Patch Out For 'Ridiculous' Trend Micro Command Execution Vulnerability (theregister.co.uk)
An anonymous reader shares a report on The Register: A bug in its software meant that Trend Micro accidentally left a remote debugging server running on customer machines. The flaw, discovered by Google's Project Zero researcher Tavis Ormandy, opened the door to command execution of vulnerable systems (running either Trend Micro Maximum Security, Trend Micro Premium Security or Trend Micro Password Manager). Ormandy -- who previously discovered a somewhat similar flaw in Trend Micro's technology -- described the latest flaw as 'ridiculous'. Trend Micro issued a patch for the flaw, a little over a week after Ormandy reported the bug to it on 22 March. The patch is not complete but does address the most critical issues at hand, according to the security firm.
Fortunately, Trend Micro won an award, they're the best at stopping zero day threats! So it's not a problem, keep using your anti-virus.
"First they came for the slanderers and i said nothing."
I'm pretty sure Trend Micro causes autism.
Welcome to realization that this is normal. Not even new normal, as it always been this way.
Pretty much any vendor out there that produces software or IT hardware doesn't effectively test it. IT vendors that take QA seriously are very very rare, most just don't take testing seriously. This is further complicated by the fact that QA is seen as a dead-end IT career. Universally lower pay matches this outlook. Consequently, hiring and retaining good QA is very challenging as anyone competent constantly attempting to move away from it.
"Whoops!" --NSA
Accidental, my arse. Yet another company who can't be trusted.
The Slashdot inline summary for your post was awesome: NSAAccidental, my arse.
I think this should be coined as a new term: NSAccidental pronounced N-S-Accidental
APK Hosts File Engine 9.0++ SR-4 32/64-bit http://www.bing.com/search?q=%...
* Less power/cpu/ram+ IO use vs. local DNS servers + addons w/ less security issues vs. DNS + routers. Less complex vs firewalls (needing layered filtering drivers - hosts don't + firewalls block less used IP addresses, hosts block more used host-domain names) complimenting 'em. Antivirus = reactive. Hosts = proactive, blocking infection BEFORE you get it. Gets its data from 10 reputable security community sites.
APK
P.S. - Hosts get you more speed (hardcodes + adblocks) & faster vs. addons, security (vs. bad sites/dns security issues), reliability (vs. downed/poisoned dns), & anonymity (dns requestlogs/trackers) vs. other "so-called -solutions'" w/ what you natively have. Unlike Adblock/UBlock/Ghostery, hosts != blockable by ClarityRay/BlockIQ... apk