FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

β€œVMware Spring Cloud Function” Java bug gives instant remote code execution – update now!

By Paul Ducklin β€” March 30th 2022 at 20:38
Easy unauthenticated remote code execution - PoC code already out

☐ β˜† βœ‡ Naked Security

Google Chrome patches mysterious new zero-day bug – update now

By Paul Ducklin β€” March 28th 2022 at 14:18
CVE-2022-1096 - another mystery in-the-wild 0-day in Chrome... check your version now!

☐ β˜† βœ‡ Naked Security

OpenSSL patches infinite-loop DoS bug in certificate verification

By Paul Ducklin β€” March 18th 2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!

☐ β˜† βœ‡ Naked Security

S3 Ep73: Ransomware with a difference, dirty Linux pipes, and much more [Podcast + Transcript]

By Paul Ducklin β€” March 10th 2022 at 19:37
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

β€œDirty Pipe” Linux kernel bug lets anyone write to any file

By Paul Ducklin β€” March 8th 2022 at 19:37
Even read-only files can be written to, leading to a dangerously general purpose elevation-of-privilege attack.

pipe-1200

☐ β˜† βœ‡ Naked Security

WordPress backup plugin maker Updraft says β€œYou should update”…

By Paul Ducklin β€” February 22nd 2022 at 17:26
A straight-talking bug report written in plain English by an actual expert - there's a teachable moment in this cybersecurity story!

☐ β˜† βœ‡ Naked Security

Google announces zero-day in Chrome browser – update now!

By Paul Ducklin β€” February 15th 2022 at 19:17
Zero-day buses: none for a while, then three at once. Here's Google joining Apple and Adobe in "zero-day week"

☐ β˜† βœ‡ Naked Security

Adobe fixes zero-day exploit in e-commerce code: update now!

By Paul Ducklin β€” February 14th 2022 at 22:38
There's a remote code execution hole in Adobe e-commerce products - and cybercrooks are already exploiting it.

☐ β˜† βœ‡ Naked Security

Apple zero-day drama for Macs, iPhones and iPads – patch now!

By Paul Ducklin β€” February 11th 2022 at 14:25
Sudden update! Zero-day browser hole! Drive-by malware danger! Patch Apple laptops and phones now...

apple-1200

☐ β˜† βœ‡ Naked Security

Linux kernel patches β€œperformance can be harmful” bug in video driver

By Paul Ducklin β€” February 1st 2022 at 19:59
This bug is fiendishly hard to exploit - but if you patch, it won't be there to exploit at all.

☐ β˜† βœ‡ Naked Security

Wormable Windows HTTP hole – what you need to know

By Paul Ducklin β€” January 12th 2022 at 16:24
One bug in the January 2022 Patch Tuesday list is getting lots of attention: "HTTP Protocol Stack Remote Code Execution Vulnerability".

❌