PoC for bug available, based on test case from the commit that fixed the bug. Crashes the Chrome renderer process. worthdoingbadly.com/

⚠️ If you're using the 5.0 branch, update to version 5.0.1 now! ⚠️
Fixes for 7 vulnerabilities. Some allow site takeover, and also a pretty serious privacy leak.

Good research by Checkpoint security researchers. Quit shocking results, they found over 50 vulnerabilities in reader in 50 days. One of the bugs was already reported and being exploited in the wild.

Modus operandi:
1: attacker enters building and connects device to local network
2: remotely connect to device and scan network to gain access to additional resources
3: log into target system, use remote access SW to retain access

Linux[.]org was hacked on friday. Attackers switched DNS servers to their own site. Web admin recognizes that he should have put multi-factor authentication on his registrar account, but also blames Whois. Euhm, what?

New zero-day (CVE-2018-15982) actively exploited in the wild.


1) stop using Flash!
2) if 1 not possible, patch now!


It seems that VTech improved the communication about the vulnerability in one of its tablets (only after BBC watchdog probe).
Shall we still agree not to buy spying devices for your kids? bbc.com/news/technology-464405

Fake app offered to read users' heart rate and asked them to place their fingers on the Touch ID sensor to trick them in paying $90 for it. Already removed by Apple.

Atrium health breached. Breach caused by the org's 3rd party billing vendor. Unauthorized access between September 22 and September 29. Names, addresses, DOB, insurance policy information, medical record nrs, account balances stolen

Another example of unbalanced vs.

Well written @wired piece about the real risks of using free wifi nowadays
TL;DR: If you're you're no high-value target you're probably safe as most (commonly used) websites are served over HTTPS.

Russian banks hit by major attacks from 2 hacker groups.
The attack involved emails claiming to come from the Central Bank of Russia containing malicious .zip file attachments.

