The number of financial phishing attacks is expected to rise during the Holiday shopping season which starts unofficially on Black Friday.
Monthly Archives: November 2016
Over 300 Million AdultFriendFinder Accounts Exposed in Massive Data Breach
Adult Friend Finder, a casual dating website with the tagline “hookup, find sex or meet someone hot now,” has suffered another massive data breach, but this time it is much worse than the last year.
Over 300 Million AdultFriendFinder accounts have reportedly been exposed in a massive data breach that hit adult dating and entertainment company Friend Finder Network.
Friend Finder Network is
![]()
New VMSA-2016-0019 – VMware product updates address multiple information disclosure issues
Posted by VMware Security Response Center on Nov 13
————————————————————————
VMware Security Advisory
Advisory ID: VMSA-2016-0019
Severity: Critical
Synopsis: VMware Workstation and Fusion updates address critical
out-of-bounds memory access vulnerability
Issue date: 2016-11-13
Updated on: 2016-11-13 (Initial Advisory)
CVE number: CVE-2016-7461
1. Summary
VMware Workstation and Fusion…
Vuln: OpenSSL CVE-2016-6303 Integer Overflow Vulnerability
OpenSSL CVE-2016-6303 Integer Overflow Vulnerability
Vuln: Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
Unexpected behavior of cmd.exe while processing .bat files leads to potential command injection vulnerabilities
Posted by Julian Horoszkiewicz on Nov 13
Unexpected behavior of cmd.exe while processing .bat files leads to
potential command injection vulnerabilities
Tested on: Windows 7, Windows 10
Author: Julian Horoszkiewicz
It was discovered that cmd.exe, when processing .bat files, treats the
ASCII substitute character (code 26) as a command separator (like & or |).
This opens the way for unexpected command injection vulnerabilities in
applications which generate .bat files based on user…
