Security News

1.5M Unpatched WordPress Sites Hacked Following Vulnerability Disclosure (Threatpost)
2017-02-10 16:45

WordPress security experts said that 1.5M sites have been defaced following the disclosure of a silently fixed content injection vulnerability.

High Severity BIND Vulnerability Can Lead to A Crash (Threatpost)
2017-02-09 18:13

The Internet Systems Consortium patched the BIND domain name system this week, addressing a remotely exploitable vulnerability it said could lead to a crash.

WordPress Silently Fixed Privilege Escalation Vulnerability in 4.72 Update (Threatpost)
2017-02-02 19:57

WordPress silently fixed a serious content injection vulnerability when it pushed out its latest security release, 4.7.2, last week

The latest on the critical RCE Cisco WebEx extension vulnerability (Help Net Security)
2017-01-30 15:14

Since Google bug hunter Tavis Ormandy revealed the existence of a remotely exploitable code execution flaw in the Cisco WebEx extension for Google Chrome last week, Cisco has pushed out several...

Docker Patches Container Escape Vulnerability (Threatpost)
2017-01-18 19:26

Docker has patched a privilege escalation vulnerability that could lead to container escapes, allowing a hacker to affect operations of a host from inside a container.

WhatsApp Security Vulnerability (Schneier on Security)
2017-01-17 12:09

Back in March, Rolf Weber wrote about a potential vulnerability in the WhatsApp protocol that would allow Facebook to defeat perfect forward secrecy by forcibly change users' keys, allowing it --...

Addressing the challenges of vulnerability coordination (Help Net Security)
2017-01-11 19:12

The FIRST Vulnerability Coordination Special Interest Group (SIG) made available for public comment through January 31, 2017 the draft Guidelines and Practices for Multi-party Vulnerability...