Lexmark has released an update for its Markvision Enterprise printer management software to address serious vulnerabilities that could allow a remote attacker to execute arbitrary code on the server hosting the product.
Markvision Enterprise is a web-based tool that allows IT professionals to manage up to 20,000 networked printers, regardless of the manufacturer.
read more
Windows Zero-Day Exploited by “FruityArmor” APT Group
A Windows zero-day vulnerability patched this month by Microsoft was discovered by Kaspersky Lab researchers in attacks conducted by an advanced persistent threat (APT) actor dubbed by the security firm “FruityArmor.”
read more
Russian Arrested by Czech Police Tied to 2012 LinkedIn Hack
The Russian national arrested this month by Czech police in cooperation with the FBI is believed to have been involved in the hacking of social media company LinkedIn in 2012.
read more
Yahoo Calls for ‘Transparency’ From U.S. Spy Agencies
Yahoo asked US spy agencies Wednesday to offer public "transparency" about data they make internet companies provide on users and to declassify any secret order served on the company.
read more
Skype Calls Expose User Keystrokes: Researchers
Microsoft’s popular text, audio and video messaging service Skype can be used to record keystrokes and reveal what a user has typed, researchers say.
read more
Firefox to Display Error When Encountering SHA-1 Certificates
Starting in Firefox 51, Mozilla’s web browser will display an error when a SHA-1 certificate is encountered that chains up to a root certificate included in Mozilla’s CA Certificate Program.
read more
Sofacy’s Flash Player Exploit Platform Exposed
Using weaponized Word documents as attachments to phishing emails is not a new attack method, but researchers have discovered an interesting variation: an RTF document with an embedded OLE Word document containing embedded Flash exploits. The purpose is to disguise the attack in layers of obfuscation.
read more
Muddy Waters Shows More Attacks on St. Jude Cardiac Devices
Investment research firm Muddy Waters and security company MedSec have published four new videos allegedly demonstrating potentially lethal attacks against implanted cardiac devices from St. Jude Medical.
read more
Illumio Unveils Security Templates to Protect Data Center Apps
New Security Templates from Illumio Help Close Security Gaps Inside Data Centers and Clouds
read more
IoT Worm “Hajime” Uses BitTorrent Protocols for Communications
While analyzing the notorious Mirai malware, researchers discovered what they claim to be a new and sophisticated worm designed to target Internet of Things (IoT) devices.
read more

