
<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0">
<channel>
<title>electronista | vulnerability News</title>
<link>http://www.electronista.com/</link>
<description>electronista is the leading source for electronic news. It offers news, reviews, discussion, tips, troubleshooting, links, and reviews every day. The best place for gadgets News. Period.</description>
<language>en-us</language>
<image>
<title>vulnerability, Latest News, Headlines, Stories;</title>
<url>http://photos.macnn.com/logo-electronista.jpg</url>
<link>http://www.electronista.com/</link>
</image>
<item>
<title>Adobe issues 'emergency' Flash update to stop new malware</title>
<link>http://www.electronista.com/articles/13/02/07/exploits.affect.both.platforms.one.targets.the.mac.specifically/</link>
<description>&#60;img align='left' src='http://photos.macnn.com/news/1302/Adobe-Flash-YesAGAIN-sm.jpg' border='0' width='176' height='120' /><![CDATA[Adobe has issued a patch to update Flash on both the Mac and Windows platform in order to fix two new vulnerabilities already being exploited "in the wild" to spread malware. One of the targeted attacks using the exploit works equally well against Mac users as it does against Windows users. Visitors are tricked into downloading and opening MS Word files that contain malicious Flash content, whil...]]></description>
<guid>http://www.electronista.com/articles/13/02/07/exploits.affect.both.platforms.one.targets.the.mac.specifically/</guid>
<pubDate>Fri, 08 Feb 2013 03:00:00 GMT</pubDate>
</item>
<item>
<title>[U] Yahoo Mail accounts compromised in quick XSS exploit</title>
<link>http://www.electronista.com/articles/13/01/07/hacker.details.attack.process.in.youtube.video/</link>
<description>&#60;img align='left' src='http://photos.macnn.com/article_images/article_thumbnail/1357583801_yahoomailhack2013.jpg' border='0' width='176' height='120' /><![CDATA[[Updated with Yahoo response] Yahoo Mail accounts have been hacked, with a DOM-based cross-site scripting vulnerability being the main vector of attack. Details of the hack, including how to perform the attack on specific e-mail accounts, has appeared online in a YouTube video demonstration, with the entire attacking process taking just a couple of minutes....]]></description>
<guid>http://www.electronista.com/articles/13/01/07/hacker.details.attack.process.in.youtube.video/</guid>
<pubDate>Mon, 07 Jan 2013 18:34:00 GMT</pubDate>
</item>
<item>
<title>Commonly used Broadcom Wi-Fi chipset vulnerable to attack</title>
<link>http://www.electronista.com/articles/12/10/26/proof.of.concept.code.knocks.affected.devices.offline/</link>
<description>&#60;img align='left' src='http://photos.macnn.com/article_images/article_thumbnail/1351301939_ipadiphone-sm.jpg' border='0' width='176' height='120' /><![CDATA[Proof-of-concept example code shows a vulnerability in the firmware of two wireless chips sold by Broadcom -- the BCM4325 and the BCM4329. The chips are found in recent devices such as the iPhone 4, iPad, iPad 2, HTC Droid Incredible 2, Motorola Droid X2, and some Edge model cards manufactured by Ford. The flaw makes the devices vulnerable to attacks that render the Wi-Fi connection unusable for t...]]></description>
<guid>http://www.electronista.com/articles/12/10/26/proof.of.concept.code.knocks.affected.devices.offline/</guid>
<pubDate>Sat, 27 Oct 2012 01:40:00 GMT</pubDate>
</item>
<item>
<title>Security flaw found in iOS, allows spoofing of SMS messages</title>
<link>http://www.electronista.com/articles/12/08/17/could.allow.messages.to.silently.re.direct.to.phishing.sites/</link>
<description>&#60;img align='left' src='http://photos.macnn.com/news/1208/Apple-iOS-security-SMS.jpg' border='0' width='176' height='120' /><![CDATA[Security researcher Pod2g has discovered a flaw in the way iOS handles SMS messages that could conceivably allow for malicious texters to disguise messages as being from a known or trusted source, potentially getting users to reveal information they normally would not, or rack up inadvertent charges on their bill. Pod2g refers to the flaw as "severe" and plans on releasing a tool to allow iPhone 4...]]></description>
<guid>http://www.electronista.com/articles/12/08/17/could.allow.messages.to.silently.re.direct.to.phishing.sites/</guid>
<pubDate>Fri, 17 Aug 2012 14:59:00 GMT</pubDate>
</item>
<item>
<title>Google increases vulnerability reporting reward to $20,000</title>
<link>http://www.electronista.com/articles/12/04/23/google.raises.vulnerability.reward.program.prizes/</link>
<description>&#60;img align='left' src='http://cdn4.macnn.com/news/1108/googlein.jpg' border='0' width='176' height='120' /><![CDATA[Google has updated the bounties for its Vulnerability Reward Program. Users who report a bug from one of Google's products stand to earn up to $20,000 for each potential vulnerability declared to the search giant....]]></description>
<guid>http://www.electronista.com/articles/12/04/23/google.raises.vulnerability.reward.program.prizes/</guid>
<pubDate>Mon, 23 Apr 2012 22:25:00 GMT</pubDate>
</item>
<item>
<title>Google Wallet vulnerability exposes PIN on rooted handsets</title>
<link>http://www.electronista.com/articles/12/02/08/google.working.quickly.to.fix.bug/</link>
<description>&#60;img align='left' src='http://cdn4.macnn.com/news/1201/samsunggalaxynexus-googlewallet2.jpg' border='0' width='176' height='120' /><![CDATA[Researchers at security firm Zvelo have released details surrounding a Google Wallet vulnerability that is claimed to leave a user's PIN data exposed. Engineers were reportedly able to develop a crack that quickly determines a user's four-digit PIN, which serves as an essential security layer to prevent the NFC system from transmitting card data without authorization....]]></description>
<guid>http://www.electronista.com/articles/12/02/08/google.working.quickly.to.fix.bug/</guid>
<pubDate>Thu, 09 Feb 2012 03:25:00 GMT</pubDate>
</item>
<item>
<title>Researchers discover Wi-Fi router PIN vulnerability</title>
<link>http://www.electronista.com/articles/11/12/28/flaw.makes.for.easier.brute.force.attacks/</link>
<description>&#60;img align='left' src='http://photos.macnn.com/news/1112/wifi.jpg' border='0' width='176' height='120' /><![CDATA[The US Computer Emergency Readiness Team (US-CERT) has reportedly issued a warning regarding a vulnerability in Wi-Fi routers that use Wi-Fi Protected Setup (WPS) PINs. The security flaw, which was said to be discovered by security researcher Stefan Viehbock, enables hackers to easily gain access to routers by using brute-force attacks and software tools to guess the PIN codes....]]></description>
<guid>http://www.electronista.com/articles/11/12/28/flaw.makes.for.easier.brute.force.attacks/</guid>
<pubDate>Wed, 28 Dec 2011 05:00:00 GMT</pubDate>
</item>
<item>
<title>Vulnerability in Window 7 64-bit may be exploited by Safari</title>
<link>http://www.electronista.com/articles/11/12/20/gives.attacker.ability.to.run.arbitrary.code/</link>
<description>&#60;img align='left' src='http://photos.macnn.com/news/1112/Windows7-64-Safari-sm.jpg' border='0' width='176' height='120' /><![CDATA[Microsoft is said to be looking into a new vulnerability in the 64-bit version of Windows 7 that can be exploited through Apple's Safari web browser for Windows, according to a report on Threat Post. The flaw, reported a few days ago by an independent researcher on Twitter and confirmed by Secunia, would allow an attacker to run arbitrary code on victimized machines....]]></description>
<guid>http://www.electronista.com/articles/11/12/20/gives.attacker.ability.to.run.arbitrary.code/</guid>
<pubDate>Wed, 21 Dec 2011 01:30:00 GMT</pubDate>
</item>
<item>
<title>HTC confirms fix underway for privacy hole in Android phones</title>
<link>http://www.electronista.com/articles/11/10/04/htc.to.plug.major.security.hole.asap/</link>
<description>&#60;img align='left' src='http://photos.macnn.com/news/1109/htc-logexploit.jpg' border='0' width='176' height='120' /><![CDATA[HTC has confirmed that it has commenced work on a patch for the gaping security hole that was discovered in its Android phones over the weekend. HTC has has also acknowledged that the vulnerability could allow a maliciously crafted third-party application to access a customerís data without permission. The company claims that it is working quickly to issue a security update for its Android devices...]]></description>
<guid>http://www.electronista.com/articles/11/10/04/htc.to.plug.major.security.hole.asap/</guid>
<pubDate>Tue, 04 Oct 2011 11:25:00 GMT</pubDate>
</item>
<item>
<title>Serious XSS vulnerability found in Skype for iOS</title>
<link>http://www.electronista.com/articles/11/09/20/users.address.books.could.be.copied/</link>
<description>&#60;img align='left' src='http://photos.macnn.com/news/1109/SuperEvr-Skype-hack-sm.jpg' border='0' width='176' height='120' /><![CDATA[A security researcher going by "Phil P" and running the Superevr security blog has found a serious scripting vulnerability in the chat messaging feature of Skype versions 3.01 and earlier for the iPhone and iPod Touch that could execute malicious Javascript code without the user being fully aware, giving the attacker access to file contents of any file that the Skype app would have access to -- su...]]></description>
<guid>http://www.electronista.com/articles/11/09/20/users.address.books.could.be.copied/</guid>
<pubDate>Tue, 20 Sep 2011 23:25:00 GMT</pubDate>
</item>
</channel>
</rss>
