Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

4/10/2008
09:43 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Security Is No Longer About The Operating System

Now that Adobe has updated its graphics and video software, a near ubiquitous security vulnerability has been fixed.

Now that Adobe has updated its graphics and video software, a near ubiquitous security vulnerability has been fixed.Just yesterday, Adobe released the most recent version of its Flash player, 9.0.124.0. And with it, vulnerabilities that could enable remote attackers to infiltrate systems running this software (and who doesn't?) have been remediated.

You can grab your copy of the update, and more information on the security flaws, right here. You'll be safe until the next round of flaws are uncovered, if they haven't been already.

Security news watchers will recognize one of the Adobe flaws as the flaw that enabled Shane Macaulay to win a laptop after gaining control of a Vista system during a hacking contest, PWN 2 OWN, at the CanSecWest conference in Vancouver.

I wasn't at this conference, but one of the interesting things I noted was that none of the systems "PWN'D" in the contest were done so through vulnerabilities in any of the core operating systems. That's right, during the first day of the contest, hacks were limited to attacks over the network directed at the operating systems. No one was successful.

So Vista was taken down through an Adobe flaw, and a small team of researchers went home with a MacBook Air and an extra $10,000 after exploiting a flaw in Safari 3.1.

This means the Microsoft vs. Apple "Which is more secure debate" is over. No one is attacking core operating system functionality anymore. Why? Because the operating systems have been sufficiently vetted and hardened. While we will still see vulnerabilities and attacks aimed at OSes, for certain, these won't be what marketers like to call "the sweet spot."

This means the browser you choose to use may have a profound impact on how secure you are while surfing the Internet. It's about Firefox vs. Explorer. QuickTime vs MediaPlayer. It's about not using anything but a fully hardened instant messaging client.

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9498
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
CVE-2020-3282
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
CVE-2020-5909
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
CVE-2020-5910
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVE-2020-5911
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.