Security News

MS Office zero-day exploited in attacks – no enabling of macros required! (Help Net Security)
2017-04-10 12:55

A new zero-day flaw affecting all versions of Microsoft Office is being exploited in attacks in the wild, and no user is safe – not even those who use a fully patched Windows 10 machine. Even...

Baseband Zero Day Exposes Millions of Mobile Phones to Attack (Threatpost)
2017-04-07 20:10

A previously undisclosed baseband vulnerability impacting Huawei smartphones, laptop WWAN modules and IoT components was revealed Thursday at the Infiltrate Conference

Week in review: IIS zero-day, iOS scareware, new issue of (IN)SECURE (Help Net Security)
2017-04-03 02:16

Here’s an overview of some of last week’s most interesting news and articles: Like it or not, “cyber” is a shorthand for all things infosec We have lost the cyber war. No, not that cyber war....

Actively exploited zero-day in IIS 6.0 affects 60,000+ servers (Help Net Security)
2017-03-30 14:15

Microsoft Internet Information Services (IIS) 6.0 sports a zero-day vulnerability (CVE-2017-7269) that was exploited in the wild last summer and is likely also being exploited by threat actors at...

Publicly Attacked Microsoft IIS Zero Day Unlikely to be Patched (Threatpost)
2017-03-29 19:15

Researchers have disclosed a zero-day vulnerability and proof-of-concept exploit for a flaw in Microsoft IIS 6.0. The zero-day has been under attack since last July, the researchers said.

Microsoft Offers Analysis of Zero-Day Being Exploited By Zirconium Group (Threatpost)
2017-03-28 21:12

Microsoft patched a zero-day vulnerability actively used in a campaign by a hacking group known as Zirconium.