When selecting targets, attackers often consider total cost of ‘pwnership’ — the expected cost of an operation versus the likelihood of success. Defenders need to follow a similar strategy. Source: …
Wheels Up: Air Service Is a Go after Aerodata Outage
Wheels Up: Air Service Is a Go after Aerodata Outage Major airlines, including Southwest, JetBlue, Delta and United Airlines, are back on their regular schedules after 780 flights were delayed …
CVE-2018-15180
qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter. Source: NIST CVE-2018-15180
Albany Works Through Impact of Ransomware
Albany Works Through Impact of Ransomware City officials in Albany, New York, have been working for several days in an effort to restore the city’s systems after it became the …
CVE-2018-4049
An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy’s ?Games? directory, version 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of installed games …
CVE-2018-3974
An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy’s install directory. An attacker can overwrite an executable that is launched as a system service …
CVE-2018-4051
An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy’s Games, version 1.2.47 for macOS. An attacker can globally create directories and subdirectories on the …
CVE-2018-4052
An exploitable local information leak vulnerability exists in the privileged helper tool of GOG Galaxy’s Games, version 1.2.47 for macOS. An attacker can pass a PID and receive information running …
CVE-2018-4053
An exploitable local denial-of-service vulnerability exists in the privileged helper tool of GOG Galaxy’s Games, version 1.2.47 for macOS. An attacker can send malicious data to the root-listening service, causing …
FireEye Creates Free Attack Toolset for Windows
The security services company releases a distribution of 140 programs for penetration testers who need to launch attacks and tools from an instance of Windows. Source: DarkReading FireEye Creates Free …