Security News

Eternal Blues: A free EternalBlue vulnerability scanner (Help Net Security)
2017-06-30 20:01

It is to be hoped that after the WannaCry and NotPetya outbreaks, companies will finally make sure to install – on all their systems – the Windows update that patches SMB vulnerabilities leveraged...

Free EternalBlue Vulnerability Scanner Released (Security Week)
2017-06-30 16:59

A free tool that can scan networks to discover computers that are vulnerable to the NSA-linked EternalBlue exploit is now available. read more

Azure AD Connect vulnerability allows attackers to reset admin passwords (Help Net Security)
2017-06-29 18:30

A vulnerability in Azure AD Connect could be exploited by attackers to reset passwords and gain unauthorized access to on-premises AD privileged user accounts, Microsoft warned on Tuesday. What...

Another RCE Vulnerability Patched in Microsoft Malware Protection Engine (Threatpost)
2017-06-26 17:54

Google Project Zero’s Tavis Ormandy found another remote code execution vulnerability in the Microsoft Malware Protection Engine, the third since early May.

OpenVPN Patches Critical Remote Code Execution Vulnerability (Threatpost)
2017-06-21 15:14

OpenVPN patched four vulnerabilities privately disclosed by Dutch researcher Guido Vranken, including a critical issue that could lead to remote code execution.

TP-Link Fixes Code Execution Vulnerability in End-of-Life Routers (Threatpost)
2017-06-20 20:19

Router manufacturer TP-Link recently fixed a vulnerability in a discontinued line of routers that if exploited could have been used to execute code on the device.

Stack Clash Vulnerability in Linux, BSD Systems Enables Root Access (Threatpost)
2017-06-19 17:05

Patches are available for a newly discovered Linux, BSD and Solaris vulnerability called Stack Clash that bypasses stack guard-page mitigations and enables root access.

Attackers Mining Cryptocurrency Using Exploits for Samba Vulnerability (Threatpost)
2017-06-12 13:34

Kaspersky Lab said it has seen some of the first exploits targeting a patched Samba vulnerability, and those are being used to mine Monero cryptocurrency.

For timely vulnerability information, unofficial sources are a better bet (Help Net Security)
2017-06-07 20:58

From over 12,500 disclosed Common Vulnerabilities and Exposures (CVEs), more than 75% were publicly reported online before they were published to the NIST’s centralized National Vulnerability...

Vulnerability affecting 1,000+ apps is exposing terabytes of data (Help Net Security)
2017-05-31 21:21

A newly discovered backend data exposure vulnerability, dubbed HospitalGown, highlights the connection between mobile apps and insecure backend databases. Appthority documented more than 1,000...