APPLICATION SECURITY Articles
Secunia Sets Six-Month Deadline for Vulnerability Disclosures
Secunia gives vendors six months to fix reported vulnerabilities before going public
Clamor for cloud apps increases corporate data breach risk
Vendor analysis of network and application traffic shows poorly managed remote access tools and traffic flowing outside port 80 are rampant.
Oracle to Issue 78 Patches, Including 27 for MySQL
Other fixes are set for Oracle's database, middleware and applications
Facebook Chat-Based Phishing Attack Impersonates Facebook Security
Phishers modify hijacked Facebook accounts to impersonate the website's security team
Sykipot Trojan Hijacks Department of Defense Authentication Smart Cards
Sykipot variant acts as smart card proxy in order to access protected resources
Anonymous Publishes Israeli SCADA Log-in Details
Anonymous publishes a list of Israeli Internet-facing SCADA systems and log-in details
Attack Code Published for Serious ASP.NET DoS Vulnerability
Exploit code for a denial-of-service vulnerability in ASP.NET was published on GitHub
Passwords aren't dead, though maybe yours should be
Despite all those "death to passwords" chants, some say it's still a solid form of authentication -- when users aren't being stupid about theirs.
Two New Tools Exploit Router Security Setup Problem
The tools can be used to figure out the access code for many brands of wireless routers
More SCADA security flaws surface
Numerous new authentication issues saddle Siemens' industrial control applications.
