Oracle released a record 299 patches, including a fix for a Solaris vulnerability disclosed by the ShadowBrokers, and another for the recently disclosed Apache Struts 2 flaw.
Patched Flaw in Bosch Diagnostic Dongle Allowed Researchers to Shut Off Engine
Two vulnerabilities were identified in Bosch’s Drivelog Connect OBD-II dongle and smartphone app that allowed researchers to shut off the engine of a vehicle.
VMware Fixes Critical RCE in vCenter Server
VMware patched a critical vulnerability in its vCenter Server platform late last week that could have let an attacker execute arbitrary code in some scenarios.
ShadowBrokers’ Windows Zero-Days Already Patched
Microsoft eased some anxiety over the latest ShadowBrokers dump of Windows zero days with news most of the vulnerabilities had already been patched.
Exploit Kit Activity Quiets, But Is Far From Silent
Here are the exploit kits to watch for over the next three to six months.
Stories From Two Years in an IoT Honeypot
A researcher at this year’s Security Analyst Summit staged a series of honeypots at his friends’ houses to record IoT traffic, exploit attempts and other statistics.
Threatpost News Wrap, April 14, 2017
Mike Mimoso, Tom Spring, and Chris Brook recap Infiltrate Con in Miami last week, and Kaspersky Lab’s Security Analyst Summit in St. Maarten
Google Making Life Difficult for Ransomware to Thrive on Android
At the Kaspersky Lab Security Analyst Summit, Android Security Team malware analyst Elena Kovakina explained Google’s strategy for countering ransomware on Android.
ShadowBrokers Expose NSA Access to SWIFT Service Bureaus
The latest ShadowBrokers dump includes exploits that allowed the NSA to target SWIFT data managed by outsourced service bureaus in the Middle East.
‘High Risk’ Zero Day Leaves 200,000 Magento Merchants Vulnerable
A popular version of the Magento ecommerce platform is vulnerable to a remote code execution bug, putting as many as 200,000 online retailers at risk.