Already burned by the discovery of serious security vulnerabilities in its SDK, the Android Security Team emerged from the shadows this week with an appeal to the...
security team
-
Android security team appeals to hackers
details »
-
Alexander Muse: Careerbuilder, wonderfully exasperating!
details »
Yesterday our operations manager suggested I post three openings we had on Careerbuilder. Instead of turning over the task to our in house recruiter I decided to post...
-
Flying to Defcon with no ID
details »
8Before Sherri Davidoff flew out to Defcon this year, she made sure to cover up the "Global Hacking Permit 230291" sticker on her laptop with a photo of two...
-
Writing a UAC compliant Application
details »
I've seen a lot of developers clueless when it comes to UAC in Vista. The whole point to UAC is give your application the minimum amount of privileges required for it...
-
Congrats to the Sun Systemic Security Team!!
details »
You know how much we like to brag, therefore it is our pleasure to inform you that four engineers from our very own Global Systems Engineering organization at Sun...
-
Wordpress blog hack rampage
details »
I received an abnormal high number of signals and messages from people abandoning their Wordpress blogs, because of their hacks, just like... [[ This is a content...
-
Blogging Is Not A Crime
details »
I found this arresting chart on Swivel. It plots the number of bloggers who have been incarcerated over the past few years, based on data collected by the World...
-
CLR Security Team CodePlex Site
details »
The CLR Security Team just launched our CodePlex site: http://www.codeplex.com/clrsecurity. Currently, it contains two assemblies that provide additional...
-
Security Idiocy Story
details »
From the Dilbert blog: They then said that I could not fill it out - my manager had to. I told them that my manager doesn't work in the building, nor does anyone in my...
-
Google releases open-source crypto toolkit
details »
Google's security team has released an open-source cryptographic toolkit aimed at making it easier and safer for developers to use cryptography in their applications. The...
-
Easy Encryption In Java and Python With Keyczar
details »
rsk writes "Keyczar is an encryption toolkit born out of the Google Security Team and released under the Apache 2 license. Keyczar's purpose is to make managing...
-
CSRF vulnerability allows Twitter 'follow' abuse
details »
Last week, TechCrunch's Jason Kincaid wrote about an obvious Twitter vulnerability that allowed a user called "johng77536" to game the popular micro-blogging service to...
-
Securing OpenID@Work - Again
details »
Last year we announced an experiment at Sun: in order to gather more information about the operational characteristics of "user-centric" identity technologies, we...
-
Security Email Addresses that are Black Holes
details »
Drupal: I reported a (minor) CSRF hole in April, but never got a response. It was fixed in Drupal 5.8 earlier this month, credited to Heine of the Drupal security team....
-
Unbreakable Unbrella
details »
http://www.youtube.com/watch?v=bO8G5zsQohg according to Wired: The entourage of the Philippine president, Gloria Macapagal-Arroyo, has an unusual secret weapon. Her...
-
Hello World!
details »
Hello and welcome! This is the first posting of the Global System Engineering (GSE) Security Team's Adaptive Security weblog. This blog is intended to capture...
-
New and Notable 254
details »
Service Security/Identity Management/SOA I am super thrilled to see Microsoft roll out "Zermatt", a .NET developer framework and SDK to help build...
-
Twitter being used to distribute malware
details »
Last week, when I wrote about Aviv Raff's auto follow-me vulnerability on Twitter, I warned that it was only a matter of time before we see nasty social engineering...
-
Arbitrary code execution vulnerabilities
details »
Multiple vulnerabilities in Ruby may lead to a denial of service (DoS) condition or allow execution of arbitrary code. ImpactWith the following vulnerabilities, an...
-
Apple Pulls Out Of Hacker Conference (AAPL) [Silicon Alley Insider]
details »
Apple (AAPL) employees are so tight-lipped that they won't tell you the time of day without permission from Steve Jobs. So how come Apple's security team is going to...