Microsoft rushes out fix for Internet Explorer zero-day

Microsoft has rushed to patch two flaws affecting IE versions 9 to 11, one of which the company says is being exploited in real attacks. Continue reading Microsoft rushes out fix for Internet Explorer zero-day

[Unpatched] Critical 0-Day RCE Exploit for vBulletin Forum Disclosed Publicly

An anonymous hacker today publicly revealed details and proof-of-concept exploit code for an unpatched, critical zero-day remote code execution vulnerability in vBulletin—one of the widely used internet forum software, The Hacker News has learned.

One… Continue reading [Unpatched] Critical 0-Day RCE Exploit for vBulletin Forum Disclosed Publicly

Exploit Reseller Offering Up To $2.5 Million For Android Zero-Days

Well, there’s some good news for hackers and vulnerability hunters, though terrible news for Google, Android device manufacturers, and their billions of users worldwide.

The zero-day buying and selling industry has recently taken a shift towards Andro… Continue reading Exploit Reseller Offering Up To $2.5 Million For Android Zero-Days

Google Uncovers How Just Visiting Some Sites Were Secretly Hacking iPhones For Years

Beware Apple users!

Your iPhone can be hacked just by visiting an innocent-looking website, confirms a terrifying report Google researchers released earlier today.

The story goes back to a widespread iPhone hacking campaign that cybersecurity researc… Continue reading Google Uncovers How Just Visiting Some Sites Were Secretly Hacking iPhones For Years

Firefox 67.0.4 Released — Mozilla Patches Second 0-Day Flaw This Week

Okay, folks, it’s time to update your Firefox web browser once again—yes, for the second time this week.

After patching a critical actively-exploited vulnerability in Firefox 67.0.3 earlier this week, Mozilla is now warning millions of its users about… Continue reading Firefox 67.0.4 Released — Mozilla Patches Second 0-Day Flaw This Week

Tor Browser 8.5.2 Released — Update to Fix Critical Firefox Vulnerability

Important Update (21 June 2019) ➤ The Tor Project on Friday released second update (Tor Browser 8.5.3) for its privacy web-browser that patches the another Firefox zero-day vulnerability patched this week.

Following the latest critical update for Fire… Continue reading Tor Browser 8.5.2 Released — Update to Fix Critical Firefox Vulnerability

New Critical Oracle WebLogic Flaw Under Active Attack — Patch Now

Oracle has released an out-of-band emergency software update to patch a newly discovered critical vulnerability in the WebLogic Server.

According to Oracle, the vulnerability—which can be identified as CVE-2019-2729 and has a CVSS score of 9.8 out of … Continue reading New Critical Oracle WebLogic Flaw Under Active Attack — Patch Now

Microsoft’s battle with SandboxEscaper zero days turns into grim Groundhog Day

Why is SandboxEscaper releasing vulnerabilities in such an irresponsible way? It matters not – Microsoft must patch what’s in front of it whatever the backstory. Continue reading Microsoft’s battle with SandboxEscaper zero days turns into grim Groundhog Day

Update: Hacker Disclosed 4 New Microsoft Zero-Day Exploits in Last 24 Hours

Less than 24 hours after publicly disclosing an unpatched zero-day vulnerability in Windows 10, the anonymous hacker going by online alias “SandboxEscaper” has now dropped new exploits for two more unpatched Microsoft zero-day vulnerabilities.

The two… Continue reading Update: Hacker Disclosed 4 New Microsoft Zero-Day Exploits in Last 24 Hours