Security News

US Voting Systems Deemed Critical Infrastructure (Threatpost)
2017-01-09 17:46

The Department of Homeland Security has designated the U.S. voting infrastructure as critical infrastructure.

Google Patches 29 Critical Android Vulnerabilities Including Holes in Mediaserver, Qualcomm (Threatpost)
2017-01-04 18:33

Google patched a critical hole in its problematic Android Mediaserver component that could have allowed an attacker to use email, web browsing, and MMS processing of media files to remotely execute code.

PHPMailer, SwiftMailer Updates Resolve Critical Remote Code Execution Vulnerabilities (Threatpost)
2016-12-29 19:20

Critical remote code execution vulnerabilities in PHPMailer and SwiftMailer, libraries used to send emails via PHP, were patched this week.

Cisco Warns of Critical Flaw in CloudCenter Orchestrator Systems (Threatpost)
2016-12-23 17:06

Cisco is warning customers of a privilege escalation flaw in Cisco CloudCenter Orchestrator systems that could allow an attacker to gain root privileges on affected systems.

End the air gapping myth in critical infrastructure security (Help Net Security)
2016-12-14 13:30

In an environment where we’re seeing increasing demand for connectivity between operational technology (OT) and IT, security teams have to dispel the air gapping myth to acknowledge that IT...

Netgear Routers Remain Exposed to Critical Flaw (Threatpost)
2016-12-12 19:30

Netgear has confirmed a critical vulnerability in its Nighthawk routers that expose devices to command injection attacks. A public exploit is available.

Critical flaw opens Netgear routers to hijacking (Help Net Security)
2016-12-12 15:16

Several Netgear router models can be easily hijacked by remote, unauthenticated attackers, CERT/CC has warned on Friday. The vulnerability that allows this takeover can be exploited by simply...

Critical Vulnerability Patched in Roundcube Webmail (Threatpost)
2016-12-07 15:00

Open source webmail provider Roundcube was patched against a vulnerability that could be trivially exploited to run code on servers or access email accounts.

Drupal Fixes ‘Moderately Critical’ Vulnerabilities in Core Engine (Threatpost)
2016-11-18 18:56

Drupal fixed a handful of issues in version 7 and 8 of the content management system core engine that could have led to cache poisoning, social engineering attacks, and a denial of service condition.

Critical Linux bug opens systems to compromise (Help Net Security)
2016-11-15 20:30

Researchers from the Polytechnic University of Valencia have discovered a critical flaw that can allow attackers – both local and remote – to obtain root shell on affected Linux systems. So far,...