Security News

Oracle Patches 270 Vulnerabilities in Year’s First Critical Patch Update (Threatpost)
2017-01-18 18:26

Oracle patched 270 vulnerabilities, many remotely exploitable, across 45 different products as part of its quarterly Critical Patch Update (CPU) on Tuesday.

Patch and security management take 8 hours per month for most companies (Help Net Security)
2017-01-17 13:00

Shavlik and AppSense used VMworld Europe 2016 to collect data from frontline experts, and to highlight patch management and security concerns in corporations. A total of 178 professionals...

FDA urges patients to implement patch to secure their cardiac implants (Help Net Security)
2017-01-12 20:58

Patients who have been implanted with pacemakers and defibrillators manufactured by US-based St. Jude Medical are urged to make sure that their Merlin@home Transmitter unit is plugged in and...

Second Try at Windows LSASS Patch Addresses Vulnerability (Threatpost)
2017-01-11 18:01

Microsoft on Tuesday patched a vulnerability in LSASS, the second attempt it has taken at fixing a remote denial-of-service issue in the critical Windows process.

Microsoft Issues Record Low Number of Patch Tuesday Bulletins (Threatpost)
2017-01-10 20:52

Microsoft patched vulnerabilities that were tied to a variety of its products including Office 2016, its Edge browser and its Local Security Authority Subsystem Service (LSASS).

Joomla vulnerability can be exploited to hijack sites, so patch now! (Help Net Security)
2016-12-15 12:33

If you’re running a website on Joomla, you should update to the newly released 3.6.5 version as soon as possible – or risk your site being hijacked. The newest version of the popular CMS has been...

Firefox Scrambles to Patch Zero Day Actively Exploiting Tor Browser (Threatpost)
2016-11-30 17:44

A zero-day vulnerability in Firefox, similar to one created by the FBI in 2013, is actively being exploited in the Tor Project’s anonymizing TorBrowser.

Pawn Storm raced to pop many targets before Windows zero-day patch release (Help Net Security)
2016-11-09 22:02

As promised, Microsoft provided this Tuesday a patch for the Windows zero-day (CVE-2016-7855) actively exploited by the Strontium (aka Pawn Storm) cyber espionage hacking group. The initial...