Author: admin

MicrosoftSecurity

Sharing research and discoveries at PWN2OWN

Credit to Author: Windows Defender Research| Date: Wed, 14 Mar 2018 23:58:49 +0000

The annual PWN2OWN exploit contest at the CanSecWest conference in Vancouver, British Columbia, Canada, brings together some of the top security talent from across the globe in a friendly competition. For the participants, these events are a platform to demonstrate world-class skills and vie for significant cash prizes. For companies like Microsoft, where we have

Read more

Read More
SecurityTrendMicro

A View of Upcoming Threat Coverage from Pwn2Own 2018

Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Wed, 14 Mar 2018 21:18:38 +0000

This blog will be updated throughout the competition so keep tracking for the latest updates on upcoming threat coverage! St. Patrick’s Day is coming up later this week, but the contestants at Pwn2Own 2018 will need more than luck on their side. They will need to dive into their expert hacking skills in the hopes…

The post A View of Upcoming Threat Coverage from Pwn2Own 2018 appeared first on .

Read More
ComputerWorldIndependent

Massive March Patch Tuesday relaxes antivirus restrictions, but there are problems

Credit to Author: Woody Leonhard| Date: Wed, 14 Mar 2018 06:55:00 -0700

On a scale from 1 to 10, Microsoft in March has ratcheted the patching pace up to 11. The good news is that there are no known exploits for any of the “Critical” rated security holes. (Worth repeating: There are still no known exploits for Meltdown or Spectre.) The bad news? Reports of another forced upgrade to Win10 Fall Creators Update. Still waiting for confirmation on that one.

By the numbers

As usual, Martin Binkmann on ghacks.net, has the best summary:

To read this article in full, please click here

Read More
IndependentSecuriteam

SSD Advisory – AppWeb Authentication Bypass (Digest, Basic and Forms)

Credit to Author: SSD / Noam Rathaus| Date: Wed, 14 Mar 2018 19:01:53 +0000

Vulnerability Summary A critical vulnerability in the EmbedThis HTTP library, and Appweb versions 5.5.x, 6.x, and 7.x including the latest version present in the git repository. In detail, due to a logic flaw, with a forged HTTP request it is possible to bypass the authentication for form and digest login types. Confirmed Vulnerable Appweb version … Continue reading SSD Advisory – AppWeb Authentication Bypass (Digest, Basic and Forms)

Read More
IndependentSecuriteam

SSD Advisory – VK Messenger (VKontakte) vk:// URI Handler Commands Execution

Credit to Author: SSD / Noam Rathaus| Date: Sun, 11 Mar 2018 10:51:34 +0000

Vulnerability Summary The following describes a vulnerability in VK Messenger that is triggered via the exploitation of improperly handled URI. VK (VKontakte; [..], meaning InContact) is “an online social media and social networking service. It is available in several languages. VK allows users to message each other publicly or privately, to create groups, public pages … Continue reading SSD Advisory – VK Messenger (VKontakte) vk:// URI Handler Commands Execution

Read More