Security News

Apple Patches Critical Kernel Vulnerabilities (Threatpost)
2017-01-23 21:35

Apple released updates across its product lines, including iOS 10.2.1, patching a number of critical code execution vulnerabilities in the kernel, libarchive and WebKit.

Advancing a standard format for vendors to disclose cybersecurity vulnerabilities (Help Net Security)
2017-01-20 12:45

Technology providers and their customers are joining forces to advance a standard format for vendors to disclose cybersecurity vulnerabilities. The work of the new OASIS Common Security Advisory...

Massive Oracle Critical Patch Update fixes 270 vulnerabilities (Help Net Security)
2017-01-19 17:22

Oracle has released the first Critical Patch Update scheduled for 2017, and it’s massive. It fixes 270 vulnerabilities across multiple products, and over 100 of them are remotely exploitable by...

Justine Bone on St. Jude Vulnerabilities and Medical Device Security (Threatpost)
2017-01-19 14:00

MedSec CEO Justine Bone talks to Mike Mimoso about the St. Jude Medical vulnerabilities, the considerations her company and Muddy Waters made in short selling St. Jude stock, and the current state...

Oracle Patches 270 Vulnerabilities in Year’s First Critical Patch Update (Threatpost)
2017-01-18 18:26

Oracle patched 270 vulnerabilities, many remotely exploitable, across 45 different products as part of its quarterly Critical Patch Update (CPU) on Tuesday.

Vulnerabilities Leave iTunes, App Store Open to Script Injection (Threatpost)
2017-01-17 21:02

Researchers say iTunes and Apple's App Store suffer from a persistent input validation and mail encoding web vulnerability. If exploited, it could allow an attacker to inject their own malicious script.

Router Vulnerabilities Disclosed in July Remain Unpatched (Threatpost)
2017-01-17 17:05

Command injection vulnerabilities and accessible default admin credentials in home routers distributed by Thailand’s largest broadband provider remain unpatched despite private disclosures to the...

WordPress 4.7.1 Fixes CSRF, XSS, PHPMailer Vulnerabilities (Threatpost)
2017-01-12 17:38

A new WordPress update, pushed this week, resolves eight security issues, including a handful of XSS and CSRF bugs.

Microsoft Patches Two Critical Security Vulnerabilities (Threatpost)
2017-01-10 20:52

Microsoft patched two vulnerabilities rated critical that tied to Office 2016, its Edge browser and its Local Security Authority Subsystem Service (LSASS).

Google Patches 29 Critical Android Vulnerabilities Including Holes in Mediaserver, Qualcomm (Threatpost)
2017-01-04 18:33

Google patched a critical hole in its problematic Android Mediaserver component that could have allowed an attacker to use email, web browsing, and MMS processing of media files to remotely execute code.