-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

The Hacker News | #1 Trusted Source for Cybersecurity News — Index Page

Google patches 6 serious Chrome bugs

Google patches 6 serious Chrome bugs

Mar 25, 2011
Google on Thursday patched six vulnerabilities in Chrome, and as usual, silently updated users' copies of the browser. The update to Chrome 10.0.648.204 also included two more blacklisted SSL certificates that may be related to last week's theft of nine digital certificates from a Comodo reseller. All six bugs were rated "high," Google's second-most-serious ranking in its threat scoring system. Of the half-dozen bugs, two were "use after free" flaws -- a type of memory management bug that can be exploited to inject attack code -- while a second pair were pegged by Google as "stale pointer" vulnerabilities, another kind of memory allocation flaw. As is Google's practice, the company locked down its bug-tracking database, blocking access to the technical details of the patched vulnerabilities. Google usually unlocks the bug entries several weeks, sometimes months later, to give users time to update before the information goes public. G...
Nasa HaCkeD By The 077 & DinelSon Tunisian HaCker

Nasa HaCkeD By The 077 & DinelSon Tunisian HaCker

Mar 25, 2011
Nasa HaCkeD By The 077 & DinelSon Tunisian HaCker Hacked link by The 077 :  http://blogs.nasa.gov/cm/resource/1015442 Hacked link by DinelSon :  http://blogs.nasa.gov/cm/resource/1015440
Delhi university's and Pakistani.pk site is vuln to XSS !

Delhi university's and Pakistani.pk site is vuln to XSS !

Mar 25, 2011
Delhi University 's & Pakistani.pk  site is vuln to XSS ! angel (4d0r4b13) Found Xss cross site scripting vulnerability in Delhi University Website, as shown. vulnerable Link :  : http://du.ac.in/index. php?id=276&sitesearch=du.ac. in&client=pub- 017673838153185424638% 3Aoxnjzwaqtce&cof=FORID%3A10& ie=UTF-8&q=%22%3E%3Cscript% 3Ealert%28%22Vuln+found+by+ 4ng31+4k4+4d0r4b13..!+angelws+ here..!+enjoy....!+delhi+ university..!+hehe..!+%3D%29+% 3D%29+%3B%29+%22%29%3C% 2Fscript%3E and  http://pakistani.pk/?s=%22%3E%3Cscript%3Ealert%28%22angel%20w45%20here..!%20heheheh%20pakistani.pk%20vuln%20to%20xss%20yup%20it%20is//!%20greets:Indian%20r00ting%20w1z4rd5..!%20vuln%20found%20n%20executed%20by%20angel%204k4%204d0r4b13%22%29%3C/script%3E
cyber security

Military Appreciation Month: 10% Off SANS Cybersecurity Training

websiteSANS InstituteCybersecurity Training
Get 10% off SANS training this May—online or in person. Use code MILITARY10. U.S. only.
cyber security

The Validation Gap: What Automated Pentesting Alone Cannot See

websitePicus SecurityAutomated Pentesting / Exposure Validation
This free guide maps the structural blind spots and gives you 3 diagnostic questions for any vendor conversation.
Anonymous Open Letter to Citizens of United States of America !

Anonymous Open Letter to Citizens of United States of America !

Mar 24, 2011
Anonymous Open Letter to Citizens of United States of America ! Just Now another Open Letter by Anonymous hackers released on Twitter m as below : Dear US Citizens,                           We, Anonymous, would like to offer you, America, the opportunity to join and support our movement.We are a group that formed on the internet--one that knows no constructs or absolutes, and one that has recently grown exponentially. We would like to introduce an Operation. An Operation that involves Americans getting our Natural Rights and dreams back. Right now, you can help by passing on the Information. Information is Power. Share the Power of the Information with other like-minded individuals. The more people we represent, the more Power we have, both as individuals and as Anonymous. Thank you for your time and your Power.                    ...
Hackers hack into TripAdvisor's members Database !

Hackers hack into TripAdvisor's members Database !

Mar 24, 2011
Hackers hack into TripAdvisor 's members Database ! Travel site TripAdvisor has warned subscribers to expect more spam following the theft of its member database. The travel review and information website said that an unspecified vulnerability allowed miscreants to make off with a portion of its email database. TripAdvisor does not collect members' credit card or financial information, and no passwords were obtained as a result of the breach. TripAdvisor has promised to tighten up its security in the wake of the incident, which is under investigation internally. The US-based website, which serves an international client base, has also reported the matter to police. Subscribers were notified of the breach by email, a copy of which was passed onto El Reg.. The incident comes days after ne'er-do-wells got their hands on the Play.com email list, sending targets links to a supposed Adobe software update that actually served up malware. Play.com blamed the incident on it...
XSS vulnerable on dmoz.org !

XSS vulnerable on dmoz.org !

Mar 24, 2011
XSS vulnerable on dmoz.org ! http://www.dmoz.org/search?q=%3Cimg%20src=%22http://lh4.ggpht.com/_bCYQxIvMQ2U/TRG6cWyFNjI/AAAAAAAAAW8/ZEHFUPXBmLk/hackernews.jpg%22/%3E View the compromised page
Iran Hackers targets Gmail and Skype with fake SSL hack !

Iran Hackers targets Gmail and Skype with fake SSL hack !

Mar 24, 2011
Iran has tricked a web firm into issuing fake security certificates for Gmail, Skype, Hotmail and more. Comodo Group, a US-based certificate authority firm with 15% of the market, admitted that one of its affiliate's accounts in Southern Europe had been hacked, letting the attackers create fake SSL security certificates for six websites. Such digital keys let websites offer secure services, and fake versions could be used to spoof sites, gather login details and watch user activity. The fake certificates target Microsoft's Live platform, Gmail and Google, Skype, Yahoo, and Mozilla Firefox extensions. The attack was quickly discovered, with the attacker still using the account when it was shut down. Comodo's CEO Melih Abdulhayogl said the attack appeared to originate in Iran, as it would have required access to the country's DNS infrastructure. "We believe these are politically motivated, state-driven/funded attacks," he said in a blog post, adding it wa...
Expert Insights Articles Videos
Cybersecurity Resources