All the latest UK technology news, reviews and analysis

A week in security: Feds investigate iPad breach

by Phil Muncaster

12 Jun 2010

Be the first to comment

  • Tweet this
FBI
The FBI is investigating the recent iPad security breach

The week has been dominated by a batch of security fixes from Microsoft, Google and Adobe covering several key products, as well as growing concerns over the security of the much hyped iPad.

Vulnerability research firm Goatse Security claimed to have found a security flaw in AT&T's protocols that exposed the personal data of more than 114,000 iPad buyers, according to reports earlier this week.

The company ran an open script on AT&T's web site which passed on the email addresses of owners based on the ID number of their 3G iPad. The situation then appeared to escalate, and the FBI confirmed that it is investigating the breach.

Microsoft kicked off the week with a mammoth Patch Tuesday, issuing 10 bulletins patching 34 vulnerabilities in Windows, Office and Internet Explorer. Three of the bulletins are rated 'critical', Microsoft's top security risk level.

The critical fixes address remote code execution flaws in a media decompression component in all currently supported versions of Windows. All client versions of Windows will also receive a critical update for flaws in Internet Explorer.

However, one flaw that wasn't patched came to light only this week after Google security engineer Tavis Ormandy identified a zero-day flaw affecting Windows XP, 2003 and possibly other Windows systems.

Ormandy found the flaw in a component of the Windows Help and Support Center which is accessed via the 'hcp://' protocol handler. A correct exploitation could give an attacker complete access to any PC running the vulnerable operating system.

Google itself issued security updates for Chrome, addressing 11 vulnerabilities for the Windows, Mac OS X and Linux versions of the browser. Eight of the flaws in the Chrome 5.0.375.70 update are labelled as 'high risk', while the remaining three are listed as 'medium' risk. The vulnerabilities range from memory corruption and cross site scripting flaws, to keystroke redirection risks.

Adobe, meanwhile, released patches for serious security flaws in Flash. The 10.1.53.64 update fixes 32 issues that could allow remote code execution, system crashes or the loss of virtualised images.

And finally, Symantec Hosted Services rounded the week off with another warning about targeted malware attacks using the World Cup as a lure. The newly discovered attack, targeting Brazilian firms, features a malicious PDF attachment and link in the same email, increasing the chances of success.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

26%

1%

12%

61%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

X2 PMO lead, Investment Banking, London up to £495 per day

X2 PMO lead, Investment Banking, London up to £495 per...

SEO analyst - Retail ecommerce - Hertfordshire. £35-55k

SEO analyst - Retail E-commerce - c35-55k - Hertfordshire...

ICT Technician

ICT Technician Leicester £10,000 per annum...

Oracle Performance Tuning, Oracle, Engineering

Oracle Performance Tuning, Oracle, Tuning, Engineering...

To send to more than one email address, simply separate each address with a comma.