Security News

Are we chasing the wrong zero days?
2018-11-26 06:45

Zero days became part of mainstream security after the world found out that Stuxnet malware was used to inflict physical damage on an Iranian nuclear facility. After the revelation, organization...

Hackers Earn $1 Million for Zero-Day Exploits at Chinese Competition
2018-11-19 11:42

White hat hackers earned more than $1 million for exploits disclosed at the Tianfu Cup PWN hacking competition that took place on November 16-17 in Chengdu, the capital of China's Sichuan...

November 2018 Patch Tuesday: Microsoft fixes 63 flaws, one actively exploited zero-day
2018-11-14 15:34

As part of the November 2018 Patch Tuesday, Microsoft has released 62 security patches and several advisories. There are 12 critical vulnerabilities among those patched this month, but...

APT Group Uses Windows Zero-Day in Middle East Attacks
2018-11-14 07:14

A Windows zero-day vulnerability addressed this week by Microsoft with its November 2018 Patch Tuesday updates has been exploited by an advanced persistent threat (APT) group in attacks aimed at...

Microsoft Patches Zero-Day Bug in Win7, Server 2008 and 2008 R2
2018-11-13 22:10

Microsoft’s November Patch Tuesday fixes include mitigation against a zero-day vulnerability leaving Windows 7, Server 2008 and Server 2008 R2 open to attack.

Ranting researcher publishes VM-busting zero-day without warning
2018-11-08 13:57

A security researcher has published a zero-day flaw in a commonly-used virtual machine management system without notifying the vendor, justifying it with a scathing critique of the infosecurity industry.

Unpatched VirtualBox Zero-Day Vulnerability and Exploit Released Online
2018-11-08 09:33

An independent exploit developer and vulnerability researcher has publicly disclosed a zero-day vulnerability in VirtualBox—a popular open source virtualization software developed by Oracle—that...

We don' need no stinkin' bounties: VirtualBox guest-to-host escape zero-day lands at GitHub
2018-11-07 11:50

Bug hunter rages at wearisome disclosure process An infosec researcher has expressed his frustration with disclosure processes by going public with a zero-day in VirtualBox, Oracle's open-source...

Researcher Drops Oracle VirtualBox Zero-Day
2018-11-07 10:31

A researcher has disclosed the details of a zero-day vulnerability affecting Oracle’s VirtualBox virtualization software. The flaw appears serious as exploitation can allow a guest-to-host escape....

Cisco Security Appliance Zero-Day Found Actively Exploited in the Wild
2018-11-02 16:50

A high severity zero-day flaw exists in Cisco System's SIP inspection engine.