Security News

Google Discloses Details of an Unpatched Microsoft Vulnerability (Schneier on Security)
2017-03-09 12:28

Google's Project Zero is serious about releasing the details of security vulnerabilities 90 days after they alert the vendors, even if they're unpatched. It just exposed a nasty vulnerability in...

Policy Experts Push To Make Vulnerability Equities Process Law (Threatpost)
2017-02-23 21:37

By making the Vulnerability Equities Process law, advocates of the idea argue there would be more reliability, transparency and accountability in the process of government vulnerability disclosure.

Impact of New Linux Kernel DCCP Vulnerability Limited (Threatpost)
2017-02-23 16:11

Existing mitigations and limitations around a newly disclosed Linux kernel vulnerability in the DCCP module mute the potential impact of local attacks.

OpenSSL Update Fixes High-Severity DoS Vulnerability (Threatpost)
2017-02-21 21:02

US-CERT issues alert to server admins warning of a dangerous OpenSSL vulnerability and urges 1.1.0 users update to version 1.1.0e.

Google Discloses Unpatched Microsoft Vulnerability (Threatpost)
2017-02-21 18:02

Google Project Zero researchers are warning of an unpatched Microsoft vulnerability in the Windows' GDI library that allows attackers to steal sensitive data from program memory.