Mozilla Patches Certificate Pinning Vulnerability in Firefox

A remote code execution in Firefox caused by the expiration of certificate pins was patched by Mozilla in Firefox 49 and Firefox ESR 45.4. Continue reading Mozilla Patches Certificate Pinning Vulnerability in Firefox

Experts Want Transparency From Government’s Vulnerabilities Equities Process

Security and policy experts make another call for additional transparency around the government’s Vulnerabilities Equities Process and the zero days it has in its possession. Continue reading Experts Want Transparency From Government’s Vulnerabilities Equities Process

Google Project Zero Prize Pays $200,000 for Critical Vulnerability Chains

Google Project Zero announced a six-month Android bug bounty program that requires researchers to file bugs as they find them, rather than hoard the whole chain. Continue reading Google Project Zero Prize Pays $200,000 for Critical Vulnerability Chains