Researchers from MIT’s CSAIL have developed an artificial intelligence platform that can ‘predict 85% of cyberattacks’ so long as it benefits from human input.
Google put app developers on notice last week, urging them to comply with a new set of privacy policies designed to better promote transparency it plans on enforcing this summer.
Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the “Panda Security URL Filtering” directory and installed files, which allows local users to gain SYSTEM privileges by modifying Panda_URL_Filteringb.exe.
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to “seek across EOF.”
Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to gain SYSTEM privileges by modifying an executable module.
Cross-site scripting (XSS) vulnerability in lucene_search.jsp in dotCMS before 3.5.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the query parameter to c/portal/layout.
Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.
Welcome to this week’s security review, which includes a detailed look at a new video scam sweeping Facebook and the return of a data-stealing malware dubbed Qbot.