Credit to Author: Paul Ducklin| Date: Tue, 25 Feb 2020 20:55:03 +0000
When a bug’s a zero-day that means it’s being actively exploited. So don’t delay, just patch today!<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/xrcwT2eXQRY” height=”1″ width=”1″ alt=””/>
Credit to Author: BrianKrebs| Date: Mon, 24 Feb 2020 17:13:11 +0000
Networking hardware vendor Zyxel today released an update to fix a critical flaw in many of its network attached storage (NAS) devices that can be used to remotely commandeer them. The patch comes 12 days after KrebsOnSecurity alerted the company that precise instructions for exploiting the vulnerability were being sold for $20,000 in the cybercrime underground. Based in Taiwan, Zyxel Communications Corp. (a.k.a “ZyXEL”) is a maker of networking devices, including Wi-Fi routers, NAS products and hardware firewalls. The company has roughly 1,500 employees and boasts some 100 million devices deployed worldwide. While in many respects the class of vulnerability addressed in this story is depressingly common among Internet of Things (IoT) devices, the flaw is notable because it has attracted the interest of groups specializing in deploying ransomware at scale.
Credit to Author: John E Dunn| Date: Thu, 09 Jan 2020 14:00:06 +0000
Firefox has issues an emergency 72.0.1 patch to fix a zero day vulnerability.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/8rtXfw6rWto” height=”1″ width=”1″ alt=””/>
Credit to Author: John E Dunn| Date: Thu, 12 Dec 2019 10:42:32 +0000
December 2019’s Patch Tuesday updates are, including a fix for the Windows flaw used in recently discovered WizardOpium attacks.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/PoQEqUB0h3I” height=”1″ width=”1″ alt=””/>
Credit to Author: Danny Bradbury| Date: Fri, 20 Sep 2019 12:22:50 +0000
A researcher has just published a zero-day security bug in one of the web’s most popular database administration software packages.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/XxpMh0dUMaQ” height=”1″ width=”1″ alt=””/>
Credit to Author: John E Dunn| Date: Thu, 12 Sep 2019 11:33:58 +0000
Sometimes, a Patch Tuesday update arrives with a bang that sends users scrambling for cover – September’s update earns that description.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/lRHTsM8cImQ” height=”1″ width=”1″ alt=””/>
Credit to Author: John E Dunn| Date: Tue, 03 Sep 2019 14:47:23 +0000
A sophisticated and sustained watering hole attack affecting iPhones may have targeted Windows and Android too.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/3wCw5XE352c” height=”1″ width=”1″ alt=””/>
Credit to Author: Thomas Reed| Date: Fri, 30 Aug 2019 17:40:24 +0000
Google announced late last night that hacked websites have been used to drop iPhone malware on unsuspecting users over a two-year period. Thomas Reed investigates.