Atlassian reset user passwords for its group chat service HipChat on Monday following an incident that may have resulted in unauthorized access to a server used by the service.
No Fix for SquirrelMail Remote Code Execution Vulnerability
SquirrelMail suffers from a remote code execution vulnerability that could let attackers execute arbitrary commands on the target and compromise the remote system.
NSA’s DoublePulsar Kernel Exploit In Use Internet-Wide
Scans show tens of thousands of Windows servers infected with the DoublePulsar kernel exploit leaked by the ShadowBrokers two weeks ago.
Mirai and Hajime Locked Into IoT Botnet Battle
A white hat hacker is believed responsible for the Hajime IoT botnet because its main objective appears to be to secure IoT devices vulnerable to the notorious Mirai malware.
Threatpost News Wrap, April 21, 2017
Last Friday’s ShadowBrokers dump, Microsoft ditching passwords, and a new car dongle hack are all discussed.
Skype Fixes ‘SPYKE’ Credential Phishing Remote Execution Bug
Microsoft fixed a bug in Skype last month that could have allowed an attacker to execute code on the system it was running on, phish Skype credentials and crash the application.
Drupal Closes Access Bypass Vulnerability in Core Engine
Drupal released a point update for its core engine to patch a critical access bypass vulnerability.
Stuxnet LNK Exploits Still Widely Circulated
Endpoints are still encountering exploits for the LNK vulnerability, one of the principal infection mechanisms used by the Stuxnet worm.
20 Linksys Router Models Vulnerable To Attack
Researchers say more than 100,000 Linksys routers in use today could be vulnerable to 10 flaws found in 20 separate router models made by the company.
Google Fixes Unicode Phishing Vulnerability in Chrome 58, Firefox Standing Pat
Google fixed a vulnerability that could’ve let an attacker carry out phishing attacks with Unicode domains in Chrome but Mozilla is holding off – for now.