Kaspersky Lab and Kings College London researchers announced today that they found a link between a modern threat actor and the Moonlight Maze attacks through samples, logs and artefacts belonging to the ancient APT, which targeted the Pentagon, NASA and more in the late 1990s.
Monthly Archives: April 2017
The right to privacy in the digital era
ESET’s Miguel Ángel Mendoza discusses the right to privacy in the digital era, which is an increasingly important issue.
The post The right to privacy in the digital era appeared first on WeLiveSecurity
![]()
Microsoft is Shutting Down CodePlex, Asks Devs To Move To GitHub
Microsoft has announced to shut down CodePlex — its website for hosting repositories of open-source software projects — on December 15, 2017.
Launched in 2006, CodePlex was one of the Microsoft’s biggest steps towards the world of open source community — where any programmer, anywhere can share the code for their software or download and tweak the code to their liking.
However, Microsoft
![]()
Bugtraq: Splunk Enterprise Information Theft CVE-2017-5607
Splunk Enterprise Information Theft CVE-2017-5607
SEC Consult SA-20170403-0 :: Misbehavior of PHP fsockopen function
Posted by SEC Consult Vulnerability Lab on Apr 03
SEC Consult Vulnerability Lab Security Advisory < 20170403-0 >
=======================================================================
title: Misbehavior of the “fsockopen” function
product: PHP
vulnerable version: 7.1.2
fixed version:
CVE number: CVE-2017-7272
impact: Medium
homepage: http://www.php.net/
found: 2017-03-06
by: Fikri…
CVE-2017-5923
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted rule that is mishandled in the yara_yyparse function.
CVE-2016-10217
The pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file that is mishandled in the color management module.
CVE-2017-5949
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers access to red-zone memory locations, related to jit/ThunkGenerators.cpp, llint/LowLevelInterpreter32_64.asm, and llint/LowLevelInterpreter64.asm.
CVE-2016-10219
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
CVE-2017-5951
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
