Independent

ComputerWorldIndependent

Duck! Windows and Office patches are coming

Credit to Author: Woody Leonhard| Date: Tue, 10 Oct 2017 04:30:00 -0700

If you’re running Windows, do yourself a favor and put Automatic Update on a temporary hold. Then wait and see if anything comes bursting apart at the seams.

Last month, there was good reason to install specific patches shortly after they were released — at least if you couldn’t train yourself to avoid the “Enable Editing” button in Word. But by and large, if you could avoid that button, there were myriad reasons why waiting a bit before installing the September patches paid off.

To read this article in full or to leave a comment, please click here

Read More
IndependentSecuriteam

SSD Advisory – QNAP HelpDesk SQL Injection

Credit to Author: SSD / Maor Schwartz| Date: Mon, 09 Oct 2017 14:26:28 +0000

Vulnerability Summary The following advisory describes a SQL injection found in QTS Helpdesk versions 1.1.12 and earlier. QNAP helpdesk: “Starting from QTS 4.2.2 you can use the built-in Helpdesk app to directly submit help requests to QNAP from your NAS. To do so, ensure your NAS can reach the Internet, open Helpdesk from the App … Continue reading SSD Advisory – QNAP HelpDesk SQL Injection

Read More
IndependentSecuriteam

SSD Advisory – PHP Melody Multiple Vulnerabilities

Credit to Author: SSD / Maor Schwartz| Date: Mon, 09 Oct 2017 13:03:25 +0000

Vulnerabilities Summary The following advisory describes three (3) vulnerabilities found in PHP Melody version 2.7.3. PHP Melody is a “self-hosted Video CMS which evolved over the last 9 years. SEO optimization, unbeaten security and speed are advantages you no longer have to compromise on. A truly great CMS should help you save time and make … Continue reading SSD Advisory – PHP Melody Multiple Vulnerabilities

Read More