Security News

‘High Risk’ Zero Day Leaves 200,000 Magento Merchants Vulnerable (Threatpost)
2017-04-13 16:51

A popular version of the Magento ecommerce platform is vulnerable to a remote code execution bug, putting as many as 200,000 online retailers at risk.

Office Zero Day Delivering FINSPY Spyware to Victims in Russia (Threatpost)
2017-04-12 18:58

Researchers have learned that the recently patched Office zero day was used to target victims in Russia with FINSPY spyware.

Microsoft Patches Word Zero-Day Spreading Dridex Malware (Threatpost)
2017-04-11 18:41

A Microsoft Word zero-day vulnerability is being used to spread the Dridex banking Trojan in attacks that have bypassed mitigation efforts.

MS Office zero-day is used to infect users with Dridex (Help Net Security)
2017-04-11 16:40

The still unpatched MS Office zero-day vulnerability publicized by McAfee and FireEye researchers this weekend is being exploited to deliver the infamous Dridex banking malware. Exploit delivered...

MS Office zero-day exploited in attacks – no enabling of macros required! (Help Net Security)
2017-04-10 12:55

A new zero-day flaw affecting all versions of Microsoft Office is being exploited in attacks in the wild, and no user is safe – not even those who use a fully patched Windows 10 machine. Even...

Baseband Zero Day Exposes Millions of Mobile Phones to Attack (Threatpost)
2017-04-07 20:10

A previously undisclosed baseband vulnerability impacting Huawei smartphones, laptop WWAN modules and IoT components was revealed Thursday at the Infiltrate Conference

Week in review: IIS zero-day, iOS scareware, new issue of (IN)SECURE (Help Net Security)
2017-04-03 02:16

Here’s an overview of some of last week’s most interesting news and articles: Like it or not, “cyber” is a shorthand for all things infosec We have lost the cyber war. No, not that cyber war....