Windows 8 to get first 'critical' security update
Windows 8, available publicly for two weeks now, is getting its first security update Nov. 13. It includes three critical updates; Windows 8 RT, for Microsoft's Surface tablet, has one critical update.
“Internet Doomsday” for some, Get rid of DNSChanger Malware Now!
July 9, 2012, has been dubbed "Internet doomsday" and there is a chance you will not be able to access the Internet on your personal computer due to a malware called DNSChanger Trojan.
Microsoft XML Core Services Attack Activity - Microsoft Security Advisory (2719615)
Microsoft Security Advisory (2719615) warns of active attacks using
a vulnerability in Microsoft XML Core Services. Microsoft Internet
Revir Malware for OS X Undergoes Revision
Recently a new PDF-based malware threat for OS X was discovered that displays a Chinese PDF file while it installs and runs its malicious code in the background. While the initial version of this malware (OSX/Revir.A) was detected over a week ago, the criminals developing the code are busy revising and refining it, and over the weekend a variant has been identified (OSX/Revir.B). As with all malware, new versions of these threats are likely to surface in the future, and as they do, expect malware detection utilities (including Apple's XProtect) to follow close behind and label them alphabetically as they appear.
Apache Tomcat HTTP Server Directory Traversal
Apache Tomcat is the servlet container for JavaServlet and JavaServer Page Web applications.
A vulnerability in Apache Tomcat HTTP server may allow for directory traversal attacks. The vulnerability is cause by a misconfiguration of certain modules. An attacker could craft a special URL to view directories and files on the HTTP server without authorization.
Stuxnet was a directed attack with insider knowledge expert says
Stuxnet appeared on the scene earlier this summer, though it was written more than a year ago. The code, its mechanics, the way it moved from system to system using Zero-Day vulnerabilities in Windows, everything about it was both frightening and shady. The hype given to it was justified, if only because it was a targeted payload, aimed at critical infrastructure.