Vulnerability
Discover expert analysis on vulnerability with news, features and insights from the team at IT Pro.
-
OpenSSL 3.0 vulnerability: Patch released for security scare
News The severity has been downgraded from 'critical' to 'high' and comparisons to Heartbleed have been quashed
By Connor Jones Published
News -
Major security exploits expected to rise before New Year
News Supply chain attacks are also expected to increase, along with affiliate programmes becoming more popular
By Zach Marzouk Published
News -
Second-ever OpenSSL critical vulnerability teased, 10 years after Heartbleed
News All OpenSSL versions beyond 3.0 are at risk, with more details due to be released alongside a patch on 1 November
By Rory Bathgate Published
News -
Apple patches actively exploited iPhone, iPad zero-day and 18 other security flaws
News The out-of-bounds write error is the eighth actively exploited zero-day impacting Apple hardware this year and could facilitate kernel-level code execution
By Rory Bathgate Published
News -
Undetectable PowerShell backdoor discovered hiding as Windows update
News SafeBreach researchers identified the backdoor, which they say went undetected on all major antivirus programs
By Rory Bathgate Published
News -
Office 365's encryption feature can be easily hacked, warns WithSecure
News Researchers advise enterprises to move away from Office 365 Message Encryption, claiming its messages can be decrypted without a key
By Rory Bathgate Published
News -
Fortinet reiterates call to mitigate against active zero-day, as customers delay fixes
News A large number of customers have yet to apply mitigations necessary to avoid the critical vulnerability
By Rory Bathgate Published
News -
Microsoft still searching for zero-day fixes following Patch Tuesday
News ProxyNotShell remains unaddressed even as Microsoft fixes several critical flaws in its monthly package of security patches
By Rory Bathgate Published
News -
Boeing 737 MAX: You can no longer escape liability due to poor code
Analysis Known vulnerabilities in Boeing’s flight software led to two fatal crashes, as well as a landmark decision with major ramifications for software development
By Rois Ni Thuama Published
Analysis -
Microsoft's third mitigation update for Exchange Server zero-day exploit bypassed within hours
News The string of problematic temporary fixes for ‘ProxyNotShell’ grows longer after a 'confusing' and 'atypical' week-long vulnerability disclosure process
By Connor Jones Published
News -
CISA issues fresh orders to polish security vulnerability detection in federal agencies
News The move marks the latest step in the cyber security authority's ongoing ambition to minimise the government's exposure to attacks
By Praharsha Anand Published
News -
US military contractor hacked through Microsoft Exchange vulnerabilities, custom exfiltration tools
News In a joint advisory, US security groups have warned the prolonged campaign showed new strategies in play, with the vector still unknown
By Rory Bathgate Published
News