Drupal Fixes ‘Moderately Critical’ Vulnerabilities in Core Engine

Drupal fixed a handful of issues in version 7 and 8 of the content management system core engine that could have led to cache poisoning, social engineering attacks, and a denial of service condition. Continue reading Drupal Fixes ‘Moderately Critical’ Vulnerabilities in Core Engine

Threatpost News Wrap, November 18, 2016

Mike Mimoso and Chris Brook discuss the news of the week, including this week’s House hearing on the Internet of Things, Samy Kamkar’s PoisonTap tool, and Windows 10’s ransomware protections. Continue reading Threatpost News Wrap, November 18, 2016

Cryptsetup Vulnerability Grants Root Shell Access on Some Linux Systems

A vulnerability in cryptsetup, a utility used to set up encrypted filesystems on Linux distributions, could allow an attacker to retrieve a root rescue shell on some systems. Continue reading Cryptsetup Vulnerability Grants Root Shell Access on Some Linux Systems

Critical MySQL Vulnerabilities Can Lead to Server Compromise

Critical vulnerabilities in MySQL and database servers MariaDB and PerconaDB can lead to arbitrary code execution, root privilege escalation, and server compromise. Continue reading Critical MySQL Vulnerabilities Can Lead to Server Compromise