Disaster Recovery News

Opera patches usurped by new threat

Thursday, October 23, 2008

Web security experts exploited a new flaw in the Opera browser on the same day that the software developer released a patch to address three existing vulnerabilities.

Network security analysts at ZDNet noted that discussion of the zero-day flaw began on the Full Disclosure mailing list.

Within hours, researcher Aviv Raff had posted a proof-of-concept exploit which arbitrarily launched the calculator program on Windows machines when users clicked on a maliciously crafted link.

"I can confirm that a separate exploit exists that launches harmful code remotely against fully patched versions of the Opera browser," warned ZDNet's Ryan Naraine.

The website urged people to discontinue use of the browser until a new fix is made available or avoid clicking on links on untrusted websites.

Aviv Raff also hit the headlines last month after demonstrating proof of concepts that exposed data security vulnerabilities in the Google Chrome browser just hours after it was released.

One built upon the previously discovered Safari carpet-bombing flaw and the other exploited Java defects to trick people into launching executables.ADNFCR-1765-ID-18840693-ADNFCR

Related News:

ChoicePoint hit by $275K fine for 2008 data security breach - 10.21.2009
ChoicePoint, a large data broker subsidiary of Reed Elsevier, has been ordered to pay a $275,000 fine by the U.S. Federal Trade Commission, over a data breach in 2008 that exposed the private data of more than 13,000 customers.

TJX settles another class action over data breach - 9.4.2009
TJX Companies yesterday announced a settlement agreement that will result in the dismissal of a class action initiated by financial institutions as a result of the data breach of TJX's network security during 2005 and 2006 that exposed approximately 40 million credit card numbers.

Radisson data breach exposed credit card numbers - 8.20.2009
Between November 2008 and May 2009, hackers infiltrated the network security of computer systems at some Radisson hotels in the U.S. and Canada and accessed customer names and credit card numbers, the hotel chain disclosed Wednesday.

Feds indict TJX hacker for data theft in Heartland breach - 8.17.2009
Federal prosecutors on Monday indicted a Miami man in connection with the biggest credit card data breach on record - the theft of 130 million card numbers from Heartland Payment Systems - along with two other high-profile hacks.

Identity theft warnings issued to 13,000 after LexisNexis data breach - 7.16.2009
Two data breaches involving a subsidiary of LexisNexis have exposed the personal information of more than 13,000 consumers, leaving them vulnerable to identity theft and fraud.

View Related Resources
Or
Watch an Online Demo
Or
Have us call you now