Content Paint

Security

New free tool aims to tackle "nightmare" of debugging IPC on Linux

"A Unix socket and a FIFO both transfer bytes from one end to another, but that’s pretty much all they have in common."

Security researcher hacks Apple, Google, Microsoft, after compromising upstream software packages.

"Shopify's build system automatically installed a Ruby gem only a few hours after I had uploaded it, and then tried to run the code inside it."

Hacker gained access to a US water treatment plant, tried to poison water.

FBI investigating after thwarted breach.

Another batch of critical bugs in Cisco products raises tough questions.

Cisco product security continues to demand regular urgent patching from users: the company last week pushing out an advisory after multiple critical (CVSS 9.8) vulnerabilities were found in a family of VPN routers. The bugs  grant any unauthenticated, remote attacker the ability to execute code as all-powerful root user.

There's an unpatched 0day in Internet Explorer that's been used to attack security researchers

No response from Microsoft to POC, says ENKI.

Serco hit by ransomware. Hackers claim 1TB of data stolen.

An NDA among the documents leaked.

Millions affected by 10-year old bug in a Linux utility that gives root.

Full root privileges on Ubuntu 20.04, Debian 10, and Fedora 33 demonstrated.

This AWS API bug lets you check permissions without generating logs in CloudTrail: It's not getting fixed.

Some 645 different API actions across 40 different AWS services affected.

A social engineering campaign is specifically - and successfully - targeting security researchers.

Possible a Chrome 0day is to blame.

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.