Category: Vulnerabilities

Top Software Testing Services

Windows 0-Day Bug, Poorly Patched, Now Unpatched, Reveals Google

A public disclosure of poorly patched security vulnerability in Windows print spooler API was made by Google’s Project Zero Team. This bug could be taken advantage of by attackers or hackers to perform arbitrary code execution. The bug was disclosed to Microsoft in December 2019 by an unidentified user working with Trend Micro’s Zero Day…
Read more

Instagram vulnerability

Instagram Vulnerability Capable of Exploiting Smartphone by RCE, Now Fixed

Facebook patched a major vulnerability in Instagram, which was large enough to take over the whole smartphone. The issue was found in the android application of Instagram. The issue privately told to Facebook, the owner of Instagram, by Check Point was present in a third party project Mozpeg.  Mozpeg is a third-party open source project utilized…
Read more

firefox

Exploitation of LAN vulnerability found in Firefox for Android

New Vulnerability in SSDP engine of firefox for android discovered, can be exploited without any malicious links or website click and launch as applications without user permission, says Australian based exploit researcher Chris Moberly. Recently, firefox application(v 68.11.0 and below) for android devices was found to be vulnerable because of a faulty code that could…
Read more

New Unpatched Bluetooth Flaw

Bluetooth 4.2 and 5.0, supporting dual-mode are vulnerable to key overwriting, says the Researchers at the École Polytechnique Fédérale de Lausanne (EPFL) and Purdue University in independent researches. The devices from iPad Pro to iPhone 11 run on these vulnerable Bluetooth versions. Cross Transport Key Derivation(CTKD), which is responsible to authenticate keys, when pairing two…
Read more

INVDOS

Invdos Bug That Could Have Crashed Bitcoin and Other Blockchain Nodes Finally Fixed After Two Years

Years old vulnerability finally revealed to the public upon rediscovery after being patched for two years. A protocol engineer by profession, Javed Khan, rediscovered a vulnerability during the Decred Bug Bounty program, an open program aimed to find bugs in the software which led the vulnerability to be disclosed to the world, which was rather kept…
Read more

emvbug

New Research Revealed Flaw in Pin Verification System of EMV

A recent study by a group of researchers at ETH Zurich University has revealed severe flaws in the EVM protocol design that makes it prone to many types of attacks. Although the security for EMV has been advertised, many attacks over the years have indicated otherwise.  EMV is the international standard protocol for smart card…
Read more

File Manager WordPress Plugin Zero-Day Vulnerability Risked Thousands Of Websites

A new zero-day vulnerability was founded by Wordfence in a WordPress plugin. The vulnerability existed in the file manager plugin and allows unauthenticated attackers to execute arbitrary code on a WordPress site. WordPress is a popular website building website and is used by millions of users worldwide. The vulnerability has affected 70,000 active users of…
Read more

FBI and NSA expose new Linux Russian malware Drovorub

The cold war started in 1947, leading to the race of nuclear weapons that might have ended in 1991, but the relations between the two world powers have never been friendly. The two nations never hesitate to trouble each other. But this time, the FBI has shown serious concerns regarding a Russian“wood cutter.” What is…
Read more

Flawed Satellite Internet to Compromise Plane and Ship Safety

Satellite broadband services have applications in various sectors- Aviation, marine, and terrestrial, from domestic to commercial. Discrepancies in the security of the systems have been identified earlier. With time, the systems advanced, but they are often unencrypted and vulnerable to eavesdropping attacks by anybody sitting anywhere using remote access. The high cost of equipment has…
Read more

Cybersecurity for International Space Station

A former NASA astronaut Pamela Melroy talked about the cybersecurity issues concerning space based infrastructure at the  Aerospace Village within the DEFCON virtual security conference. She served as pilot on Space Shuttle missions STS-92 and STS-112 and commanded mission STS-120 before leaving the agency in August 2009. The International Space Station (ISS) is a hub of computer systems, and…
Read more