[pchelpers] News:Hackers milk massive increase in browser plug-in bugs

Plug-in vulnerabilities triple in first half of '07, Symantec says
Gregg Keizer

September 17, 2007  (Computerworld) -- Hackers loosed a record number of
malicious code threats in the first six months of 2007, Symantec Corp.
said today, with the most dangerous targeting vulnerabilities in browser
plug-ins -- the weak link in Web 2.0. 

"Web 2.0 is barely coined [as a term], and we're seeing hundreds of
vulnerabilities aimed at it," said Alfred Huger, vice president of
engineering for Symantec's security response group. "There's been a
massive increase in the number of malicious threats, thanks to
automation. In six months, we saw an increase of 185% in the number of
samples of malicious code. And they weren't just variants, but entirely
new binaries."

According to Symantec's just-published Internet Security Threat Report,
the security vendor tagged 212,101 malware threats during the six-month
stretch from January to June 2007. Trojans made up the majority of the
top 50 threats.

But at the spear-point of the threat explosion, said Huger, were a rash
of exploits that leveraged vulnerabilities in browser plug-ins, the
typically single-purpose, third-party applications that work with a
browser to play music, display certain file types or make possible
software-as-a-service.

More here:
http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=security&articleId=9036978&taxonomyId=17&intsrc=kc_top
-- 
John Durham
Site http://modecideas.com
Server hosted on Ubuntu 4.10
Good advice is like good paint. It only works when applied.



-- 
-------list-services-below-----------
Regards, John Durham (list moderator) <http://modecideas.com/contact.html?sig>
Freelists login at http://www.freelists.org/cgi-bin/lsg2.cgi
List archives at http://www.freelists.org/archives/pchelpers
PC-HELPERS list subscribe/unsub at http://modecideas.com/discuss.htm?sig
Latest news live feeds at http://modecideas.com/indexhomenews.htm?sig
Good advice is like good paint- it only works if applied.

Other related posts: