Security News

Hundreds of Thousands of Netgear Routers Vulnerable to Password Bypass (Threatpost)
2017-01-30 21:48

Hundreds of thousands–potentially more than one million–Netgear routers are susceptible to a pair of vulnerabilities that can lead to password disclosure.

Dridex Returns With Windows UAC Bypass Method (Threatpost)
2017-01-27 18:56

Dridex banking malware returns with a new bypass technique that allows the malware to execute without triggering a Windows UAC alert to the user.

Microsoft Silently Fixes Kernel Bug That Led to Chrome Sandbox Bypass (Threatpost)
2016-11-30 21:10

Microsoft appears to have silently fixed a two-year-old bug in in Windows Kernel Object Manager that could have allowed for the bypass of privileges in Google's Chrome browser.

iOS 10 Passcode Bypass Can Access Photos, Contacts (Threatpost)
2016-11-17 19:38

A vulnerability in iOS 8, 9, 10, and even the most recent beta version, 10.2 beta 3, could allow an attacker to access photos and contacts on a locked iPhone.

Outlook Web Access Two-Factor Authentication Bypass Exists (Threatpost)
2016-11-03 19:15

Two-factor authentication protecting Outlook Web Access and Office 365 portals can be bypassed-and the situation likely cannot be fixed, a researcher has disclosed.

Researchers bypass ASLR by exploiting flaw in Intel chip (Help Net Security)
2016-10-19 22:03

Researchers have found a design flaw in the branch predictor, a component of Intel’s Haswell processor, and have exploited it to bypass ASLR (Address Space Layout Randomization). What is ASLR?...