Critical Vulnerability Patched in Roundcube Webmail

Open source webmail provider Roundcube was patched against a vulnerability that could be trivially exploited to run code on servers or access email accounts. Continue reading Critical Vulnerability Patched in Roundcube Webmail

Flash Exploit Found in Seven Exploit Kits

An Adobe Flash Player vulnerability used by the Sofacy APT gang was also found in seven of the top exploit kits, according to an analysis by Recorded Future. Continue reading Flash Exploit Found in Seven Exploit Kits

Sony Closes Backdoors in IP-Enabled Cameras

Backdoors, likely intentional remote administration features, were closed off in 80 different Sony IP-enabled cameras running the IPELA Engine technology. Continue reading Sony Closes Backdoors in IP-Enabled Cameras

Dirty Cow Vulnerability Patched in Android Security Bulletin

Today’s Android Security Bulletin included a patch for the Dirty Cow vulnerability, a seven-year-old Linux bug that had yet to be patched by Google. Continue reading Dirty Cow Vulnerability Patched in Android Security Bulletin

Distributed Guessing Attack Reels in Payment Card Data

A research paper describes vulnerabilities enabling distributed guessing attacks which allow an attacker to collect payment card data across a number of sites without triggering alerts. Continue reading Distributed Guessing Attack Reels in Payment Card Data

DoD Publishes Vulnerability Disclosure Policy

In the wake of the Pentagon and Army bug bounties, the government continues to engage researchers with the publication of the DoD’s vulnerability disclosure program. Continue reading DoD Publishes Vulnerability Disclosure Policy