Security News

Remote Code Execution Vulnerability Patched in Git
2018-05-30 12:40

Updates released on Tuesday for the Git version control system patch two security flaws, including a serious vulnerability that can be exploited for remote code execution using specially crafted...

Schneider Electric Patches XXE Vulnerability In Software
2018-05-23 19:28

Schneider Electric on Tuesday issued fixes for a vulnerability its SoMachine Basic software that could result in disclosure and retrieval of arbitrary data.

New speculative-execution vulnerability strikes AMD, ARM, and Intel
2018-05-22 16:24

Fortunately, existing fixes should provide the protection we need.

Another Spectre-Like CPU Vulnerability
2018-05-22 14:38

Google and Microsoft researchers have disclosed another Spectre-like CPU side-channel vulnerability, called "Speculative Store Bypass." Like the others, the fix will slow the CPU down. The German...

Dell Patches Vulnerability in Pre-installed SupportAssist Utility
2018-05-21 17:43

Dell Patches Local Privilege Escalation in SupportAssist Dell recently addressed a local privilege escalation (LPE) vulnerability in SupportAssist, a tool pre-installed on most of all new Dell...

Linux admins: Dire vulnerability gives attackers root access in RHEL, CentOS, Fedora
2018-05-16 12:21

A flaw related to a NetworkManager integration script is trivially easy for attackers to leverage.

Serious XSS vulnerability discovered in Signal
2018-05-16 10:37

Researchers have discovered a serious cross-site scripting (XSS) vulnerability affecting all desktop versions of Edward Snowden’s favourite security application, Signal.

The pace of vulnerability disclosure shows no signs of slowing
2018-05-15 13:00

Unless the pace of vulnerability disclosure slows down in the coming quarters, we are looking at yet another record-breaking year, according to Risk Based Security’s 2018 Q1 Vulnerability...

The EFAIL vulnerability – why it’s OK to keep on using email
2018-05-15 11:18

The EFAIL bug shows how to trick some mail clients into turning the email encryption tools S/MIME and OpenPGP against themselves.

Details on a New PGP Vulnerability
2018-05-14 18:36

A new PGP vulnerability was announced today. Basically, the vulnerability makes use of the fact that modern e-mail programs allow for embedded HTML objects. Essentially, if an attacker can...