Vulnerability
Discover expert analysis on vulnerability with news, features and insights from the team at IT Pro.
-

Apple patches actively exploited iPhone, iPad zero-day and 18 other security flaws
News The out-of-bounds write error is the eighth actively exploited zero-day impacting Apple hardware this year and could facilitate kernel-level code execution
By Rory Bathgate Published
News -

Undetectable PowerShell backdoor discovered hiding as Windows update
News SafeBreach researchers identified the backdoor, which they say went undetected on all major antivirus programs
By Rory Bathgate Published
News -

Office 365's encryption feature can be easily hacked, warns WithSecure
News Researchers advise enterprises to move away from Office 365 Message Encryption, claiming its messages can be decrypted without a key
By Rory Bathgate Published
News -

Fortinet reiterates call to mitigate against active zero-day, as customers delay fixes
News A large number of customers have yet to apply mitigations necessary to avoid the critical vulnerability
By Rory Bathgate Published
News -

Microsoft still searching for zero-day fixes following Patch Tuesday
News ProxyNotShell remains unaddressed even as Microsoft fixes several critical flaws in its monthly package of security patches
By Rory Bathgate Published
News -

Boeing 737 MAX: You can no longer escape liability due to poor code
Analysis Known vulnerabilities in Boeing’s flight software led to two fatal crashes, as well as a landmark decision with major ramifications for software development
By Rois Ni Thuama Published
Analysis -

Microsoft's third mitigation update for Exchange Server zero-day exploit bypassed within hours
News The string of problematic temporary fixes for ‘ProxyNotShell’ grows longer after a 'confusing' and 'atypical' week-long vulnerability disclosure process
By Connor Jones Published
News -

CISA issues fresh orders to polish security vulnerability detection in federal agencies
News The move marks the latest step in the cyber security authority's ongoing ambition to minimise the government's exposure to attacks
By Praharsha Anand Published
News -

US military contractor hacked through Microsoft Exchange vulnerabilities, custom exfiltration tools
News In a joint advisory, US security groups have warned the prolonged campaign showed new strategies in play, with the vector still unknown
By Rory Bathgate Published
News -

GitHub alerts users to active phishing campaign
News The attack revolves around counterfeit CircleCI notifications urging users to accept updated terms of use and privacy policy
By Praharsha Anand Published
News -

1.1 million Tesla cars recalled over software glitch
News The mass recall is prompted by a flaw in the vehicles' automatic window reversal system
By Praharsha Anand Published
News -

Mozilla patches high-severity security flaws in new ‘speedy’ Firefox release
News Numerous vulnerabilities across Mozilla's products could potentially lead to code execution and system takeover
By Connor Jones Published
News