Security News

Vulnerability Has Been Lurking in Avaya Phones for 10 Years
2019-08-09 15:51

A security vulnerability discovered and patched 10 years ago has remained unaddressed in various Avaya phones until recently, McAfee security researchers have discovered.  read more

Microsoft's new vulnerability tracking service is about IT productivity
2019-08-09 10:23

With so many threats and vulnerabilities to deal with, just knowing which actions you should prioritize can be hard. The new Threat & Vulnerability Management service from Microsoft should help.

Vulnerability in Kubernetes Allows Access to Custom Resources
2019-08-08 04:51

A vulnerability addressed this week in the Kubernetes container orchestration system could allow users to read, modify or delete cluster-wide custom resources. read more

SQL Injection Vulnerability Exposed Starbucks Financial Records
2019-08-07 12:33

A critical SQL injection vulnerability exposed nearly one million financial records stored in a Starbucks enterprise database, a researcher revealed this week. read more

Flexera unveils Vendor Patch Module for its Software Vulnerability Manager
2019-08-02 02:30

Flexera, the software company that helps organizations realize technology’s power to accelerate their business, releases an add-on module for its popular Software Vulnerability Manager – Vendor...

How to build a vulnerability response plan: 6 tips
2019-08-01 15:10

Cybersecurity vulnerabilities continue to increase, and automated scanners can't always detect the most critical ones, according to Bugcrowd.

Vulnerability in VxWorks RTOS allows attackers to control internal networks
2019-07-29 15:40

Internet-connected devices powered by VxWorks 6.5 and newer are affected by a vulnerability that allows remote attackers full control over targeted devices.

ProFTPD Vulnerability Can Expose Servers to Attacks
2019-07-23 11:21

A security hole affecting the free and open source ProFTPD file transfer protocol (FTP) server can be exploited to copy files to vulnerable servers and possibly execute arbitrary code. read more

Critical RCE Vulnerability Found in Palo Alto Networks VPN Product
2019-07-22 14:39

A critical remote code execution vulnerability has been found and patched in Palo Alto Networks’ GlobalProtect product. read more

Tesla Vulnerability: A Bounty Hunter's Tale
2019-07-19 07:33

The latest edition of the ISMG Security Report describes the accidental discovery of a Tesla software vulnerability. Also featured: an analysis of the latest ransomware trends and insights from...