Security News

Microsoft Zero-Day Actively Exploited, Patch Forthcoming
2020-01-21 14:58

An unpatched remote code-execution vulnerability in Internet Explorer is being actively exploited in the wild, Microsoft has announced. "If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system," Microsoft explained.

Microsoft Warns of Zero-Day Internet Explorer Exploits
2020-01-20 12:33

Microsoft says it's prepping a patch to fix a memory corruption flaw in multiple versions of Internet Explorer that is being exploited by in-the-wild attackers. The flaw, which exists in a scripting engine built into Internet Explorer, could be exploited by attackers to remotely execute code of their choosing, Microsoft says.

Microsoft Warns of Unpatched IE Browser Zero-Day That's Under Active Attacks
2020-01-18 05:11

Microsoft earlier today issued an emergency security advisory warning millions of Windows users of a new zero-day vulnerability in Internet Explorer browser that attackers are actively exploiting in the wild - and there is no patch yet available for it. A remote attacker can execute arbitrary code on targeted computers and take full control over them just by convincing victims into opening a maliciously crafted web page on the vulnerable Microsoft browser.

It's Friday, the weekend has landed... and Microsoft warns of an Internet Explorer zero day exploited in the wild
2020-01-18 01:17

Microsoft let slip on Friday an advisory detailing an under-attack zero-day vulnerability for Internet Explorer. In brief... A poorly configured Elasticsearch database left an app's baby photos and videos accessible from the public internet.

Browser zero day: Update your Firefox right now!
2020-01-09 14:00

Just two days after releasing Firefox 72, Mozilla has issued an update to patch a critical zero-day flaw. Some Linux distros and many businesses stick to Firefox's Extended Support Release because it gets security fixes at the same pace as the regular version, but doesn't force you to take on new features at every update.

Mozilla patches actively exploited Firefox zero-day
2020-01-09 11:34

Mozilla has patched a Firefox zero-day vulnerability that is being exploited in attacks in the wild and is urging Firefox and Firefox ESR users to update their installations as soon as possible. A day after Mozilla released Firefox 72 - which blocks fingerprinting scripts by default for all users, replaces annoying notification request pop-ups from various sites with a speech bubble in the address bar, and fixes a number of security issues - the corporation pushed out Firefox 72.0.1 with a fix for CVE-2019-17026, a type confusion vulnerability in IonMonkey, the JavaScript Just-In-Time compiler for Mozilla's JavaScript engine.

Mozilla Patches Firefox Zero-Day Exploited in Targeted Attacks
2020-01-09 05:53

Updates released by Mozilla on Wednesday for its Firefox browser address a zero-day vulnerability that has been exploited in targeted attacks. Mozilla says it's aware of targeted attacks exploiting this zero-day, but no other information has been made available.

3 Google Play Store Apps Exploit Android Zero-Day Used by NSO Group
2020-01-07 08:41

Watch out! If you have any of the below-mentioned file managers and photography apps installed on your Android phone-even if downloaded from the official Google Store store⁠-you have been hacked and being tracked. These newly detected malicious Android apps are Camero, FileCrypt, and callCam that are believed to be linked to Sidewinder APT, a sophisticated hacking group specialized in cyber espionage attacks.

App Found in Google Play Exploits Recent Android Zero-Day
2020-01-07 05:29

A malicious application in the Google Play store targeted a recently patched zero-day vulnerability that affects multiple Android devices, including Google's Pixel phones. Tracked as CVE-2019-2215, the vulnerability was disclosed as a zero-day in October by Google Project Zero security researcher Maddie Stone.

Top Zero Days, Data Breaches and Security Stories of 2019: News Wrap
2019-12-20 17:40

From ransomware ramp up, to voice assistant privacy perils, the Threatpost team breaks down the top news stories from this past year.