Most Orgs Would Take Security Bugs Over Ethical Hacking Help
A new survey suggests that security is becoming more important for enterprises, but they’re still falling back on old “security by obscurity” ways.
Want to know more about this topic or about us? Contact us!
A new survey suggests that security is becoming more important for enterprises, but they’re still falling back on old “security by obscurity” ways.
The vulnerability affects all unpatched Windows 10 versions following a messy Microsoft January update.
The researcher found that he could gain unauthorized camera access via a shared iCloud document that could also “hack every website you’ve ever visited.”
Companies must take more ‘innovative and proactive’ approaches to security in 2022 to combat threats that emerged last year, researchers said.
Meanwhile, Zerodium’s quest to buy VPN exploits is problematic, researchers said.
The security vulnerabilities bring the web behemoth up to 10 browser zero-days found so far this year.
The bug in Edge’s auto-translate could have let remote attackers pull off RCE on any foreign-language website just by sending a message with an XSS payload. Microsoft patched two bugs in its Chromium-based Edge browser last week, one of which could be used by an attacker to bypass security and . . . Read more
Experts from Intel, GitHub and KnowBe4 weigh in on what you need to succeed at security bug-hunting. Zero-day disclosures, those known bugs without a fix, can have potentially catastrophic results. One of the best ways to combat them is by discovering them before the bad guys do. Some of the . . . Read more
by Paul Ducklin We investigate whether AirDrop is really as dangerous as researchers claimed. We discuss the pestiferous problem of fake Linux bugs submitted as an academic exercise. We review the latest Sophos Ransomware Report and uncover uncomfortable truths about paying up. With Kimberly Truong, Doug Aamoth and Paul Ducklin. . . . Read more
The zero-day flaw research group has revised its disclosure of the technical details of vulnerabilities in the hopes of speeding up the release and adoption of fixes. Google Project Zero will now give organizations a 30-day grace period to patch zero-day flaws it discovers in a new disclosure policy revealed . . . Read more