Security News

Exploit Writing and Mitigation Going Hand in Hand (Threatpost)
2015-11-12 18:33

Researchers at Endgame shared how two exploit mitigations could go a long way toward wiping out a nasty class of vulnerabilities.

Microsoft Patches Denial of Service Issue in Hyper-V (Threatpost)
2015-11-12 16:39

Microsoft addressed an issue in its hypervisor, Hyper-V, this week, that could lead to a denial of service condition.

November Patch Tuesday Brings 12 Bulletins, Four Critical (Threatpost)
2015-11-10 20:12

Microsoft pushed out 12 bulletins as part of November's Patch Tuesday, including four critical updates, all of which can lead to remote code execution.

Adobe Flash Update Includes Patches for 17 Vulnerabilities (Threatpost)
2015-11-10 17:50

Adobe patched 17 critical remote code execution vulnerabilities in Flash Player.

Critical Java Bug Extends to Oracle, IBM Middleware (Threatpost)
2015-11-10 14:07

Researchers have built proof-of-concept exploits for an unpatched unserialize vulnerability in Apache Commons Collections, a library used in most Java rollouts.

88 Percent of Networks Susceptible to Privileged Account Hacks (Threatpost)
2015-11-10 12:27

A security firm is warning this week that 88 percent of networks are at risk of being compromised via credential theft and reuse.

Comodo Issues Eight Forbidden Certificates (Threatpost)
2015-11-09 19:50

Certificate authority Comodo admits it incorrectly issued eight certificates that include forbidden internal server names or reserved IP addresses.

ProtonMail Back Online Following Six-Day DDoS Attack (Threatpost)
2015-11-09 18:00

Encrypted email service ProtonMail is back online Monday following a crippling six-day DDoS attack.

High-Risk SAP HANA Vulnerabilities Patched (Threatpost)
2015-11-09 17:13

Nearly two dozen critical SAP HANA vulnerabilities have been patched, including a critical misconfiguration of the TrexNet administrative interface.

Microsoft Considers Earlier SHA-1 Deprecation Deadline (Threatpost)
2015-11-06 18:10

Microsoft said this week it's considering moving up its deadline for blocking SHA-1 signed certificates to June 2016.