#securitybugs

Slim Bill (He/Him)wjmalik@noc.social
2024-11-13

The Weakest Link Revisited
A Bit of Security for November 13, 2024
My colleague Jonathan Care recently published a piece on the Insider Threat which completes an argument I’ve been working on for quite a while. Listen to this -
Let me know what you think in the comments below.
#cybersecuritytips #insiderthreat #weakestlink #securitybugs #UIdesign # #BitofSec
youtu.be/l3WgXGYPrug

2020-12-15

Millions of Unpatched IoT, OT Devices Threaten Critical Infrastructure - Industrial, factory and medical gear remain largely unpatched when it comes to the URGENT/11 and C... threatpost.com/unpatched-iot-o #criticalinfrastructure #operationaltechnology #internetofthings #vulnerabilities #medicaldevices #securitybugs #factories #unpatched #urgent/11 #takeover #armis #cdpwn #iot #ot

2020-12-08

Microsoft Wraps Up a Lighter Patch Tuesday for the Holidays - Nine critical bugs and 58 overall fixes mark the last scheduled security advisory of 2020. threatpost.com/microsoft-patch #patchingpriority #vulnerabilities #securitypatches #exchangeserver #cloudsecurity #december2020 #patchtuesday #securitybugs #websecurity #sharepoint #microsoft #critical

2020-11-16

Citrix SD-WAN Bugs Allow Remote Code Execution - The bugs tracked as CVE-2020–8271, CVE-2020–8272 and CVE-2020–8273 exist in the Citrix SD-WAN Cent... threatpost.com/citrix-sd-wan-b #remotecodeexecution #vulnerabilities #cloudsecurity #cve-2020–8271 #cve-2020–8272 #cve-2020–8273 #securitybugs #websecurity #realmode #citrix #sd-wan

2020-11-12

2 More Google Chrome Zero-Days Under Active Exploitation - Browser users are once again being asked to patch severe vulnerabilities that can lead to remote c... threatpost.com/2-zero-day-bugs #stablechannelrelease #remotecodeexecution #activelyexploited #googleprojectzero #vulnerabilities #remoteattackers #cve-2020-16013 #cve-2020-16017 #zerodayproject #securitybugs #websecurity #freetype #zero-day #browser #windows #chrome #google #apple #linux #patch #mac

2020-10-26

Microsoft IE Browser Death March Hastens - Internet Explorer redirects more traffic to Edge Chromium browser as Microsoft warns of the upcomi... threatpost.com/ie-browser-deat #internetexplorer11 #microsoftedge87 #vulnerabilities #browsersupport #securityissues #microsoftedge #endofsupport #securitybugs #websecurity #end-of-life #ie-to-edge #transition #windowsxp #chromium #ie

2020-10-20

Mobile Browser Bugs Open Safari, Opera Users to Malware - A set of address-spoofing bugs affect users of six different types of mobile browsers, with some r... threatpost.com/mobile-browser- #vulnerabilities #addressspoofing #mobilesecurity #disinformation #mobilebrowsers #cve-2020-9987 #securitybugs #websecurity #rafayboloch #unpatched #phishing #malware #rapid7 #safari #apple #opera

2020-09-11

It’s No ‘Giggle’: Managing Expectations for Vulnerability Disclosure - Vulnerability-disclosure policies (VDPs), if done right, can help provide clarity and clear guidel... threatpost.com/giggle-managing #vendor-researcherrelationship #vulnerabilitydisclosurepolicy #zerodayinitiative #vulnerabilities #bugbounty.patch #federalagencies #digitalshadows #securitybugs #90daywindow #government #bugbounty #facebook #whatsapp #mandate #hacks

2020-09-04

WhatsApp Discloses 6 Bugs via Dedicated Security Site - The company committed to more transparency about app flaws, with an advisory page aimed at keeping... threatpost.com/whatsapp-disclo #dedicatedsecurityadvisorysite #vulnerabilities #mobilesecurity #cve-2020-1890 #securitybugs #transparency #websecurity #disclosure #mobileapps #facebook #security #whatsapp #patches #flaws #bugs #chat

2020-08-18

Large Orgs Plagued with Bugs, Face Giant Patch Backlogs - Vulnerability management continues to challenge businesses, as they face tens of thousands of bugs... threatpost.com/large-orgs-plag #vulnerabilitymanagement #mostrecentthreatlists #patchprioritization #ponemoninstitute #vulnerabilities #cloudsecurity #cloudpatches #databreaches #securitybugs #ibmx-force #backlog #survey

2020-08-03

Meetup Critical Flaws Allow ‘Group’ Takeover, Payment Theft - Researchers disclosed critical flaws in the popular Meetup service at Black Hat USA 2020 this week... threatpost.com/critical-meetup #crosssitescripting #blackhatusa2020 #vulnerability #securitybugs #websecurity #websiteflaw #blackhat #meetup #hacks #flaws #patch #csrf #xss

2020-05-19

Bluetooth Bugs Allow Impersonation Attacks on Legions of Devices - A host of unpatched security bugs that allow BIAS attacks affects Bluetooth chips from Apple, Inte... more: threatpost.com/bluetooth-bugs- #securecommunicationsprotocols #impersonationattacks #devicecompromise #vulnerabilities #mobilesecurity #securitybugs #longtermkey #knobattack #bluetooth #laptops #phones #bias #iot

2020-05-12

WordPress Page Builder Plugin Bugs Threaten 1 Million Sites with Full Takeover - Severe CSRF to XSS bugs open the door to code execution and complete website compromise. more: threatpost.com/wordpress-page- #securityvulnerabilities #vulnerabilities #securitybugs #sitetakeover #websecurity #pagebuilder #siteorigin #wordpress #webpages #patches #plugin #csrf #xss

2020-04-09

‘Unbreakable’ Smart Lock Draws FTC Ire for Deceptive Security Claims - Tapplock catches heat for patched vulnerabilities -- because of its claims that its smart locks ca... more: threatpost.com/unbreakable-sma #deceptivesecuritypractices #deceptivesecurityclaims #internetofthings #vulnerabilities #ftccomplaint #securitybugs #unbreakable #government #smartlock #tapplock #hacks #iot

2020-02-04

Medtronic Patches Implanted Device, CareLink Programmer Bugs - The medical device giant has issued fixes for bugs first disclosed in 2018 and 2019. more: threatpost.com/medtronic-patch #criticalinfrastructure #carelinkprogrammers #implanteddevices #vulnerabilities #cve-2018-10596 #medicaldevices #cve-2018-5446 #cve-2018-5448 #cve-2019-6538 #cve-2019-6540 #securitybugs #healthcare #medtronic #patches #crt-d #icd #mri #sdn

2019-09-19

No surprises in the top 25 most dangerous software errors - An in-depth study of reported bugs has produced a list of the top 25 bug categories in software to... more: nakedsecurity.sophos.com/2019/ #commonvulnerabilitiesandexposures #commonweaknessenumeration #cross-sitescripting #securitythreats #vulnerability #securitybugs #bufferflaws #mitre #cves #cwe #xss

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst