The attackers downloaded 1.7GB of data from the web server and deleted the company's web site more »

23 May 2012
Cross-browser worm uses commercial Javascript extension engine

Botnet network icon Browser extensions are the new hiding place for malware, and legitimate cross-browser extension toolkits are being leveraged to make cross-browser and cross-platform malware more »

23 May 2012
Wireshark updates close DoS security holes

Wireshark logo Versions 1.6.8 and 1.4.13 of the open source network protocol analyser address three security vulnerabilities that could be exploited by an attacker to cause a denial-of-service by injecting a malformed packet more »

23 May 2012
Worth Reading: The $50,000 breakout

Chrome breakout Google has detailed how participants managed to break out of Chrome's sandbox during the first Pwnium contest more »

23 May 2012
Hackers use fake Facebook cancellation emails to deploy malware

Facebook logo The link in the email will forward users to a third party application that prompts them to install a Java applet. The Java applet will then fake a Flash Player update warning and install malware on the user's machine more »

23 May 2012
Windows XP in update loop

Microsoft icon Three .NET security updates are putting Windows XP users' systems into an update loop more »

23 May 2012
SpyEye rips off users and films them in the process

Virus icon Kaspersky has discovered a SpyEye variant which films the user in front of the computer when he or she visits a German banking web site more »

22 May 2012
SecurID software tokens cloned

Padlock icon A security specialist has found a way to take tokens tied to certain computers and make them executable on other systems more »

22 May 2012
Nmap now fully ready for IPv6

Nmap logo Following nearly three years of development, NMap 6.0, the open source network scanner and mapper, has arrived with full IPv6 support, new scripts and a new Nping tool, an updated mapping GUI and many performance improvements more »

22 May 2012
Anonymous leaks US government crime statistics data

Anonymous icon A 1.7GB archive of a database and internal emails from the United States Bureau of Justice Statistics has been released as a torrent by the hacktivist group more »

21 May 2012
SIGINT: Few advances in GSM security

GSM icon Although weaknesses in GSM encryption have been well known for years now, only seven of the network operators included in GSMMap have made improvements. Also, few providers took action against services that locate users using text messages more »

21 May 2012
ZTE admits to backdoor in one of its Android devices

ZTE logo The Chinese handset maker included a program with a hard-coded password in its ZTE Score smartphone which gives root access. The backdoor was discovered after a user posted the credentials on Pastebin more »

19 May 2012
The H Roundup for the week ending 19 May

The H Roundup icon In the last seven days: a beta for PostgreSQL 9.2 arrived, Chrome 19 was declared stable, and Oracle changed its mind about damages in the Android case. Also, The H provided some tools and tips for the systemd Linux init system, and Andrew Back took a practical look at the Internet of Things more »

18 May 2012
Twitter refines tracking, adds Do Not Track support

Twitter logo Do Not Track is based on the idea that user changes to default browser settings related to privacy should have an effect on the way service providers online handle personal data more »

18 May 2012
Global Payments breach reportedly worse than expected

Padlock broken icon According to a report, the security breach at credit card processing company Global Payments extends back even further than was previously believed and may affect more than seven million accounts more »

Got news? Let us know!







The H open source

The H Security

The H Internet Toolkit