Security News

Second Try at Windows LSASS Patch Addresses Vulnerability (Threatpost)
2017-01-11 18:01

Microsoft on Tuesday patched a vulnerability in LSASS, the second attempt it has taken at fixing a remote denial-of-service issue in the critical Windows process.

Google Patches Android Custom Boot Mode Vulnerability (Threatpost)
2017-01-06 21:03

IBM's X-Force security team discovers a high-risk vulnerability in the Android platform opening phones up to DoS and elevation of privilege vulnerabilities.

Siemens Patches Insufficient Entropy Vulnerability in ICS Systems (Threatpost)
2016-12-22 17:28

German industrial giant Siemens has provided a firmware update addressing software vulnerabilities that are found in a popular line of its Desigo PX industrial control hardware.

Panasonic, IOActive Clash on Vulnerability Report (Threatpost)
2016-12-21 14:00

Panasonic Avionics has pushed back against research released Tuesday by IOActive disclosing vulnerabilities in in-flight entertainment systems.

Joomla vulnerability can be exploited to hijack sites, so patch now! (Help Net Security)
2016-12-15 12:33

If you’re running a website on Joomla, you should update to the newly released 3.6.5 version as soon as possible – or risk your site being hijacked. The newest version of the popular CMS has been...

Critical Vulnerability Patched in Roundcube Webmail (Threatpost)
2016-12-07 15:00

Open source webmail provider Roundcube was patched against a vulnerability that could be trivially exploited to run code on servers or access email accounts.

Dirty Cow Vulnerability Patched in Android Security Bulletin (Threatpost)
2016-12-05 20:32

Today's Android Security Bulletin included a patch for the Dirty Cow vulnerability, a seven-year-old Linux bug that had yet to be patched by Google.

PayPal Fixes OAuth Token Leaking Vulnerability (Threatpost)
2016-11-28 20:52

PayPal fixed an issue that could have allowed an attacker to hijack OAuth tokens associated with any PayPal OAuth application. The vulnerability was publicly disclosed on Monday by Antonio Sanso,...

Exploit Code Released for NTP Vulnerability (Threatpost)
2016-11-22 15:30

NTP 4.2.8p9 includes a patch for a vulnerability that could crash ntpd with a single malformed packet.

DoD Publishes Vulnerability Disclosure Policy (Threatpost)
2016-11-22 13:57

In the wake of the Pentagon and Army bug bounties, the government continues to engage researchers with the publication of the DoD’s vulnerability disclosure program.