Vulnerability
Discover expert analysis on vulnerability with news, features and insights from the team at IT Pro.
-
'Vast majority' of mobile apps found leaking AWS credentials are on iOS
News Only 2% of the apps that were found to be leaking hard-coded AWS credentials were on the Android platform, research has shown
By Connor Jones Published
News -
US government set to outlaw leaky software in the military
News The 'secure-by-design' approach has been met broadly positively by experts and will aim to prevent high-profile security incidents
By Connor Jones Published
News -
Apple patches 'superpower' zero-days affecting iPhones, iPads, and Macs
News The RCE and kernel-level bugs may have been actively exploited and could give high-level privileges to attackers
By Connor Jones Published
News -
SpaceX bug bounty offers up to $25,000 per Starlink exploit
News The spacecraft manufacturer has offered white hats immunity to exploit a wide range of Starlink systems, with a dedicated report page
By Rory Bathgate Published
News -
Zoom patches privilege escalation flaw for macOS users
News Threat actors were able to use the application’s updater to distribute malicious files at superuser level
By Rory Bathgate Published
News -
Dogwalk RCE variant among 121 vulnerabilities fixed in Microsoft's August Patch Tuesday
News The second-biggest security update released by Microsoft this year featured 17 critical-rated RCEs and privilege escalation bugs
By Connor Jones Published
News -
Over 200,000 DrayTek routers vulnerable to total device takeover
News The routers are popular with small and medium businesses, but are easily exploitable by threat actors seeking to steal data or launch ransomware
By Rory Bathgate Published
News -
Microsoft warns hackers turning to IIS exploits to create backdoors in businesses
News Internet information service modules formed part of the attack of Microsoft's own Exchange servers earlier this year
By Connor Jones Published
News -
Actively exploited zero-day and four 'critical' vulnerabilities fixed in Microsoft's July Patch Tuesday
News The month's list of 84 bug fixes has been branded "boring" by some experts but should be welcome news to security personnel
By Connor Jones Published
News -
HackerOne employee fired for using position to steal bug bounties
News The threat actor was identified by their duplicate data, which they were trying to pass off as their own for financial gain
By Rory Bathgate Published
News -
LockBit 2.0 ransomware disguised as PDFs distributed in email attacks
News Researchers have urged vigilance over compressed attachments sent under false pretenses
By Rory Bathgate Published
News -
Proofpoint details 'dangerous' ransomware flaw in SharePoint and OneDrive
News Functionality allows ransomware to encrypt files stored on SharePoint and OneDrive to make them potentially unrecoverable, vendor says
By Daniel Todd Published
News