Security News

Exploit Available for Critical Apache Struts Vulnerability (Security Week)
2017-09-06 08:12

The latest version of Apache Struts 2 addresses several vulnerabilities, including a critical remote code execution flaw for which an exploit was created within hours after the release of a patch....

PoC Released for Dangerous iOS Kernel Exploit (Security Week)
2017-08-25 09:41

Proof-of-concept (PoC) code has been released for recently patched iOS vulnerabilities that can be chained to take full control of a mobile device. The flaws could also be useful for a jailbreak,...

Bounty for Encrypted Messaging Exploits: $500,000 (InfoRiskToday)
2017-08-24 15:03

Zero-Day Exploit Vendor Zerodium Seeks Exploits for Signal, WhatsApp, TelegramThere's another option for governments trying to overcome the end-to-end encryption barrier: buy a zero-day software...

Zerodium Offers $500,000 For Messaging, Email App Exploits (Security Week)
2017-08-24 11:07

Zerodium has made some changes to its exploit acquisition program and the company is now offering up to $500,000 for remote code execution and privilege escalation vulnerabilities affecting...

A Company Offers $500,000 For Secure Messaging Apps Zero-Day Exploits (The Hackers News)
2017-08-24 00:27

How much does your privacy cost? It will soon be sold for half a Million US dollars. A controversial company specialises in acquiring and reselling zero-day exploits is ready to pay up to...

ROPEMAKER Exploit Allows for Changing of Email Post-Delivery (Threatpost)
2017-08-23 17:53

An exploit dubbed ROPEMAKER relies on taking advantage of email design functionality, namely by remotely changing CSS in HTML-based emails after they've been sent.

Simple Exploit Allows Attackers to Modify Email Content — Even After It's Sent! (The Hackers News)
2017-08-23 06:05

Security researchers are warning of a new, easy-to-exploit email trick that could allow an attacker to turn a seemingly benign email into a malicious one after it has already been delivered to...

Neptune Exploit Kit Dropping Cryptocurrency Miners Through Malvertisements (Threatpost)
2017-08-22 21:51

Researchers say the Neptune, or Terror exploit kit has been spreading Monero cryptocurrency miners via malvertisements.

Neptune Exploit Kit Used to Deliver Monero Miner (Security Week)
2017-08-22 14:23

Cybercriminals have been using the Neptune exploit kit to deliver cryptocurrency miners via malvertising campaigns, FireEye reported on Tuesday. read more

New Exploit Kit: A Closer Look (InfoRiskToday)
2017-08-18 10:48

The latest edition of the ISMG Security Report leads with a closer look at a new exploit kit and whether it represents a resurgence in these types of criminal packages. Also featured: a discussion...