Undocumented SNMP String Exposes Rockwell PLCs to Remote Attacks

Industrial control system operators running Rockwell MicroLogix 1400 PLCs have been warned about a vulnerability that exposes these devices in critical industries to attack. Continue reading Undocumented SNMP String Exposes Rockwell PLCs to Remote Attacks

Academics Devise New Way to Steal Data from Air-Gapped Computers

Researchers can exfiltrate data from air-gapped computers using malware to steal it and transmit it to a receiver by manipulating the mechanical movements of a computer’s hard-disk drive. Continue reading Academics Devise New Way to Steal Data from Air-Gapped Computers

Microsoft Mistakenly Leaks Secure Boot Key

Microsoft inadvertently published a Secure Boot “golden key” policy that allows for self-signed or unsigned binaries to be loaded on Windows devices. Continue reading Microsoft Mistakenly Leaks Secure Boot Key

vBulletin Patches Serious Flaw in Forum Software

A serious vulnerability has been patched in forum software made by vBulletin that could allow attackers to scan servers hosting the package and possibly execute arbitrary code. Continue reading vBulletin Patches Serious Flaw in Forum Software

Putting Apple Bug Bounty Rewards in Perspective

Competing zero-day acquisition programs pay out much more than Apple’s new bug bounty program, but researchers used to submitting bugs gratis to Apple aren’t complaining much. Continue reading Putting Apple Bug Bounty Rewards in Perspective

Windows PDF Library Flaw Puts Edge Users at Risk for RCE

Microsoft today released nine security bulletins as part of its August 2016 Patch Tuesday updates. Continue reading Windows PDF Library Flaw Puts Edge Users at Risk for RCE

A Month Without Adobe Flash Player Patches

Adobe rolled out patches for four vulnerabilities in Adobe Experience Manager, the first time since January its monthly patch release cycle has not included a Flash Player security update. Continue reading A Month Without Adobe Flash Player Patches