Author Archives: CIRT Team



CIRT Team

in News Clipping

685 million users may be affected by the Branch.io service XSS vulnerability [360totalsecurity]

Hundreds of million users may have been exposed to cross-site scripting (XSS) attacks due to vulnerabilities in the Branch.io services used by Tinder, Shopify, Yelp and many others. When the researchers analyzed Tinder and other applications, they found a Tinder domain, go.tinder.com, which had multiple XSS vulnerabilities. The researchers said that these vulnerabilities could be used to access Tinder users’ profiles. However, in most cases,...

Read More

0
22 Oct 2018
in News Clipping

Fake application disguised itself as Google Photos in Microsoft Store [360totalsecurity]

In May of this year, an app called “Album by Google Photos” was launched in the Microsoft App Store. Its developer, calling itself “Google LLC” (Google LLC). However, in fact, this is completely fake. Attentive people will know that the official Google app that was released before, its developer column is displayed as “Google Inc.” In view of its release for several months, Google has...

Read More

0
22 Oct 2018
in News Clipping

New iPhone Bug Gives Anyone Access to Your Private Photos [source: thehackernews]

A security enthusiast who discovered a passcode bypass vulnerability in Apple’s iOS 12 late last month has now dropped another passcode bypass bug that works on the latest iOS 12.0.1 that was released last week. Jose Rodriguez, a Spanish amateur security researcher, discovered a bug in iOS 12 in late September that allows attackers with physical access to your iPhone to access your contacts and photos. The...

Read More

0
22 Oct 2018
in Security Advisories & Alerts

Microsoft Releases Security Update

Description: Microsoft has released a security update to address a vulnerability in the Yammer desktop application. Impact: A remote attacker could exploit this vulnerability to take control of an affected system. Mitigation: Updates are available. Please see the references or vendor advisory for more information. Reference URL’s: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8569

0
22 Oct 2018
in Security Advisories & Alerts

libssh 0.8.4 and 0.7.6 Security and Bugfix Release

Description: libssh has released security updates addressing a vulnerability affecting libssh versions 0.6 and above. Impact: A remote attacker could exploit this vulnerability to take control of an affected system. Mitigation: Updates are available. Please see the references or vendor advisory for more information. Reference URL’s: https://www.libssh.org/2018/10/16/libssh-0-8-4-and-0-7-6-security-and-bugfix-release/

0
22 Oct 2018
in Security Advisories & Alerts

Drupal Releases Security Updates

Description: Drupal has released security updates addressing multiple vulnerabilities in Drupal 7.x and 8.x. Impact: A remote attacker could exploit this vulnerability to take control of an affected system. Mitigation: Updates are available. Please see the references or vendor advisory for more information. Reference URL’s: http://www.drupal.org/sa-core-2018-006

0
22 Oct 2018
in Security Advisories & Alerts

Cisco Releases Security Updates

Description: Cisco has released security updates to address multiple vulnerabilities affecting Cisco products. Impact: A remote attacker could exploit this vulnerability to take control of an affected system. Mitigation: Updates are available. Please see the references or vendor advisory for more information. Reference URL’s: https://tools.cisco.com/security/center/publicationListing.x

0
22 Oct 2018
in Security Advisories & Alerts

Oracle Releases October 2018 Security Updates

Description: Oracle has released its Critical Patch Update for October 2018 to address 301 vulnerabilities across multiple products. Impact: A remote attacker could exploit this vulnerability to take control of an affected system. Mitigation: Updates are available. Please see the references or vendor advisory for more information. Reference URL’s: https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html

0
22 Oct 2018
in Security Advisories & Alerts

Advisory on PHP Vulnerabilities

Description: Multiple vulnerabilities have been discovered in PHP, the most severe of which could allow an attacker to execute arbitrary code. PHP is a programming language originally designed for use in web-based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web-based software applications. Successfully exploiting the most severe of these vulnerabilities could allow for arbitrary code execution...

Read More

0
22 Oct 2018
in News Clipping

The Big Hack: How China Used a Tiny Chip to Infiltrate [source: bloomberg]

In 2015, Amazon.com Inc. began quietly evaluating a startup called Elemental Technologies, a potential acquisition to help with a major expansion of its streaming video service, known today as Amazon Prime Video. Based in Portland, Ore., Elemental made software for compressing massive video files and formatting them for different devices. Its technology had helped stream the Olympic Games online, communicate with the International Space Station, and funnel drone...

Read More

0
09 Oct 2018
Page 56 of 134« First...102030...5455565758...708090...Last »