Displaying items by tag: Tavis ormandy

Processor manufacturer AMD has issued an advisory about a cross-process information leak in some of its hardware, that it rates to be of medium severity, following the release of details of the flaw by Google Information Security researcher Tavis Ormandy.

Published in Security

The OpenSSL project, an open-source cryptographic library, has released a fix for a serious vulnerability present in versions 1.0.2, 1.1.1 and 3.0.

Published in Security

The Microsoft-owned code repository GitHub has sought to protect the wares of its parent company from attack by taking down proof-of-concept code for exploiting two of the four Microsoft Exchange Server bugs that came to light recently.

Published in Security

A row has broken out between researchers from Google after ex-NSA hacker Patrick Wardle revealed the details of two zero-day vulnerabilities in the Mac version of Zoom that could be exploited to give the attacker root access. Neither vulnerability is remotely exploitable and can only be taken advantage of by a local attacker – someone who has physical access to the machine in question.

Published in Security

Czech anti-virus firm Avast has been forced to disable a JavaScript interpreter within its software after a Google vulnerability researcher detailed how the emulator could be abused to effect a remote exploit.

Published in Security

Google's video-sharing site YouTube has started to ban videos that show users how to get past software restrictions and provide instructions on information security.

Published in Security

Well-known Google security researcher Tavis Ormandy has taken a swipe at security industry veteran Richard Bejtlich, after the latter chided him for releasing details about a vulnerability in Microsoft software after the 90-day period normally given for patching expired.

Published in Security

Microsoft has released a patch to fix a nasty hole in the Windows malware scanner which is present on many versions of Windows, including Windows 10.

Published in Security
Saturday, 25 February 2017 10:28

Cloudflare fixes serious bug that leaked user data

Content delivery network Cloudflare has revealed that it recently fixed a serious software bug in its infrastructure that may have led to the exposure of cookies, passwords and user authentication tokens.

Published in Security

A security researcher has released details of a remotely exploitable vulnerability which can cause a buffer overflow in the core Symantec Antivirus Engine used in most Symantec and Norton branded anti-virus products.

Published in Security

Subscribe to Newsletter

*  Enter the security code shown: img0

CYBERSECURITY

PEOPLE MOVES

GUEST ARTICLES

Guest Opinion

ITWIRETV & INTERVIEWS

RESEARCH & CASE STUDIES

Channel News

Comments