Zero-Day News, Articles and Updates

Microsoft Patch Tuesday: Nearly 50 patches, most for privilege escalation

Microsoft patched nearly 50 vulnerabilities this month, including patches for an Adobe Flash Player zero-day vulnerability that was announced earlier this month.

App zero-day flaw exploited to fool users into malicious downloads

Attackers were found exploiting a zero-day Telegram app vulnerability in order to make the names and extensions of malicious files appear more legitimate, in hopes that users who received these files would more willingly open them.

Attackers exploit critical Adobe Flash Player zero-day bug; no patch yet

Adobe Systems says it plans to address a critical zero-day vulnerability in Flash Player that a researcher asserts is being actively exploited in the wild to attack South Koreans conducting research on North Korea.

Huawei router vulnerability exploited, most are unlikely to be patched

An amateur hacker who has titled himself 'Nexus Zeta' has managed to exploit the Huawei home router HG532 by finding all the necessary information on online forums just a few days before carrying out the attack.

macOS Zero Day details exposed by researcher

An independent security researcher called Siguza revealed a local privilege escalation Zero Day in macOS that can be exploited by any unprivileged user.

Symantec endpoint zero-day unpatched for months

A vulnerability in Symantec endpoint clients remains unpatched months after disclosure, according to security researchers.

Zero day Windows SMB network file sharing bug may lead to DoS and BSOD

Admins must wait until Patch Tuesday for Microsoft to fix a memory corruption bug that could enable an attacker to leverage SMB to crash computers.

Passwords begone: two LastPass vulns found and promptly fixed, update now!

Two security vulnerabilities have been found and fixed in password manager LastPass. One by prolific security-vulnerability finder Tavis Ormandy, and the other by Mathias Karlsson of Detectify Labs.

Neutrino EK adopts new exploit after open source POC release

The Neutrino exploit kit (EK) added a former Internet Explorer zero-day vulnerability to its arsenal.

ICYMI: CEO Sacked; MS Zero-day; Passwords dropped; Ransomware wild, charging hack

The latest In Case You Missed It (ICYMI) looks at CEO whaling victim; Unpatched zero-day; Passwords dropped; Self-propagating ransomware; USB charging hack

Zero-day affects Linux computers—and Android devices?

A zero-day bug in version 3.8 of Linux can potentially affect millions of Linux computers and servers as well as 66 percent of Android devices.

Cyber-security firm offers £645K (US$1 million) for iOS 9 jailbreak and vulnerabilities

Zerodium is offering up to £1.9 million for vulnerabilities and a jail break of iOS 9.

Unpatched 0-day threatens Apple Mac users

OS X flaw is exposed by teenage Italian security researcher without warning Apple - reigniting the debate about 'irresponsible' bug disclosure.

Zero-day exploit hits fully patched Macs

OS X 10.10 has a vulnerability that allows hackers to install malware without system passwords

Apple App Store and iTunes buyers hit by zero-day

A zero-day flaw in Apple's online AppStore and iTunes store reportedly allows attackers to hijack users' purchasing sessions, buy and download any app or movie they want, then charge it to the original user.

Update: Jeep taken over from 10 miles away via in-car entertainment system

Car hack exploit could enable criminals could take control of Jeep Cherokee over the internet

Google slams US cyber-rules that hit UK student's research

Google has warned that planned US curbs on exporting 'intrusion software' - intended to limit the sale of zero-days by organisations like Hacking Team - could be a boon for hackers making "billions ...less secure".

Updated: Facebook CSO calls time on Flash after Hacking Team breach

New cyber-attacks by Chinese and others criminals are exploiting the Adobe Flash zero-days leaked through the recent Hacking Team breach - prompting calls for Flash to be "put out to pasture".

Time to abandon Flash? Hit by zero-day once again

Security industry calls on organisations to ditch vulnerable browser plug-in as yet another zero-day flaw hits flash

Duqu2.0 knocks Kaspersky and security peers for six

The news that Kaspersky Lab was hit by a "next-generation" malware attack is an indication of both how far we have come in cyber-warfare and how much further we still have to go.

Venom vulnerability: toxic threat or hissing hyperbole?

Anyone reading the news headlines on the Venom flaw over the last 24 hours might be forgiven for thinking that the sky, or at least the cloud, is falling down.

'Venom' VM zero-day draws comparisons with Heartbleed

CrowdStrike security researchers have discovered a zero-day affecting virtual machines, dubbed 'Venom', which could allow an attacker to "escape out of the virtual machine and execute code on the host with full privileges", thus putting data centres potentially in danger.

Android zero-day opens phones up to drive-by-downloads

A new zero-day flaw affecting all versions of Google's Android operating system could be exploited by hackers looking to steal data or take control of the mobile device.

APT gang caught exploiting Flash and Windows zero-days

Cyber-security firm FireEye details zero-day exploits perpetrated by 'nation-state' sponsored threat actors.

Under-fire Google tweaks bug disclosure policy

After stinging criticism from Microsoft and others over how and when it reported zero-day flaws, Google has changed its vulnerability disclosure policy.

ICYMI: EU data protection, iPhone spyware and Flash zero-days

The latest ICYMI column looks at the biggest stories on SC this week, including worrying news on EU data protection laws, claims of iPhone spyware and new Flash Player zero-days.

Adobe suffers second zero-day in 24 hours

Adobe has been hit by two zero-day flaws in the space of 24 hours, raising questions over the safety of its Flash Player platform which is being heavily targeted by cyber-criminals.