Security News

Critical "Same Origin Policy" Bypass Flaw Found in Samsung Android Browser
2017-12-29 12:33

A critical vulnerability has been discovered in the browser app comes pre-installed on hundreds of millions of Samsung Android devices that could allow an attacker to steal data from browser tabs...

AutoIt Scripting Used By Overlay Malware to Bypass AV Detection
2017-11-10 17:00

IBM’s X-Force Research team reports hackers attacking Brazilian banks are using the Windows scripting tool called AutoIt to reduces the likelihood of antivirus software detection.

Flawed BIOS Implementations Lead to Intel Boot Guard Bypass
2017-10-09 11:56

Poor firmware implementation can lead to the bypass of advanced technologies created to protect Unified Extensible Firmware Interface (UEFI) BIOS, such as Intel Boot Guard, from illegal...

Apple Silently Patched macOS Security Bypass Flaw
2017-09-28 16:05

Researchers claim Apple has silently patched a macOS vulnerability that can be exploited to bypass one of the operating system’s security features and execute arbitrary JavaScript code without...

Windows Defender Bypass Tricks OS into Running Malicious Code
2017-09-28 14:36

Researchers at CyberArk have devised a Windows Defender bypass that tricks the operating system into executing malicious code while Defender scans a benign file.

Report: North Korea Seeks Bitcoins to Bypass Sanctions
2017-09-14 12:03

JP Morgan Chief Slams Bitcoin as Fit Only for Drug Dealers, Murderers, RegimesIn cryptocurrency we trust: The government of North Korea has been turning to bitcoin exchange heists and...

Microsoft Won’t Fix Security Bypass Vulnerability in Edge (Threatpost)
2017-09-07 18:24

Microsoft is opting to stand pat and not fix a content security bypass vulnerability in its Edge browser, something researchers warn could potentially lead to the disclosure of confidential information.

Chinese Man Jailed For Selling VPNs that Bypass Great Firewall (The Hackers News)
2017-09-05 02:36

In an effort to continue its crackdown on VPNs, Chinese authorities have arrested a 26-year-old man for selling VPN software on the Internet. China's Supreme Court has sentenced Deng Jiewei from...

Drupal Patches Critical Access Bypass in Core Engine (Threatpost)
2017-08-17 19:50

A critical flaw in Drupal CMS platform could allow unwanted access to the platform allowing a third-party to view, create, update or delete entities.

Access Bypass Vulnerabilities Patched in Drupal 8 (Security Week)
2017-08-17 06:08

A Drupal 8 security update released on Wednesday addresses several access bypass vulnerabilities affecting components such as views, the REST API and the entity access system. read more