Government of the Republic of Trinidad and Tobago                                                                                                                                        


News

Two Windows Privilege Escalation Vulnerabilities Exploited in Attacks

9th July 2019

Microsoft’s July 2019 Patch Tuesday updates fix nearly 80 vulnerabilities, including two Windows zero-day flaws and six issues whose details were previously made public. One of the zero-day vulnerabilities is CVE-2019-0880, which Microsoft describes as a local privilege escalation issue related to how the splwow64.exe component in Windows handles certain calls. Splwow64.exe is designed to […]

Read More

Vulnerability Gives Attackers Remote Access to Zoom Users’ Cameras

9th July 2019

A vulnerability in the Zoom Client for Mac allows a remote attacker to force a user into joining a video call with the video camera active, a security researcher has discovered. Zoom offers “enterprise video conferencing with real-time messaging and content sharing,” allowing users to join meetings from both desktop and mobile devices, for improved […]

Read More

Adobe Fixes Low Priority Flaws

9th July 2019

Adobe’s Patch Tuesday updates for July 2019 address vulnerabilities in the company’s Bridge CC, Experience Manager and Dreamweaver products, but none of the security holes appear serious. The latest update for Bridge CC on Windows and macOS resolves an out-of-bounds memory read issue that can result in information disclosure in the context of the targeted […]

Read More

New Malware Lays P2P Network on Top of IPFS

13th June 2019

A newly discovered piece of malware uses a peer-to-peer (p2p) network on top of InterPlanetary File System’s (IPFS) p2p network, Anomali’s security researchers report. Discovered in May 2019 and dubbed IPStorm, the malware is written in the Go (Golang) programming language and targets Windows machines. Once it has infected a system, the malicious program allows […]

Read More

XSS Vulnerability Exposed Google Employees to Attacks

13th June 2019

A researcher revealed on Wednesday that he discovered a blind cross-site scripting (XSS) vulnerability that could have been exploited to attack Google employees and possibly gain access to invoices and other sensitive information. Thomas Orlita, a 16-year-old bug bounty hunter from the Czech Republic, analyzed the Google Invoice Submission Portal hosted on gist-uploadmyinvoice.appspot.com, where vendors […]

Read More

Microsoft Patches Critical Vulnerabilities in NTLM

13th June 2019

Microsoft on Tuesday released security patches for nearly 90 vulnerabilities, including two Critical bugs impacting the proprietary authentication protocol NTLM. Tracked as CVE-2019-1040 and CVE-2019-1019, the two security issues consist of three logical flaws in NTLM that allow the bypass of all major NTLM protection mechanisms, Preempt’s security researchers reveal. The flaws impact all Windows […]

Read More

New Class of Vulnerabilities Leak Data From Intel Chips

14th May 2019

Millions of computers powered by Intel processors are affected by vulnerabilities that can be exploited by malicious actors to obtain potentially sensitive information. Intel and other tech giants have already released patches and mitigations. The side-channel attack methods, named ZombieLoad, RIDL (Rogue In-Flight Data Load), and Fallout, are similar to the notorious Meltdown and Spectre, […]

Read More

Remote Code Execution Vulnerability Impacts SQLite

14th May 2019

A use-after-free vulnerability in SQLite could be exploited by an attacker to remotely execute code on a vulnerable machine, Cisco Talos security researchers have discovered. Tracked as CVE-2019-5018 and featuring a CVSS score of 8.1, the vulnerability resides in the window function functionality of Sqlite3 3.26.0 and 3.27.0. To trigger the flaw, an attacker would […]

Read More

Apple Patches 21 Vulnerabilities in WebKit

14th May 2019

Security updates Apple released this week for iOS, macOS, Safari, tvOS and watchOS include patches for 21 vulnerabilities that affect open source web browser engine WebKit. These bugs include 20 memory corruption issues that could lead to arbitrary code execution during the processing of maliciously crafted web content. Apple says it addressed the flaws with […]

Read More

Cost of Data Breach in UK Increases More Than 41% in Two Years

8th April 2019

The UK government, in the form of the Department for Digital, Culture, Media and Sport (DCMS) has published its fourth annual breaches survey: the Cyber Security Breaches Survey 2019. It was carried out by Ipsos Mori in partnership with the Institute for Criminal Justice Studies at the university of Portsmouth. The survey queried more than […]

Read More

Page 1 of 912345...Last »