Security News

Massive Oracle Critical Patch Update fixes 270 vulnerabilities (Help Net Security)
2017-01-19 17:22

Oracle has released the first Critical Patch Update scheduled for 2017, and it’s massive. It fixes 270 vulnerabilities across multiple products, and over 100 of them are remotely exploitable by...

Oracle Patches 270 Vulnerabilities in Year’s First Critical Patch Update (Threatpost)
2017-01-18 18:26

Oracle patched 270 vulnerabilities, many remotely exploitable, across 45 different products as part of its quarterly Critical Patch Update (CPU) on Tuesday.

Microsoft Patches Two Critical Security Vulnerabilities (Threatpost)
2017-01-10 20:52

Microsoft patched two vulnerabilities rated critical that tied to Office 2016, its Edge browser and its Local Security Authority Subsystem Service (LSASS).

Should Elections Be Classified as "Critical Infrastructure"? (Schneier on Security)
2017-01-10 12:02

I am co-author on a paper discussing whether elections be classified as "critical infrastructure" in the US, based on experiences in other countries: Abstract: With the Russian government hack of...

US Voting Systems Deemed Critical Infrastructure (Threatpost)
2017-01-09 17:46

The Department of Homeland Security has designated the U.S. voting infrastructure as critical infrastructure.

Google Patches 29 Critical Android Vulnerabilities Including Holes in Mediaserver, Qualcomm (Threatpost)
2017-01-04 18:33

Google patched a critical hole in its problematic Android Mediaserver component that could have allowed an attacker to use email, web browsing, and MMS processing of media files to remotely execute code.

PHPMailer, SwiftMailer Updates Resolve Critical Remote Code Execution Vulnerabilities (Threatpost)
2016-12-29 19:20

Critical remote code execution vulnerabilities in PHPMailer and SwiftMailer, libraries used to send emails via PHP, were patched this week.

Cisco Warns of Critical Flaw in CloudCenter Orchestrator Systems (Threatpost)
2016-12-23 17:06

Cisco is warning customers of a privilege escalation flaw in Cisco CloudCenter Orchestrator systems that could allow an attacker to gain root privileges on affected systems.

End the air gapping myth in critical infrastructure security (Help Net Security)
2016-12-14 13:30

In an environment where we’re seeing increasing demand for connectivity between operational technology (OT) and IT, security teams have to dispel the air gapping myth to acknowledge that IT...

Netgear Routers Remain Exposed to Critical Flaw (Threatpost)
2016-12-12 19:30

Netgear has confirmed a critical vulnerability in its Nighthawk routers that expose devices to command injection attacks. A public exploit is available.