An anonymous security researcher going by the name of SandboxEscaper today publicly shared a second zero-day exploit that can be used to bypass a recently patched elevation of privilege vulnerability in the Microsoft Windows operating system.SandboxEscaper is known for publicly dropping zero-day exploits for unpatched Windows vulnerabilities. In the past year, the hacker has … [Read more...] about Hacker Discloses Second Zero-Day to Bypass Patch for Windows EoP Flaw
Flaw
Nearly 1 Million Computers Still Vulnerable to “Wormable” BlueKeep RDP Flaw
Nearly 1 million Windows systems are still unpatched and have been found vulnerable to a recently disclosed critical, wormable, remote code execution vulnerability in the Windows Remote Desktop Protocol (RDP)—two weeks after Microsoft releases the security patch.If exploited, the vulnerability could allow an attacker to easily cause havoc around the world, potentially much … [Read more...] about Nearly 1 Million Computers Still Vulnerable to “Wormable” BlueKeep RDP Flaw
PoC Exploit For Unpatched Windows 10 Zero-Day Flaw Published Online
An anonymous hacker with an online alias "SandboxEscaper" today released proof-of-concept (PoC) exploit code for a new zero-day vulnerability affecting Windows 10 operating system—that's his/her 5th publicly disclosed Windows zero-day exploit [1, 2, 3] in less than a year.Published on GitHub, the new Windows 10 zero-day vulnerability is a privilege escalation issue that could … [Read more...] about PoC Exploit For Unpatched Windows 10 Zero-Day Flaw Published Online
Bluetooth Flaw Found in Google Titan Security Keys; Get Free Replacement
A team of security researchers at Microsoft discovered a potentially serious vulnerability in the Bluetooth-supported version of Google's Titan Security Keys that could not be patched with a software update.However, users do not need to worry as Google has announced to offer a free replacement for the affected Titan Security Key dongles.In a security advisory published … [Read more...] about Bluetooth Flaw Found in Google Titan Security Keys; Get Free Replacement
Microsoft Releases Patches For A Critical ‘Wormable Flaw’ and 78 Other Issues
It's Patch Tuesday—the day when Microsoft releases monthly security updates for its software.Microsoft has software updates to address a total of 79 CVE-listed vulnerabilities in its Windows operating systems and other products, including a critical wormable flaw that can propagate malware from computer to computer without requiring users' interaction.Out of 79 vulnerabilities, … [Read more...] about Microsoft Releases Patches For A Critical ‘Wormable Flaw’ and 78 Other Issues
Hackers Used WhatsApp 0-Day Flaw to Secretly Install Spyware On Phones
Whatsapp has recently patched a severe vulnerability that was being exploited by attackers to remotely install surveillance malware on a few "selected" smartphones by simply calling the targeted phone numbers over Whatsapp audio call.Discovered, weaponized and then sold by the Israeli company NSO Group that produces the most advanced mobile spyware on the planet, the WhatsApp … [Read more...] about Hackers Used WhatsApp 0-Day Flaw to Secretly Install Spyware On Phones
Unpatched Flaw in UC Browser Apps Could Let Hackers Launch Phishing Attacks
A bug hunter has discovered and publicly disclosed details of an unpatched browser address bar spoofing vulnerability that affects popular Chinese UC Browser and UC Browser Mini apps for Android.Developed by Alibaba-owned UCWeb, UC Browser is one of the most popular mobile browsers, specifically in China and India, with a massive user base of more than half a billion users … [Read more...] about Unpatched Flaw in UC Browser Apps Could Let Hackers Launch Phishing Attacks
Critical Flaw in Cisco Elastic Services Controller Allows Full System Takeover
Cisco has patched a critical flaw in its virtualized function automation tool, Cisco Elastic Services Controller. Source link … [Read more...] about Critical Flaw in Cisco Elastic Services Controller Allows Full System Takeover
Pre-Installed Software Flaw Exposes Most Dell Computers to Remote Hacking
If you use a Dell computer, then beware — hackers could compromise your system remotely.Bill Demirkapi, a 17-year-old independent security researcher, has discovered a critical remote code execution vulnerability in the Dell SupportAssist utility that comes pre-installed on most Dell computers.Dell SupportAssist, formerly known as Dell System Detect, checks the health of your … [Read more...] about Pre-Installed Software Flaw Exposes Most Dell Computers to Remote Hacking
Hackers Found Exploiting Oracle WebLogic RCE Flaw to Spread Ransomware
Taking advantage of newly disclosed and even patched vulnerabilities has become common among cybercriminals, which makes it one of the primary attack vectors for everyday-threats, like crypto-mining, phishing, and ransomware.As suspected, a recently-disclosed critical vulnerability in the widely used Oracle WebLogic Server has now been spotted actively being exploited to … [Read more...] about Hackers Found Exploiting Oracle WebLogic RCE Flaw to Spread Ransomware