ie8 fix

InSecurity Complex

Microsoft to plug critical IE hole targeted by exploit code

Microsoft said on Thursday that it will offer six updates for 12 vulnerabilities next week including a critical hole in Internet Explorer that affects Windows 7 and other current versions of the operating system for which exploit code has been released.

Late last month, Microsoft said it was investigating an IE vulnerability after someone released proof-of-concept code affecting IE 6 and IE 7 that could be used to take control of computers.

Microsoft described the problem in an advisory issued November 23: "The vulnerability exists as an invalid pointer reference of Internet Explorer. It is possible under certain conditions … Read more

Avast update falsely flags good apps as malware

Czech Republic-based Avast issued an update late on Wednesday to its antivirus software that mistakenly flagged hundreds of innocent files as a Trojan. It fixed the situation five and a half hours later.

Falsely labeled as malware were programs from Adobe, Realtek, sound card drivers, and various media players, among others, according to a blog post on the Avast Support Center.

The errant update had been issued around 12:15 a.m. GMT. A new update was issued at 5:50 a.m. GMT that corrected the problem. Customers who did not use their computers between that time will most … Read more

EFF sues feds for info on social-network surveillance

The Electronic Frontier Foundation sued the CIA, the U.S. Department of Defense, Department of Justice, and three other government agencies on Tuesday for allegedly refusing to release information about how they are using social networks in surveillance and investigations.

The nonprofit Internet rights watchdog group formally asked more than a dozen agencies or departments in early October to provide records about federal guidelines on the use of sites like Facebook, Twitter, and Flickr for investigative or data gathering purposes, according to the lawsuit.

The requests were prompted by published news reports about how authorities are using social networks to … Read more

Fake CDC vaccine e-mail leads to malware

Updated 5:10 p.m. PST with information about later versions of the e-mail campaign directing to a landing page with hidden code that uses an Adobe exploit to try to download malware onto the system.

You can ignore that e-mail that looks like it comes from the U.S. Centers for Disease Control and Prevention about creating a profile for an H1N1 vaccination program. It's a malware scam, according to security provider AppRiver.

The fake alert informs recipients that as part of a "State Vaccination H1N1 Program" they need to create a profile on the CDC … Read more

Building circuits, code, community at Noisebridge hacker space

SAN FRANCISCO--About 30 people listened intently on a recent Thursday night to short presentations on linear algebra and beer brewing, watched a demo of an iPhone cyberspace shooter game, and learned how to make a light staff (acrylic rod, LED, resistor, tape, no soldering required).

For the last talk, a speaker billed as "Dr. Baron Mikheil von Burstein, esq." explained how to pull off his interactive public art specialty--swings that hang in the aisles on the underground trains in the Bay Area Rapid Transit (BART) system.

"I installed it publicly, illegally and got away with it," … Read more

Microsoft warns of IE exploit code in the wild

Microsoft on Monday said it is investigating a possible vulnerability in Internet Explorer after exploit code that allegedly can be used to take control of computers, if they visit a Web site hosting the code, was posted to a security mailing list.

Microsoft confirmed that the exploit code affects IE 6 and IE 7, but not IE 8, and it said it is "currently unaware of any attacks trying to use the claimed vulnerability or of customer impact," according to a statement.

The exploit code was published to the BugTraq mailing list on Friday with no explanation.

"… Read more

Chrome OS security: 'Sandboxing' and auto updates

With most computers threatened by attacks coming through Web applications, it's no surprise that security would be a key piece of Chrome OS, Google's browser-based operating system that stores data in the cloud.

Google showed off its new lightweight operating system designed for Netbooks and cloud computing on Thursday. As anticipated, it will rely on many of the same security features and concepts used by the Chrome browser.

"The browser is the operating system. We've expanded the browser to add operating system functionality," Caesar Sengupta, a group product manager at Google, said in an interview. … Read more

Cisco launches iPhone security app

Cisco is offering a free iPhone app that will allow people to get customized alerts on new security threats and other information for safe Web browsing.

The app, which will be available on Friday in the Apple iTunes store, provides information about new malware signatures, bulletins for how to mitigate against threats, ways to see if particular Web sites are compromised, as well as links to podcasts and videos.

The Cisco SIO To Go iPhone app gets its information from the company's Security Intelligence Operations (SIO) system which gathers information in real time from 700,000 sensors located at … Read more

Fortified rice, fuel cells among Tech Award winners

SAN JOSE, Calif.--Projects that turn slaughterhouse waste into energy and fertilizer, and zinc oxide from fuel cells into fertilizer, as well as programs to fortify rice with nutrients, feed Indian children, and boost wages for artisans were honored Thursday night at the Tech Awards for technology benefiting humanity.

Established in 2001, the Tech Awards recognize 15 laureates in the categories of education, equality, environment, biosciences economic development, and health. One laureate in each category receives a $50,000 cash prize. The winners were announced at a ceremony at which Al Gore, former U.S. vice president and Nobel Peace … Read more

T-Mobile UK says workers sold customer data

Updated November 18 at 11:19 a.m. PST to clarify that the data was sold by workers at T-Mobile UK, which is operated separately from T-Mobile USA.

T-Mobile workers sold personal data on thousands of customers to third parties who then called the individuals as their wireless contracts were due to expire, a T-Mobile UK spokesman has confirmed.

T-Mobile notified England's Information Commission, the watchdog agency responsible for safeguarding consumer privacy, and said the activity was done "without our knowledge," according to the BBC.

Information Commissioner Christopher Graham told the news agency his office will prosecute … Read more

ie8 fix