A researcher has published a method by which a local admin can hijack any other Windows sessions without the need for credentials.
Browsing Author: Michael Mimoso
Researchers at SEC Consult disclosed a command injection vulnerability in Ubiquiti Networks gear for ISPs after a private disclosure to the vendor in November went unresolved.
Security tools that proxy and inspect HTTPS traffic create a blindspot for network administrators trying to determine whether communication between clients and servers is secure.
Two recent fileless malware campaigns targeting financial institutions, government agencies and other enterprises have been linked to the same attack group.
Intel and Microsoft announced bug bounties, paying $30,000 and $15,000 respectively for critical vulnerabilities.
The Department of Justice indicted four individuals, including two Russian FSB officers, for their roles in the Yahoo breach.
JSON libraries using the JWE specification to create, sign and encrypt access tokens have been patched against an attack that allows for the recovery of a private key.
Microsoft released 18 security bulletins, eight rated critical. The company also patched publicly disclosed vulnerabilities that surfaced since last month’s postponement of Patch Tuesday.
The recently patched REST API Endpoint vulnerability in WordPress could be leveraged to pull off stored cross-site scripting attacks.
Researchers at Check Point found and remediated malware on 38 Android devices that were infected somewhere along the supply chain.