Security News

On the Zero-Day Market
2024-05-24 11:07

Echo May 24, 2024 7:34 AM. The proposals about more government openness and more emphasis on import-export controls is good. More emphasis needs to be placed on positive public interest and also public benefit tests to discourage secrecy for the wrong reasons and also prevent banning activities which are of public benefit because they're automatically caught up in blanket bans.

Update Chrome Browser Now: 4th Zero-Day Exploit Discovered in May 2024
2024-05-24 10:10

Google on Thursday rolled out fixes to address a high-severity security flaw in its Chrome browser that it said has been exploited in the wild. Assigned the CVE identifier CVE-2024-5274, the...

Google fixes eighth actively exploited Chrome zero-day this year
2024-05-24 09:30

Google has released a new emergency security update to address the eighth zero-day vulnerability in Chrome browser confirmed to be actively exploited in the wild. CVE-2024-5274 is the eighth actively exploited vulnerability that Google fixed in Chrome since the beginning of the year, and the third this month.

Google fixes yet another Chrome zero-day exploited in the wild (CVE-2024-5274)
2024-05-24 07:41

For the eighth time this year, Google has released an emergency update for its Chrome browser that fixes a zero-day vulnerability with an in-the-wild exploit.As per usual, Google keeps technical details of the vulnerability under wraps.

QNAP QTS zero-day in Share feature gets public RCE exploit
2024-05-20 14:57

The above bugs impact QTS, the NAS operating system on QNAP devices, QuTScloud, the VM-optimized version of QTS, and QTS hero, a specialized version focused on high performance. QNAP has addressed CVE-2023-50361 through CVE-2023-50364 in a security update released in April 2024, in versions QTS 5.1.6.2722 build 20240402 and later, and QuTS hero h5.1.6.2734 build 20240414 and later.

Google fixes third exploited Chrome zero-day in a week (CVE-2024-4947)
2024-05-16 08:49

For the third time in the last seven days, Google has fixed a Chrome zero-day vulnerability for which an exploit exists in the wild.While the two Chrome zero days fixed in the past few days have been attributed to an anonymous researcher, this time around the reporters are known: Kaspersky threat researchers Vasiliy Berdnikov and Boris Larin.

Google Patches Yet Another Actively Exploited Chrome Zero-Day Vulnerability
2024-05-16 03:01

Google has rolled out fixes to address a set of nine security issues in its Chrome browser, including a new zero-day that has been exploited in the wild. Assigned the CVE identifier CVE-2024-4947,...

Google fixes third actively exploited Chrome zero-day in a week
2024-05-15 22:36

​Google has released a new emergency Chrome security update to address the third zero-day vulnerability exploited in attacks within a week. [...]

Google patches third exploited Chrome zero-day in a week
2024-05-15 22:36

Google has released a new emergency Chrome security update to address the third zero-day vulnerability exploited in attacks within a week. Chrome updates automatically when security patches are available.

Microsoft Patches 61 Flaws, Including Two Actively Exploited Zero-Days
2024-05-15 07:17

Microsoft has addressed a total of 61 new security flaws in its software as part of its Patch Tuesday updates for May 2024, including two zero-days which have been actively exploited in the wild....