A number of popular services, including Apple iCloud, Twitter, Cloudflare, Minecraft and Steam, are reportedly vulnerable to a zero-day exploit affecting a popular Java logging library. The vulnerability, dubbed “Log4Shell” by researchers at LunaSec and credited to Chen Zhaojun of Alibaba, has been found in Apache Log4j, an open source logging utility that’s used in […]
Zeroday in ubiquitous Log4j tool poses a grave threat to the Internet
Minecraft is the first, but certainly not the last, app known to be affected.
Is the UK government’s new IoT cybersecurity bill fit for purpose?
Internet of Things (IoT) devices — essentially, electronics like fitness trackers and smart lightbulbs that connect to the internet — are now part of everyday life for most. However, cybersecurity remains a problem, and according to Kaspersky, it’s only getting worse: there were 1.5 billion breaches of IoT devices during the first six months of […]
Microsoft reports SIP-bypassing “Shrootless” vulnerability in macOS
Exploit based on SIP entitlement inheritance was patched by Apple on October 26.
F12 isn’t hacking: Missouri governor threatens to prosecute local journalist for finding exposed state data
Missouri governor Mike Parson is facing a monumental backlash after threatening to prosecute a journalist for responsibly reporting a serious security lapse in the state’s website. Earlier this week, St. Louis Post-Dispatch journalist Josh Renaud reported that the website for the state’s Department of Elementary and Secondary Education (DESE) was exposing over 100,000 teachers’ Social Security […]
Apple forgot to sanitize the Phone Number field for lost AirTags
Another bug-bounty boondoggle leads to public disclosure before the bug is fixed.
PoC exploit released for Azure AD brute-force bug—here’s what to do
Microsoft maintains it’s not a security risk but is working toward a solution.
New Azure Active Directory password brute-forcing flaw has no fix
Microsoft says AD authentication responses are working as intended.
Exchange/Outlook autodiscover bug exposed 100,000+ email passwords
A flaw in the Autodiscover protocol can expose email passwords to third parties.
Unpatched MacOS vulnerability lets remote attackers execute code
Internet shortcuts come with code execution capability. Latest Mac not fully patched.