Security News

Google Spots Attacks Exploiting iOS Zero-Day Flaws
2019-02-08 09:55

Google security researchers revealed that two of the vulnerabilities patched by Apple on Thursday with the release of iOS 12.1.4 were zero-day flaws exploited in the wild by malicious actors. read more

Latest iOS 12.1.4 Update Patches 2 Zero-Day and FaceTime Bugs
2019-02-08 08:03

Apple has finally released iOS 12.1.4 software update to patch the terrible Group FaceTime privacy bug that could have allowed an Apple user to call you via the FaceTime video chat service and...

Zero-day Vulnerability Highlights the Responsible Disclosure Dilemma
2019-02-07 17:30

A zero-day vulnerability found in a video-conferencing system and responsibly disclosed led to the response, "Our developers are aware of some known vulnerabilities with the systems, development...

MacOS Zero-Day Exposes Apple Keychain Passwords
2019-02-06 22:14

A researcher who discovered a flaw letting him steal passwords in MacOS is not sharing his findings with Apple without a macOS bug bounty program.

macOS Mojave Zero-Day Allows Theft of Keychain Passwords
2019-02-06 16:45

A researcher has disclosed the existence of a zero-day vulnerability in macOS Mojave that can be exploited by malware to steal plaintext passwords from the operating system’s Keychain. The flaw...

I won't bother hunting and reporting more Sony zero-days, because all I'd get is a lousy t-shirt
2019-02-05 23:56

It's 2019. Should billion-dollar corps do better than offer swag for vulns? Analysis Hunting for exploitable security bugs in software is not an easy way to make a living, and vulnerability...

Zero-Days in WordPress Plugin Actively Exploited
2019-01-28 18:33

The commercial Total Donations plugin for WordPress is impacted by multiple zero-day vulnerabilities that are being actively exploited in attacks, Wordfence security researchers report.  read more

WordPress Users Urged to Delete Zero-Day-Ridden Plugin
2019-01-28 14:39

The development team of the vulnerable Total Donations plugin appears to have abandoned it, and did not respond to inquiries from researchers.

You're an admin! You're an admin! You're all admins, thanks to this Microsoft Exchange zero-day and exploit
2019-01-25 00:31

Easily swapped hashed passwords gives Domain Admin rights via API call. Fix may land next month Microsoft Exchange appears to be currently vulnerable to a privilege escalation attack that allows...

0patch releases micropatch for Windows Contacts RCE zero-day
2019-01-22 11:33

ACROS Security, the creators of 0patch, have released a micropatch for a recently revealed zero-day RCE flaw affecting Windows. About the vulnerability and the micropatch Security researcher John...