Authors
Posts by Ryan Naraine
thumbnail Ryan Naraine

Ryan Naraine

Content Writer
Firefox Zero-Day Code Execution Hoax?

A public claim by hackers that Mozilla’s Firefox browser is vulnerable to multiple code execution vulnerabilities may be an overblown hoax. On the heels of a ToorCon presentation where two security researchers—Mischa Spiegelmock and Andrew Wbeelsoi—warned that Firefox’s implementation of JavaScript was badly flawed and could allow PC takeover attacks, Mozilla’s engineers say the risk […]

Oct 3, 2006
Inside the Third-Party Patching Conundrum

The emergence of a high-profile group of security professionals promising third-party software fixes during zero-day attacks has rekindled a debate on the merits—and risks—associated with deploying unsupported product updates. The Zero Day Emergency Response Team, or ZERT, stepped out of stealth mode on Sept. 22 with a stopgap patch for a VML (Vector Markup Language) […]

Sep 29, 2006
Microsoft Research Builds ‘BrowserShield’

Microsoft researchers are experimenting with an automatic code zapper for the company’s Internet Explorer Web browser. Researchers at the Redmond, Wash., company have completed work on a prototype framework called BrowserShield that promises to allow IE to intercept and remove, on the fly, malicious code hidden on Web pages, instead showing users safe equivalents of […]

Sep 4, 2006
MS06-040 Botnet Attack Reloaded

Botnet herders have reloaded and launched a new round of worm attacks against Windows users, exploiting multiple product flaws to hijack unpatched computers. In addition to the MS06-040 Windows Server Service flaw, attackers have added exploits for three other Windows worm holes as part of the latest wave of attacks, according to anti-virus experts tracking […]

Sep 1, 2006
Why Did Microsoft Delay IE Patch?

Microsoft has temporarily delayed the re-release of a critical Internet Explorer browser patch because of problems with the way its proprietary Systems Management Server handles cabinet (.cab) files, according to sources familiar with the matter. The Redmond, Wash., software giant markets SMS as a business tool for simplifying patch management, but because of a bug […]

Aug 23, 2006
Microsoft Dismisses PowerPoint Zero-Day Warning

Microsoft is pouring cold water on a warning from anti-virus vendor Trend Micro that a new PowerPoint zero-day attack is under way. The Trend Micro warning, first issued Aug. 19, said that a specially crafted “.ppt” file was being used to exploit an undocumented PowerPoint vulnerability. The Japanese anti-virus company said it received a sample […]

Aug 21, 2006
Did Microsoft Patch Miss the Mark?

An anonymous security researcher has posted a proof-of-concept exploit for a flaw patched in Microsoft’s “critical” MS06-035 bulletin, but the company’s security response team says the issue is actually a brand-new, unpatched vulnerability. The researcher, who uses the online moniker “cocoruder,” published the attack code on the Milw0rm Web site alongside a claim that it […]

Jul 31, 2006
Websense Taps Google API

Security researchers have a brand-new tool to use to go digging for malicious executables on the Web: the Google SOAP Search API. Malware hunters at Websense Security Labs have figured out a way to use the freely available Google API to find dangerous .exe files sitting on thousands of Web servers around the world. The […]

Jul 17, 2006
Microsoft Research Automates Hunt for Search Engine Spam

Researchers at Microsoft are working on an ambitious new project to hunt down and neutralize large-scale search engine spammers. The Redmond, Wash., software giant’s Cybersecurity and Systems Management Research Group has taken the wraps off Strider Search Defender, an experimental project that automates the discovery of search spammers through non-content analysis. The project integrates technology […]

Jul 13, 2006
Seven MS Office, Windows Patches to Cover Critical Flaws

Microsoft plans to release seven security bulletins on July 11 to cover a range of critical vulnerabilities affecting Windows and Office users. Four of the seven bulletins will include patches for flaws in the Windows operating system, while three will deal with bugs in the Microsoft Office productivity suite. eBay ends the bidding on a […]

Jul 6, 2006
Microsoft Finds (Random) Way to Secure Vista

A security feature used in the open-source world is now helping to harden Windows Vista against buffer overrun exploits. Microsoft has quietly fitted the feature, called ASLR (Address Space Layout Randomization) in Windows Vista Beta 2 as part of a larger plan to make it more difficult to automate attacks against the operating system. “Not […]

Jun 1, 2006
Microsoft: Use MS Word in Safe Mode

Use Microsoft Word in safe mode to protect against targeted zero-day attacks. That’s the advice from Microsoft’s security response team to counter known attacks against a serious code execution vulnerability in the widely used word processing program. In a pre-patch security advisory, Microsoft said the flaw can be exploited when a user opens a specially […]

May 23, 2006
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.