Researchers: hackers are actively exploiting an RCE vulnerability in Zimbra email servers, disclosed on September 27, triggered by emailing the SMTP server
When the mail server handles an email address with shell escape characters, the postjournal binary just shells out and runs whatever is specified. … Will Dormann / @wdormann@infosec.exchange : “Best e...
Microsoft disables Windows App Installer's ms-appinstaller after the URI scheme was used to spread malware; Microsoft disabled and re-enabled the scheme in 2022
While I was there this was used to deliver malware and had no basic security thought put into it, so they disabled the feature. — After I left they reenabled it, it got misused for malware again (su...
Plex tells users to reset passwords immediately after a hacker accessed some data, including emails, usernames, and encrypted passwords
is your credit card info exposed, too? Nathan Wasson / HotHardware : Plex Users Should Reset Their Login Information ASAP Due To Alarming Data Breach Rob Thubron / TechSpot : Plex warns all users to c...
In a post on the REvil dark web blog, the gang takes credit for the Kaseya attack, claims it infected 1M+ systems, and demands $70M in bitcoin for the decryptor
and Kaseya's $70M REvil demand Usama Jawad / Neowin : Ransomware group demands $70 million in Bitcoin for “universal decryptor” Gavin Phillips / MUO : Ransomware Group Demands $70m Bitcoin Payment to ...
Chrome to immediately stop recognizing extended validation status of Symantec-issued certs and gradually nullify all currently valid certs of Symantec-owned CAs
Saturday, March 25, 2017 Sean Michael Kerner / eWeek : Google Threatens to Distrust Symantec SSL/TLS Certificates Lucian Constantin / Macworld : To punish Symantec, Google may distrust a third of the ...