Skip Links

Patch Management Research Center

Your source for patch management news, opinion, product comparisons and reviews.

Patch Management News
Experts ding DHS vulnerability sharing plan as too limited
The Department of Homeland Security's plan to selectively share information on zero-day vulnerabilities is too restrictive and should be opened up to...
Microsoft rushes Explorer 8 patch release
Just 11 days after issuing an advisory, Microsoft has released a patch for a bug in Internet Explorer 8 that bedeviled the U.S. Department of Labor...
Adobe releases critical security updates for Reader, Flash Player and ColdFusion
Adobe has released scheduled security updates for its Reader, Acrobat, Flash Player and ColdFusion products on Tuesday in order to fix many critical...
Feds' offensive fueling hacker underground, report says
The U.S. government is contributing to the Internet's underground economy by scooping up hacker tools to incorporate into offensive cyber weapons, a...
Companies, government unprepared for new wave of cybersabotage
A new wave of cyberattacks reportedly aimed at industrial control systems comes at a time when private companies and government are still struggling...
Google's five-year plan for authentication: It's complicated
Google has released a draft of its next five-year plan for login authentication that tries to stay at least on par with criminal hackers, but...
Lesson from the Google office hack: Do not trust third-parties
The recent hack of the building management system in a Google's Australian HQ demonstrates how organizations should not trust third-party installers...
Microsoft releases fix-it for Internet Explorer 8 vulnerability
Microsoft has released a temporary fix for a zero-day vulnerability in Internet Explorer 8, which was used by hackers in a prominent attack against...
Highly critical vulnerability fixed in Nginx Web server software
The development team behind the popular Nginx open-source Web server software released security updates on Tuesday to address a highly critical...
Welcome sign for hijackers on 24-7 for 30% of social networkers
Online social networkers invite data marauders to compromise their accounts by choosing a convenient but risky option offered by many websites,...
Google Play changes bring cautious optimism on Android security
Google's decision to have Android apps on Google Play updated only through the online store will likely improve security on the mobile platform, but...
Apache servers ambushed by sophisticated backdoor attacks
Apache servers are being ambushed by a particularly pernicious malware program called Linux/Cdorked.A that's infecting visitors to the sick machines...
Hackers increasingly target shared Web hosting servers for use in mass phishing attacks
Cybercriminals increasingly hack into shared Web hosting servers in order to use the domains hosted on them in large phishing campaigns, according to...
Recently patched Java flaw already targeted in mass attacks, researchers say
A recently patched Java remote code execution vulnerability is already being exploited by cybercriminals in mass attacks to infect computers with...
Bogus ad network marks new twist on Android malware
In a clever twist to Android malware, cybercriminals posing as an ad network were able to fool Google Play and have their malware-distributing...
Browsers pose the greatest threat to enterprise, Microsoft reports
Microsoft's latest security report has found that Web-based attacks pose the greatest threat to companies, giving credence to efforts to develop...
Java 7 Update 21 to fix bugs, change applet warning messages
Oracle will release a new version of Java on Tuesday that will include 42 security fixes and will make changes to how Web-based Java content will be...
Oracle shipping 128 patches for apps, database and middleware
Oracle is planning to release 128 patches on Tuesday covering security weaknesses that affect "hundreds" of its products.
Microsoft amends security update after reports of system errors
Microsoft has amended a security update containing a patch that reportedly caused errors in some third-party software.
Spam botnet-for-hire used to deliver Android malware
The world's largest spam botnet has recently been found sending bogus email with links to the Stels Android Trojan, an indication that the malware...