Security News

I won't bother hunting and reporting more Sony zero-days, because all I'd get is a lousy t-shirt
2019-02-05 23:56

It's 2019. Should billion-dollar corps do better than offer swag for vulns? Analysis Hunting for exploitable security bugs in software is not an easy way to make a living, and vulnerability...

Zero-Days in WordPress Plugin Actively Exploited
2019-01-28 18:33

The commercial Total Donations plugin for WordPress is impacted by multiple zero-day vulnerabilities that are being actively exploited in attacks, Wordfence security researchers report.  read more

WordPress Users Urged to Delete Zero-Day-Ridden Plugin
2019-01-28 14:39

The development team of the vulnerable Total Donations plugin appears to have abandoned it, and did not respond to inquiries from researchers.

You're an admin! You're an admin! You're all admins, thanks to this Microsoft Exchange zero-day and exploit
2019-01-25 00:31

Easily swapped hashed passwords gives Domain Admin rights via API call. Fix may land next month Microsoft Exchange appears to be currently vulnerable to a privilege escalation attack that allows...

0patch releases micropatch for Windows Contacts RCE zero-day
2019-01-22 11:33

ACROS Security, the creators of 0patch, have released a micropatch for a recently revealed zero-day RCE flaw affecting Windows. About the vulnerability and the micropatch Security researcher John...

Exploit for Recent Flash Zero-Day Added to Fallout Exploit Kit
2019-01-18 20:30

An updated version of the Fallout exploit kit recently emerged with an exploit for a recent Flash zero-day included in its arsenal, Malwarebytes Labs security researchers warn. read more

Prices for Zero-Day Exploits Are Rising
2019-01-17 12:33

Companies are willing to pay ever-increasing amounts for good zero-day exploits against hard-to-break computers and applications: On Monday, market-leading exploit broker Zerodium said it would...

IDenticard Zero-Days Allow Corporate Building Access, Location Recon
2019-01-15 22:43

Multiple hardcoded passwords allow attackers to create badges to gain building entry, access video surveillance feeds, manipulate databases and more.

Zerodium’s waving fatter payouts for zero-day bug hunters
2019-01-09 12:06

Any chance we could appeal to your conscience and integrity and put in a call for ethical disclosure?

Zerodium Offers to Buy Zero-Day Exploits at Higher Prices Than Ever
2019-01-08 12:03

Well, there's some good news for hackers and vulnerability hunters, though terrible news for tech manufacturers! Exploit vendor Zerodium is now willing to offer significantly higher payouts for...