are

We Asked Def Con Attendees Why People Are Still Getting Hacked




are

Horde Groupware Webmail Edition 5.2.22 PHP File Inclusion

Horde Groupware Webmail Edition version 5.2.22 suffers from a PHP file inclusion vulnerability.




are

Music Sales Are Not Affected By Web Piracy, Study Finds




are

Passport Snoop Snared




are

Nissan Car Secretly Shares Driver Data With Websites







are

Lenovo Patches Intel Firmware Flaws In Multiple Product Lines




are

Intel Fixes Severe NUC Firmware, Web Console Vulnerabilities




are

RIAA Wants Infamous File-Sharer To Campaign Against Piracy







are

WebTareas 2.0p8 Cross Site Scripting

WebTareas version 2.0p8 suffers from a cross site scripting vulnerability.










are

COVID-19: Bay Area Requires All 7 Million Residents To Shelter In Place





are

VMware Host VMX Process COM Class Hijack Privilege Escalation

The VMX process (vmware-vmx.exe) process configures and hosts an instance of VM. As is common with desktop virtualization platforms the VM host usually has privileged access into the OS such as mapping physical memory which represents a security risk. To mitigate this the VMX process is created with an elevated integrity level by the authentication daemon (vmware-authd.exe) which runs at SYSTEM. This prevents a non-administrator user opening the process and abusing its elevated access. Unfortunately the process is created as the desktop user which results in the elevated process sharing resources such as COM registrations with the normal user who can modify the registry to force an arbitrary DLL to be loaded into the VMX process. Affects VMware Workstation Windows version 14.1.5 (on Windows 10). Also tested on VMware Player version 15.




are

snaretext-1.1.tar.gz

Snare for Apache provides a remote distribution facility for Apache Web server logs. It is known to run on most Unix variations, including Linux, Solaris, AIX, Tru64, and Irix. Snare for Apache can be used to send data to either a remote or local SYSLOG server, or the Snare Server for centralized collection, analysis, and archival.




are

snaresquid-1.2.tar.gz

Snare for Squid provides a remote distribution facility for Squid proxy server logs, and is known to run on most Unix variations, including Linux, Solaris, AIX, Tru64, and Irix. Snare for Squid can be used to send data to either a remote or local SYSLOG server, or the Snare Server for centralized collection, analysis, and archival.




are

Malware Analysis Part I

Malware Analysis Part I - This guide is the first part of a series of three where we begin with setting up the very foundation of a analysis environment; the analysis station. It will give the reader a quick recap in the different phases of malware analysis along with a few examples. It will then guide the reader in how to build an analysis station optimized for these phases. Along with this, the guide also introduces a workflow that will give the reader a good kick-start in performing malware analysis on a professional basis, not only on a technical level.




are

COVID-19 Malware Wipes Your PC And Rewrites Your MBR




are

Box Adds Automated Malware Detection To Box Shield







are

Bull / IBM AIX Clusterwatch / Watchware File Write / Command Injection

Bull / IBM AIX Clusterwatch / Watchware suffers from having trivial admin credentials, system file writes, and OS command injection vulnerabilities.



















are

Why Big ISPs Aren't Happy About Google's Plans For Encrypted DNS




are

New Attack On Home Routers Sends Users To Spoofed Sites That Push Malware