Security News

PHPMailer, SwiftMailer Updates Resolve Critical Remote Code Execution Vulnerabilities (Threatpost)
2016-12-29 19:20

Critical remote code execution vulnerabilities in PHPMailer and SwiftMailer, libraries used to send emails via PHP, were patched this week.

Nagios Core Patches Root, RCE Vulnerabilities (Threatpost)
2016-12-16 16:00

Nagios Core has been updated to take care of two critical vulnerabilities that can be pinned together to attack servers hosting the open source IT infrastructure monitoring software.

Apple Fixes 97 Vulnerabilities Across macOS, iTunes, Safari, iCloud (Threatpost)
2016-12-14 18:04

Apple released a massive update for macOS Sierra on Tuesday to address 72 vulnerabilities in the operating system.

Microsoft Patches Publicly Disclosed IE, Edge Vulnerabilities (Threatpost)
2016-12-13 20:27

Microsoft patched a half-dozen critical browser vulnerabilities that have been publicly disclosed, but apparently not used in attacks as of yet.

Adobe Patches 31 Vulnerabilities, Flash Zero-Day Under Attack (Threatpost)
2016-12-13 18:00

As part of Patch Tuesday Adobe patched a zero-day vulnerability in Flash Player the company claims is being used in targeted attacks against Internet Explorer users on Windows.

Apple Fixes 12 Vulnerabilities in iOS 10.2 (Threatpost)
2016-12-12 21:22

Apple released iOS 10.2 on Monday, addressing a handful of security vulnerabilities, including two issues that could have led to arbitrary code execution.

PoS attacks: Undetected vulnerabilities lay in wait (Help Net Security)
2016-12-08 12:45

Attivo Networks issued a report detailing severe vulnerabilities in the nation’s POS systems that could lead to large breaches during the Holiday shopping period and on into next year. The report,...

158% increase in Android platform vulnerabilities (Help Net Security)
2016-11-30 12:30

A new Quick Heal report reveals an increase in vulnerabilities on the Android platform, as well as a 33 percent rise in mobile ransomware. Researchers also found a slight decrease in Potentially...

Drupal Fixes ‘Moderately Critical’ Vulnerabilities in Core Engine (Threatpost)
2016-11-18 18:56

Drupal fixed a handful of issues in version 7 and 8 of the content management system core engine that could have led to cache poisoning, social engineering attacks, and a denial of service condition.

Mozilla Patches 29 Vulnerabilities, Prevents MIME Confusion Attacks, in Firefox 50 (Threatpost)
2016-11-16 21:42

Mozilla addressed 29 vulnerabilities, three critical, when it released the latest iteration of its flagship browser, Firefox 50 on Tuesday.