Feeds

Hackers look outside Windows for flaws

SANS Top 20 highlights backup risks

  • alert
  • submit to reddit

Security for virtualized datacentres

Security vulnerabilities are on the rise with a 10.8 percent increase in vulnerabilities over last quarter, according to a study from the SANS Institute. There were 422 new vulnerabilities in the second quarter of 2005, compared to the 381 reported in Q1 2005.

SANS highlights a growing number of vulnerabilities in popular back-up products from Symantec/Veritas and Computer Associates as an unwelcome trend. Meanwhile consumers face risk from new vulnerabilities in iTunes and RealPlayer, along with a seemingly endless stream of browser vulnerabilities. The full SANS report (featuring a list of the top 20 newly discovered security vulnerabilities) can be found here.

"We are seeing a trend to exploit not only the Windows, but other vendor programs that are installed on potentially large number of systems," says Rohit Dhamankar, a research manager in 3Com's TippingPoint security appliance division. "These include backup software, management software, licensing software etc. Flaws in these programs put critical resources at risk as well as having a potential to compromise the entire enterprise."

Security firm Qualys has released a free network scanning service (here) to help companies find and eliminate vulnerabilities listed in the SANS Top 20 update. ®

Related stories

SANS revises Top 20 security vulns list
Red Hat holes less severe than Windows - study
Three critical fixes in MS July security update
3Com puts a bounty on vulns
Browser bugs sprout eternal

Secure remote control for conventional and virtual desktops

More from The Register

next story
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.