Security News

8 RCE, DoS holes in Microsoft Malware Protection Engine plugged (Help Net Security)
2017-05-30 17:22

After the discovery and the fixing of a “crazy bad” remote code execution flaw in the Microsoft Malware Protection Engine earlier this month, now comes another MMPE security update that plugs...

The CIA's "Development Tradecraft DOs and DON'Ts" (Schneier on Security)
2017-03-13 17:00

Useful best practices for malware writers, courtesy of the CIA. Seems like a lot of good advice. General: DO obfuscate or encrypt all strings and configuration data that directly relate to tool...

OpenSSL Update Fixes High-Severity DoS Vulnerability (Threatpost)
2017-02-21 21:02

US-CERT issues alert to server admins warning of a dangerous OpenSSL vulnerability and urges 1.1.0 users update to version 1.1.0e.

Week in review: Windows DoS zero-day, uncloaking Tor Browser users (Help Net Security)
2017-02-06 04:32

Here’s an overview of some of last week’s most interesting news and articles: Half of IT pros don’t know how to improve their security posture Mid-market enterprises have high confidence in their...

Exploit for Windows DoS zero-day published, patch out on Tuesday? (Help Net Security)
2017-02-03 20:12

A zero-day bug affecting Windows 10, 8.1, Windows Server 2012 and 2016 can be exploited to crash a vulnerable system and possibly even to compromise it. The bug It is a memory corruption bug in...

BlackNurse Low-Volume DoS Attack Targets Firewalls (Threatpost)
2016-11-11 14:00

Researchers say BlackNurse attacks are low bandwidth (18Mbps) and can still knock offline many of today’s firewalls.