CanSecWest has again produced enlightening results. ZDNet records the latest breach of Windows 7: Hacker exploits IE8 on Windows 7 to win Pwn2Own. In case you’ve been sleeping, these are Microsoft’s latest offerings. The more things change, the more they remain the same.
I should also note that Peter Vreugdenhil bypassed the two core elements of Microsoft’s security plan: ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention). It took him just two weeks to implement.