FTC sets $25,000 Prize for Automatic IoT Patch Management Solution

The U.S. Federal Trade Commission has announced a “prize competition” for creating a software or hardware-based solution with the ability to auto-patch vulnerable Internet of Things (IoT) devices.

Today we are surrounded by a number of Internet-connected devices. Our homes are filled with tiny computers embedded in everything from security cameras, TVs and refrigerators to thermostat and door

Akamai NetSession 1.9.3.1 DLL Hijacking

Tempest Security Intelligence Advisory ADV-8/2016 – Akamai Netsession 1.9.3.1 is vulnerable to dll hijacking as it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned dll is missing from its installation. Thus making it possible to hijack the dll and subsequently inject code within the Akamai NetSession process space.

Audacity 2.1.2 DLL Hijacking

Tempest Security Intelligence Advisory ADV-7/2016 – Audacity version 2.1.2 is vulnerable to dll hijacking as it tries to load avformat-55.dll without supplying the absolute path, thus relying upon the presence of such dll on the system directory. This behavior results in an exploitable dll hijacking vulnerability, even if the SafeDllSerchMode flag is enabled.