Announcements

Critical XSS 0-Day Disclosed in WordPress

  • 26th April 2015
This is a Public Service Announcement, it does not mean you are affected. It is being shared to help bring awareness to a vulnerability that affects multiple WordPress installs. This morning a critical 0-Day Cross-Site Scripting (XSS) vulnerability was released in WordPress. This vulnerability targets the way that the ...
Continue reading

SSL certificate flaw allows hackers to crash devices running iOS 8

  • 22nd April 2015
A flaw in iOS 8 would allow attackers to render devices running the mobile OS useless if they're within range of a fake wireless hotspot, according to researchers from security firm Skycure. The vulnerability exploits an issue in how iOS 8 handles SSL certificates. By manipulating the certificates, researchers found they were able to get ...
Continue reading

Drupal Core - Moderately Critical - Multiple Vulnerabilities

  • 20th March 2015
Advisory ID: DRUPAL-SA-CORE-2015-001 Project: Drupal core Version: 6.x, 7.x Date: 2015-March-18  Security risk: 14/25 (Moderately Critical) AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access bypass, Open Redirect, Multiple vulnerabilities Description Access bypass (Password reset URLs - ...
Continue reading

Apple Security Update 2015-002 is now available

  • 10th March 2015
Security Update 2015-002 is now available and addresses the following: iCloud Keychain Available for: OS X Yosemite v10.10.2 Impact: An attacker with a privileged network position may be able to execute arbitrary code Description: Multiple buffer overflows existed in the handling of data during iCloud Keychain recovery. These issues were ...
Continue reading