Security News

Microsoft Won’t Fix Security Bypass Vulnerability in Edge (Threatpost)
2017-09-07 18:24

Microsoft is opting to stand pat and not fix a content security bypass vulnerability in its Edge browser, something researchers warn could potentially lead to the disclosure of confidential information.

Microsoft Programming Error is Behind Dangerous Kernel Bug, Researchers Claim (Threatpost)
2017-09-07 13:00

Researchers say a 18-year-old programming error by Microsoft is creating a kernel bug that can be abused by an attacker.

Tor Project Brings Security Slider Feature to Android App Orfox (Threatpost)
2017-09-06 21:05

Tor Project developers recently bolstered Orfox, a Tor Browser for Android devices, to help privacy-conscious mobile browsers better customize their security.

IDN Homograph Attack Spreading Betabot Backdoor (Threatpost)
2017-09-06 18:16

An IDN homograph attack leveraging Adobe’s brand has been discovered, with the malicious site spreading the Betabot backdoor

Multiple Vulnerabilities Found in NVIDIA, Qualcomm, Huawei Bootloaders (Threatpost)
2017-09-06 17:55

Researchers find six previously unknown memory corruption and unlock-bypass vulnerabilities in major chipset vendors' firmware code.

13 Critical Remote Code Execution Bugs Fixed in September Android Update (Threatpost)
2017-09-06 17:12

Google fixed 81 vulnerabilities, including 13 critical remote code execution bugs, in the September edition of its Android Security Bulletin on Tuesday.

WireX Variant Capable of UDP Flood Attacks (Threatpost)
2017-09-06 12:55

F5 Labs has detected a WireX variant capable of launching UDP flood DDoS attacks.

Patch Released for Critical Apache Struts Bug (Threatpost)
2017-09-05 18:10

The Apache Software Foundation released a patch on Tuesday for a critical vulnerability impacting all versions of Struts since 2008.

Four Million Time Warner Cable Records Left on Misconfigured AWS S3 (Threatpost)
2017-09-05 18:06

600 gigabytes of information, including SQL database dumps, code, access logs, and customer information, belonging to BroadSoft and its client, TWC, was left online, accessible to anyone.

Military Contractor’s Vendor Leaks Resumes in Misconfigured AWS S3 (Threatpost)
2017-09-05 16:16

Thousands of resumes and job applications from U.S. military veterans, law enforcement, and others were leaked by a recruiting vendor in an unsecured AWS S3 bucket.