This Week in Security: Firewall 0-day, Apple’s response, and an Android Bluetooth Bug
Sophos firewall appliances are actively being attacked by a 0-day exploit chain that originates with a SQL injection. That injection is a nasty one, as it can be launched from the WAN user portal. The observed attack used that vulnerability to inject a shell command into the device database, where …read more