Security News

Code Execution Flaws Patched in Apache Tomcat
2017-10-04 18:58

Several vulnerabilities, including ones that allow remote attackers to execute arbitrary code, have been patched in recent weeks in Apache Tomcat. read more

Oracle Patches Apache Struts, Reminds Users to Update Equifax Bug
2017-09-26 18:28

Oracle released fixes for a handful of recently patched Apache Struts 2 vulnerabilities late last week.

Oracle Releases Patches for Exploited Apache Struts Flaw
2017-09-25 15:36

Oracle has released patches for many of its products to address several vulnerabilities in the Apache Struts 2 framework, including one that has been exploited in the wild for the past few weeks. read more

Optionsbleed bug makes Apache HTTP Server leak data from memory
2017-09-20 20:16

On Monday, security researcher Hanno Böck detailed a memory-leaking vulnerability in Apache HTTP Server that’s similar to the infamous OpenSSL Heartbleed bug uncovered in April 2014. Unlike...

'Optionsbleed' Flaw Causes Apache to Leak Data
2017-09-20 09:52

A vulnerability found in Apache HTTP Server (httpd) can cause certain systems to leak potentially sensitive data in response to HTTP OPTIONS requests, a researcher warned. read more

Risks Limited With Latest Apache Bug, Optionsbleed
2017-09-19 14:29

The risks surrounding the latest Apache bug, called Optionsbleed, are limited given it can only be attacked under certain conditions. Apache, and many Linux distributions, have patched the flaw.

Equifax Confirms Apache Struts Flaw Used in Hack
2017-09-14 11:12

U.S. credit reporting agency Equifax confirmed on Wednesday that an Apache Struts vulnerability exploited in the wild since March was used to breach its systems. read more

Equifax's Colossal Error: Not Patching Apache Struts Flaw
2017-09-14 09:33

Confirmed: Hackers Behind Mega-Breach Exploited Struts Flaw, Patch Was AvailableEquifax made an error that led to one of the largest and most sensitive data breaches of all time, and the mistake...

Equifax Suffered Data Breach After It Failed to Patch Old Apache Struts Flaw
2017-09-14 01:38

The massive Equifax data breach that exposed highly sensitive data of as many as 143 million people was caused by exploiting a flaw in Apache Struts framework, which Apache patched over two months...

Is Unpatched Apache Struts Flaw to Blame for Equifax Hack?
2017-09-12 18:03

Credit Bureau Has Yet to Describe Exploited 'Website Application Vulnerability'Equifax has yet to describe how its site was breached, except to blame a vague "U.S. website application...