Stock prices
Vulnerability disclosures could be used to manipulate stock prices

Security disclosures tip the stock market

Events such as Microsoft's Patch Tuesday could be used for fraud, says McAfee

Written by Shaun Nichols in San Francisco

The disclosure of software vulnerabilities can have an impact as far away as Wall Street, according to a recent report by security firm McAfee.

Researcher Anthony Bettini examined the most regular of all vulnerability disclosures, Microsoft's Patch Tuesday, and found that the company's stock price is routinely lower on the days when it releases patches.

Advertisement

Bettini credited much of this impact on stock price to the press stories and concerns which surround the disclosures.

The fluctuations in Microsoft's stock price on Patch Tuesday are relatively minor and short-lived in comparison with other market forces, but Bettini warned that a clever researcher or investor could manipulate the disclosure process to pull off significant stock fraud.

"Consider that fake vulnerability disclosures and rumours already appear today on mailing lists such as Full Disclosure or on IRC chat rooms," Bettini explained.

"It is possible that events could be orchestrated via social engineering to manipulate the market and its participants."

The McAfee report was written weeks ago for inclusion in the company's security journal, but its release comes just days after the SEC opened an investigation into possible stock fraud after a false report claiming that Apple chief Steve Jobs had suffered a heart attack.

David Marcus, security research and communications manager at McAfee, told vnunet.com that the similarities between the Microsoft and Apple scenarios were not lost on the company. "It was really kind of eerie, truth be told," he said.

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols

19 Dec 2008

2.93 MBPodcast Special: Views from the Valley More...

Podcast image

18 Dec 2008

17.6 MBComputing podcast - the highlights of 2008 More...

Shaun Nichols and Iain Thomson

15 Dec 2008

4.98 MBPodcast Special: Views from the Valley More...

Poll

Communications super-database

Communications super-database

Should the government be allowed to track our emails and internet use?

Previous poll results

Spotlight

Palm Pre

Video: Palm Pre launch at CES

vnunet.com checks out Palm's touchscreen smartphone at CES 2009 in...  More...

CES 2009

CES 2009 Special Report

All the latest coverage from Las Vegas   More...

Green lightbulb

Electronics makers urged to go greener

Greenpeace research finds much work still needs to be done   More...

Macworld 2009

Macworld 2009 Special Report

All the latest coverage from San Francisco   More...

Primary Navigation