Security News

SAP Patches Critical Vulnerability in Business Client
2018-09-11 18:04

SAP today released its September 2018 set of patches to address a total of 14 vulnerabilities in its products, including a critical bug in SAP Business Client. read more

The Vulnerability Disclosure Process: Still Broken
2018-09-05 17:03

Despite the advent to bug bounty programs and enlightened vendors, researchers still complain of abuse, threats and lawsuits.

CVE-2018-11776 — The Latest Apache Struts Vulnerability
2018-09-04 10:49

A Critical security flaw (CVE-2018-11776) impacts Apache Struts 2.3 through 2.3.34, Struts 2.5 through 2.5.16, and possibly unsupported versions of the popular Java framework.

Critical Vulnerability Patched in PHP Package Repository
2018-08-31 14:29

A critical remote code execution vulnerability was recently addressed in packagist.org read more

Android 'API breaking' vulnerability leaks device data, allows user tracking
2018-08-30 12:45

A vulnerability in the Android operating system can be used to track users without their knowledge.

Microsoft Windows zero-day vulnerability disclosed through Twitter
2018-08-28 15:39

There is no known workaround for the security flaw.

Critical Apache Struts Vulnerability Exploited in Live Attacks
2018-08-28 14:07

A Critical remote code execution vulnerability in Apache Struts 2 that was patched last week is already being abused in malicious attacks, threat intelligence firm Volexity warns. read more

Incorporating sensitive asset data into your vulnerability and compliance program
2018-08-28 12:00

In this podcast recorded at Black Hat USA 2018, Tim White, Director of Product Management, Policy Compliance at Qualys, talks about the importance of incorporating inaccessible or sensitive asset...

Hacker Discloses Unpatched Windows Zero-Day Vulnerability (With PoC)
2018-08-28 10:33

A security researcher has publicly disclosed the details of a previously unknown zero-day vulnerability in the Microsoft's Windows operating system that could help a local user or malicious...