Security News

Your server remote login isn't root:password, right? Cool. You can keep your data. Oh sh... your IoT gear, though?
2019-06-27 06:58

Not-quite-Iranian file-wiping malware emerges as Tehran blamed for rise in cyber-attacks Not content to be the focus of the geopolitical news cycle, Iran now also finds itself in the middle of two...

rkt Container Runtime Flaws Give Root Access to Host
2019-06-02 13:06

Unpatched vulnerabilities found in the rkt container runtime can be exploited by an attacker to escape the container and gain root access to the host.  read more

No Root Password for 20% of Popular Docker Containers
2019-05-22 15:14

An analysis of 1,000 popular Docker containers revealed that nearly 20% of them have nulled root passwords, Kenna Security says.  read more

Good heavens, is it time to patch Cisco kit again? Prime Infrastructure root privileges hole plugged
2019-05-17 08:09

Do the thing ASAP, you know how it works by now Among a bumper crop of 57 security issues Cisco divulged on Wednesday was a fix for a trio of vulns, one critical, in networks management tool Prime...

Cybersecurity skills shortage still the root cause of rising security incidents
2019-05-14 04:45

The cybersecurity skills shortage is worsening for the third year in a row and has impacted nearly three quarters (74 percent) of organizations, as revealed in the third annual global study of...

Alpine Linux Docker Images Shipped for 3 Years with Root Accounts Unlocked
2019-05-09 17:06

Alpine Linux Docker images available via the Docker Hub contained a critical flaw allowing attackers to authenticate on systems using the root user and no password.

What’s in a cybersecurity question? Getting to the root of cyber insights
2019-04-17 05:40

The day to day practice of cybersecurity is based around asking questions. How do I secure my applications? How do I protect my data’s integrity? How do I manage storage and access? We all know...

Vulnerability in Verizon Fios Quantum Gateway allows attackers to gain root privileges
2019-04-09 13:48

The vulnerability requires local access to be exploited, though Tenable Research claims it can be exploited remotely through the assistance of social engineering.

A patchy Apache a-patchin: HTTP server gets fix for worrying root access hole
2019-04-03 19:52

Rogue 'worker' processes can sneak in with elevated privileges at startup Apache HTTP Server has been given a patch to address a potentially serious elevation of privilege vulnerability.…

BSides SF 2019: Remote-Root Bug in Logitech Harmony Hub Patched and Explained
2019-03-05 05:02

Users of Logitech’s Harmony Hub get long-awaited answers about the critical bugs that left their home networks wide open to attack.