This Week in Security: Android Bluetooth RCE, Windows VMs, and HTTPS Everywhere

Android has released it’s monthly round of security updates, and there is one patched bug in particular that’s very serious: CVE-2021-0316. Few further details are available, but a bit of sleuthing finds the code change that fixes this bug.

Fix potential OOB write in libbluetooth
Check event id if of
…read more

Continue reading This Week in Security: Android Bluetooth RCE, Windows VMs, and HTTPS Everywhere

Cybercriminals Ramp Up Exploits Against Serious Zyxel Flaw

More than 100,000 Zyxel networking products could be vulnerable to a hardcoded credential vulnerability (CVE-2020-29583) potentially allowing cybercriminal device takeover. Continue reading Cybercriminals Ramp Up Exploits Against Serious Zyxel Flaw

Zyxel’s Ridiculous Backdoor: Happy New Year, Now Patch Your Gear

Zyxel, maker of networking gear, “accidentally” introduced a backdoor into its latest firmware, giving hackers access to the networks of businesses and government agencies.
The post Zyxel’s Ridiculous Backdoor: Happy New Year, Now Patch Your Gear appe… Continue reading Zyxel’s Ridiculous Backdoor: Happy New Year, Now Patch Your Gear

Backdoor account found in 100,000+ Zyxel Firewalls, VPN Gateways

By Deeba Ahmed
Researchers have discovered a hard-coded admin-level backdoor account as a Zyxel firmware binary revealing username and password.
This is a post from HackRead.com Read the original post: Backdoor account found in 100,000+ Zyxel Firewalls… Continue reading Backdoor account found in 100,000+ Zyxel Firewalls, VPN Gateways

Report: Most Popular Home Routers Have ‘Critical’ Flaws

Common devices from Netgear, Linksys, D-Link and others contain serious security vulnerabilities that even updates don’t fix. Continue reading Report: Most Popular Home Routers Have ‘Critical’ Flaws

Report: Most Popular Home Routers Have ‘Critical’ Flaws

Common devices from Netgear, Linksys, D-Link and others contain serious security vulnerabilities that even updates don’t fix. Continue reading Report: Most Popular Home Routers Have ‘Critical’ Flaws

Zxyel Flaw Powers New Mirai IoT Botnet Strain

In February, hardware maker Zyxel fixed a zero-day vulnerability in its routers and VPN firewall products after KrebsOnSecurity told the company the flaw was being abused by attackers to break into devices. This week, security researchers said they spotted that same vulnerability being exploited by a new variant of Mirai, a malware strain that targets vulnerable Internet of Things (IoT) devices for use in large-scale attacks and as proxies for other cybercrime activity. Continue reading Zxyel Flaw Powers New Mirai IoT Botnet Strain