Pegasus spyware and how it exploited a WebP vulnerability

Categories: Android

Categories: Apple

Categories: Exploits and vulnerabilities

Tags: Pegasus

Tags: spyware

Tags: nso

Tags: webp

Tags: libwebp

Tags: buffer overflow

The company behind the infamous Pegasus spyware used a vulnerability in almost every browser to plant their malware on victim’s devices.

(Read more…)

The post Pegasus spyware and how it exploited a WebP vulnerability appeared first on Malwarebytes Labs.

Read more

Update Chrome now! Google patches critical vulnerability being exploited in the wild

Categories: Exploits and vulnerabilities

Categories: News

Tags: Google

Tags: Chrome

Tags: CVE-2023-4863

Tags: WebP

Tags: buffer overflow

Tags: 116.0.5845.187/.188

Chrome users are being urged to patch a critical vulnerability for which an exploit is available.

(Read more…)

The post Update Chrome now! Google patches critical vulnerability being exploited in the wild appeared first on Malwarebytes Labs.

Read more

Two Apple issues added by CISA to its catalog of known exploited vulnerabilities

Categories: Exploits and vulnerabilities

Categories: News

Tags: Blastpass

Tags: citizenlab

Tags: pegasus

Tags: nso

Tags: cisa

Tags: apple

Tags: cve-2023-41064

Tags: cve-2023-41061

Tags: buffer overflow

CISA has added two recently discovered Apple vulnerabilities to its catalog of known exploited vulnerabilities.

(Read more…)

The post Two Apple issues added by CISA to its catalog of known exploited vulnerabilities appeared first on Malwarebytes Labs.

Read more

Windows 11 is showing its first signs of Rust

Categories: News

Tags: Windows 11

Tags: OS

Tags: operating system

Tags: programming language

Tags: rust

Tags: C

Tags: C++

Tags: kernel

Tags: buffer overflow

We take a look at the slow introduction of programming language Rust into the Windows 11 kernel in an effort to make it more memory safe.

(Read more…)

The post Windows 11 is showing its first signs of Rust appeared first on Malwarebytes Labs.

Read more

Explained: Fuzzing for security

Categories: Explained

Categories: News

Tags: Fuzzing

Tags: fuzz testing

Tags: memory leaks

Tags: runtime errors

Tags: race conditions

Tags: control flow error

Tags: memory allocation

Tags: buffer overflow

Fuzzing is an automated software testing method that uses a wide range of invalid and unexpected data as input to find flaws.

(Read more…)

The post Explained: Fuzzing for security appeared first on Malwarebytes Labs.

Read more

SSD Advisory – CloudMe Unauthenticated Remote Buffer Overflow

Credit to Author: SSD / Noam Rathaus| Date: Sun, 11 Feb 2018 07:06:24 +0000

The following advisory describes one (1) vulnerability found in CloudMe. CloudMe is “a file storage service operated by CloudMe AB that offers cloud storage, file synchronization and client software. It features a blue folder that appears on all devices with the same content, all files are synchronized between devices.” The vulnerability found is a buffer … Continue reading SSD Advisory – CloudMe Unauthenticated Remote Buffer Overflow

Read more

SSD Advisory – Python Bytecode Disassembler and Decompiler (pycdc) Multiple Vulnerabilities

Credit to Author: SSD / Maor Schwartz| Date: Sun, 04 Feb 2018 12:03:20 +0000

Vulnerabilities summary The following advisory describes 12 (twelve) vulnerabilities found in Python Bytecode Disassembler and Decompiler (pycdc). Python Bytecode Disassembler and Decompiler (pycdc) “aims to translate compiled Python byte-code back into valid and human-readable Python source code. While other projects have achieved this with varied success, Decompyle++ is unique in that it seeks to support … Continue reading SSD Advisory – Python Bytecode Disassembler and Decompiler (pycdc) Multiple Vulnerabilities

Read more

SSD Advisory – Kingsoft Antivirus/Internet Security 9+ Privilege Escalation

Credit to Author: SSD / Maor Schwartz| Date: Tue, 26 Dec 2017 10:03:53 +0000

Vulnerability Summary The following advisory describes a kernel stack buffer overflow that leads to privilege escalation found in Kingsoft Antivirus/Internet Security 9+. Kingsoft Antivirus “provides effective and efficient protection solution at no cost to users. It applies cloud security technology to monitor, scan and protect your systems without any worrying. The comprehensive defender and anti-virus … Continue reading SSD Advisory – Kingsoft Antivirus/Internet Security 9+ Privilege Escalation

Read more