Security

FortinetSecurity

Multiple Plone Cross-Site Scripting Vulnerabilities

Credit to Author: Zhouyuan Yang| Date: Tue, 05 Dec 2017 13:30:59 +0000

Plone is a free and open source content management system, and is ranked among the top 2% of all open source projects worldwide. More than 350 solution providers in more than 100 countries currently support it. The project has been actively developed since 2001, is available in more than 40 languages, and has the best security track record of any major CMS. The users (https://plone.com/about/they-use-plone) include the Federal Bureau of Investigation (FBI), the Central Intelligence Agency (CIA), the Intellectual Property Rights Center, and so on. Earlier…

Read More
SecurityTrendMicro

2018’s Biggest Attacks Will Stem from Known Vulnerabilities

Credit to Author: Martin Roesler (Director, Threat Research)| Date: Tue, 05 Dec 2017 13:00:12 +0000

Trend Micro just released its annual predictions report for next year. In this, we outline 8 ways the threat landscape is expected to evolve in 2018. While the predictions touch on a wide range of issues – from IoT to cyberpropaganda – the underlying theme is this, 2018’s biggest attacks will stem from known vulnerabilities….

Read More
MalwareBytesSecurity

Seamless campaign serves RIG EK via Punycode

Credit to Author: Jérôme Segura| Date: Mon, 04 Dec 2017 22:48:49 +0000

The most prolific gate to the RIG exploit kit is coming in a different flavor. The Seamless campaign is now using a domain name with foreign characters translated by Punycode.

Categories:

Tags:

(Read more…)

The post Seamless campaign serves RIG EK via Punycode appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

A week in security (November 27 – December 03)

Credit to Author: Malwarebytes Labs| Date: Mon, 04 Dec 2017 18:30:33 +0000

A compilation of notable security news and blog posts from Monday, November 27 to Sunday, December 3, including smart toys, another security breach, ransomware, and things to ponder when shopping for gifts this Christmas season.

Categories:

Tags:

(Read more…)

The post A week in security (November 27 – December 03) appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

Yet another flaw in Apple’s “iamroot” bug fix

Credit to Author: Thomas Reed| Date: Mon, 04 Dec 2017 17:05:12 +0000

Flaws in Apple’s response to the “iamroot” vulnerability show that some systems can remain vulnerable even after applying the patch.

Categories:

Tags:

(Read more…)

The post Yet another flaw in Apple’s “iamroot” bug fix appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

An IRISSCON 2017 roundup

Credit to Author: Christopher Boyd| Date: Thu, 30 Nov 2017 13:00:25 +0000

Last week, researcher Chris Boyd gave a talk at Ireland’s longest running security event: IRISSCON. This post contains links to many of the top-rated talks from the event, along with links to additional content.

Categories:

Tags:

(Read more…)

The post An IRISSCON 2017 roundup appeared first on Malwarebytes Labs.

Read More