Vulnerability
SSD Encryption from Crucial and Samsung is not secure Exposes Data

The researchers examined multiple SSDs, including Crucial and Samsung, some of which they found could be unlocked with any password if the password validation routine in RAM was modified through a standard JTAG debugging interface.

Read more
Vulnerability
Cisco WebEx Meetings Server XML External Entity (CVE-2018-18895)

Cisco Webex Meetings Server includes a version of Castor XML that is affected by XXE. Because of that Cisco WebEx Meetings Server prior to versions 2.8MR3 and 3.0MR2 patch 1 are affected from XXE vulnerability.

Read more
Vulnerability
U-Boot verified boot bypass vulnerabilities (CVE-2018-18439, CVE-2018-18440)

Multiple techniques have been identified that allow to execute arbitrary code, within a running U-Boot instance, by means of externally provided unauthenticated data.

Read more
Vulnerability
New PortSmash Side-Channel Vulnerability (CVE-2018-5407)

A new vulnerability being called PortSmash, (CVE-2018-5407) has been discovered impacting all CPUs that use a Simultaneous Multithreading (SMT) architecture. SMT is a technology that allows multiple computing threads to be executed simultaneously on a CPU core.

Read more
Vulnerability
Armis Discovers "BLEEDINGBIT," Two Critical Chip-Level Vulnerabilities

Armis, the enterprise IoT security company, today announced the discovery of two critical vulnerabilities related to the use of Bluetooth Low Energy (BLE) chips made by Texas Instruments (TI), and used in Cisco, Meraki and Aruba wireless access points, called "BLEEDINGBIT."

Read more
Vulnerability
Wireshark Security Advisory

- ------------------------------------------------------------------------- Debian Security Advisory DSA-4217-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 03, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : wireshark CVE ID : CVE-2018-9273 CVE-2018-7320 CVE-2018-7334 CVE-2018-7335 CVE-2018-7419 CVE-2018-9261 CVE-2018-9264 CVE-2018-11358 CVE-2018-11360 CVE-2018-11362 It was discovered that Wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for PCP, ADB, NBAP, UMTS MAC, IEEE 802.11, […]

Read more
Vulnerability
p-smash DoS (ICMP 9 flood)

p-smash DoS (ICMP 9 flood) Vulnerability Severity p-smash DoS (ICMP 9 flood) 7.8 (High) Summary - It was possible to crash the remote machine by flooding it with ICMP type 9 packets. Vulnerability Detection Result - Vulnerability was detected according to the Vulnerability Detection Method. Impact - A cracker may use this attack to make […]

Read more
Vulnerability
WordPress 4.5.2 Security Release

WordPress 4.5.2 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately.

Read more
Vulnerability
WordPress Redirect Hack via Test0.com/Default7.com

We’ve been working on a few WordPress sites with the same infection that randomly redirects visitors to malicious sites via the default7 .com / test0 .com / test246 .com domains.

Read more
Hack
Cracked Uber accounts tumble to 40 cents on the dark web

A posting from naked security titled " Cracked Uber accounts tumble to 40 cents on the dark web"  by Lisa Vaas emember those cracked Uber accounts that were selling for as little as $1 on the dark web a few months ago? Well, welcome to the Midsummer Madness Sale: prices have been slashed, and now, they're going […]

Read more