ATENTIONβΌ New - CVE-2017-8777
π Read
via "National Vulnerability Database".
Open-Xchange GmbH OX Cloud Plugins 1.4.0 and earlier is affected by: Missing Authorization.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-8341
π Read
via "National Vulnerability Database".
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-8340
π Read
via "National Vulnerability Database".
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-6912
π Read
via "National Vulnerability Database".
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-5984
π Read
via "National Vulnerability Database".
In libavcodec in Libav 9.21, ff_h264_execute_ref_pic_marking() has a heap-based buffer over-read.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-5871
π Read
via "National Vulnerability Database".
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-5864
π Read
via "National Vulnerability Database".
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-5863
π Read
via "National Vulnerability Database".
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.π Read
via "National Vulnerability Database".
π΄ Alphabet's Chronicle Explores Code-Signing Abuse in the Wild π΄
π Read
via "Dark Reading: ".
A new analysis highlights the prevalence of malware signed by certificate authorities and the problems with trust-based security.π Read
via "Dark Reading: ".
Darkreading
Alphabet's Chronicle Explores Code-Signing Abuse in the Wild
A new analysis highlights the prevalence of malware signed by certificate authorities and the problems with trust-based security.
β The city of Baltimore is being held hostage by ransomware β
π Read
via "Naked Security".
The mayor said noβfor nowβto paying 13 Bitcoins to (purportedly) unlock all seized systems. Manual rebuilding could take months.π Read
via "Naked Security".
Naked Security
The city of Baltimore is being held hostage by ransomware
The mayor said noβfor nowβto paying 13 Bitcoins to (purportedly) unlock all seized systems. Manual rebuilding could take months.
β Mozilla fixes bugs, improves privacy in latest Firefox release β
π Read
via "Naked Security".
Mozilla rolled out version 67 of its Firefox browser this week, fixing some security bugs and introducing a host of privacy features.π Read
via "Naked Security".
Naked Security
Mozilla fixes bugs, improves privacy in latest Firefox release
Mozilla rolled out version 67 of its Firefox browser this week, fixing some security bugs and introducing a host of privacy features.
β Tor Browser for Android 8.5 offers mobile users privacy boost β
π Read
via "Naked Security".
After nine months of alpha testing, a stable release of the Tor browser for Android can now be downloaded from Googleβs Play store or direct from the Projectβs website.π Read
via "Naked Security".
Naked Security
Tor Browser for Android 8.5 offers mobile users privacy boost
After nine months of alpha testing, a stable release of the Tor browser for Android can now be downloaded from Googleβs Play store or direct from the Projectβs website.
β Google stored some passwords in plain text for 14 years β
π Read
via "Naked Security".
Nobody got at the subset of G Suite passwords, Google said, apologizing and saying that it's working to ensure this is an isolated incident.π Read
via "Naked Security".
Naked Security
Google stored some passwords in plaintext for 14 years
Nobody got at the subset of G Suite passwords, Google said, apologizing and saying that itβs working to ensure this is an isolated incident.
β Soaring Cryptocurrency Prices Draw Malicious New Onslaught of Apps, Malware β
π Read
via "Threatpost".
As Bitcoin prices surge, so too are malicious apps, malware-ridden scams and cryptojacking attacks looking to profit from the cryptocurrency industry.π Read
via "Threatpost".
Threat Post
Soaring Cryptocurrency Prices Draw Malicious New Onslaught of Apps, Malware
As Bitcoin prices surge, so too are malicious apps, malware-ridden scams and cryptojacking attacks looking to profit from the cryptocurrency industry.
π΄ Incident Response: 3 Easy Traps & How to Avoid Them π΄
π Read
via "Dark Reading: ".
Sage legal advice about navigating a data breach from a troubleshooting cybersecurity outside counsel.π Read
via "Dark Reading: ".
Darkreading
Incident Response: 3 Easy Traps & How to Avoid Them
Sage legal advice about navigating a data breach from a troubleshooting cybersecurity outside counsel.
β SandboxEscaper Drops Three More Windows Exploits, IE Zero-Day β
π Read
via "Threatpost".
As promised, developer SandboxEscaper has dropped exploit code for four more bugs, on the heels of releasing a Windows zero-day yesterday.π Read
via "Threatpost".
Threat Post
SandboxEscaper Drops Three More Windows Exploits, IE Zero-Day
As promised, developer SandboxEscaper has dropped exploit code for four more bugs, on the heels of releasing a Windows zero day yesterday.
ATENTIONβΌ New - CVE-2018-15664
π Read
via "National Vulnerability Database".
In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-5213
π Read
via "National Vulnerability Database".
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-5212
π Read
via "National Vulnerability Database".
Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-5211
π Read
via "National Vulnerability Database".
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-5210
π Read
via "National Vulnerability Database".
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.π Read
via "National Vulnerability Database".