Two 0-Days Under Active Attack, Among 120 Bugs Patched by Microsoft

One of the two zero-day bugs is rated ‘critical’ and is classified as a remote code-execution bug impacting Microsoft’s Internet Explorer. Continue reading Two 0-Days Under Active Attack, Among 120 Bugs Patched by Microsoft

Microsoft Patches Zero-Day Bug in Win7, Server 2008 and 2008 R2

Microsoft’s November Patch Tuesday fixes include mitigation against a zero-day vulnerability leaving Windows 7, Server 2008 and Server 2008 R2 open to attack. Continue reading Microsoft Patches Zero-Day Bug in Win7, Server 2008 and 2008 R2

Windows Zero-Day Revealed on Twitter, Microsoft Data Sharing Service Affected

A new zero-day Windows vulnerability has been disclosed via the Twitter social network. According to the information released by the security researcher the problem lies within the Microsoft Data Sharing service. It is used to allow data sharing betwee… Continue reading Windows Zero-Day Revealed on Twitter, Microsoft Data Sharing Service Affected

CVE-2018-8453: Microsoft Windows Zero-Day Vulnerability Used in Attacks Worldwide

Security experts discovered a zero-day vulnerability affecting Microsoft Windows that is used by hackers to launch targeted attacks. It is being tracked in the CVE-2018-8453 advisory which describes it as a weakness in a Win32 Driver file. Microsoft ha… Continue reading CVE-2018-8453: Microsoft Windows Zero-Day Vulnerability Used in Attacks Worldwide

Drone Assassins, Security Shaming, and Zero-Day – Hack Naked News #189

Drone assassins are cheap, deadly, and at your local store, State Department shamed, MS-ISAC releases advisory advisory PHP vulnerabilities, a nasty piece of CSS code, a Zero-Day bug in CCTV surveillance cameras, and FreeBSD has its own TCP-queue-of-de… Continue reading Drone Assassins, Security Shaming, and Zero-Day – Hack Naked News #189

0day alert: Be ready to update Adobe Flash Player tomorrow

On Tuesday, Adobe has pushed out security updates for Cold Fusion and Adobe Acrobat and Reader, but has also announced an update for Flash Player that should be released on Thursday and will fix a zero-day flaw (CVE-2016-4117) that’s being actively exploited in attacks in the wild. What kind of attacks? Adobe didn’t say. But the vulnerability is considered to be critical, as successful exploitation could cause a crash and potentially allow an attacker to … More Continue reading 0day alert: Be ready to update Adobe Flash Player tomorrow

iOS zero-day breaks Apple’s iMessage encryption

A team of Johns Hopkins University researchers headed by computer science professor Matthew Green have discovered a zero-day flaw in Apple’s iOS encryption, which could allow attackers to decrypt intercepted iMessages. Not many details about the actual vulnerability have been shared, and won’t be until Apple patches the flaw. According to the Washington Post, the company said that the flaw has been partially fixed in iOS 9 (pushed out last fall), but will be completely … More Continue reading iOS zero-day breaks Apple’s iMessage encryption