#zero_day — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #zero_day, aggregated by home.social.
-
Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025
https://www.bleepingcomputer.com/news/security/hackers-exploit-16-zero-days-on-first-day-of-pwn2own-automotive-2025/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025
https://www.bleepingcomputer.com/news/security/hackers-exploit-16-zero-days-on-first-day-of-pwn2own-automotive-2025/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025
https://www.bleepingcomputer.com/news/security/hackers-exploit-16-zero-days-on-first-day-of-pwn2own-automotive-2025/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025
https://www.bleepingcomputer.com/news/security/hackers-exploit-16-zero-days-on-first-day-of-pwn2own-automotive-2025/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Pwn2Own Ireland Reveals Over 70 Zero-Day Vulnerabilities - https://www.redpacketsecurity.com/researchers-discover-over-70-zero-day-bugs-at-pwn2own-ireland/
-
Pwn2Own Ireland Reveals Over 70 Zero-Day Vulnerabilities - https://www.redpacketsecurity.com/researchers-discover-over-70-zero-day-bugs-at-pwn2own-ireland/
-
Pwn2Own Ireland Reveals Over 70 Zero-Day Vulnerabilities - https://www.redpacketsecurity.com/researchers-discover-over-70-zero-day-bugs-at-pwn2own-ireland/
-
Pwn2Own Ireland Reveals Over 70 Zero-Day Vulnerabilities - https://www.redpacketsecurity.com/researchers-discover-over-70-zero-day-bugs-at-pwn2own-ireland/
-
Security Week 2443: уязвимости нулевого дня в реальных атаках
На прошлой неделе подразделение Mandiant компании Google выпустило отчет , в котором сделана попытка проанализировать реальную эксплуатацию уязвимостей в атаках. Это достаточно важная метрика: далеко не все уязвимости, информация о которых так или иначе становится доступной, могут быть эксплуатированы для нанесения реального ущерба. Исследователи Google ограничили анализ уязвимостями, обнародованными в 2023 году. Из них был выделен набор из 138 багов, которые использовались в реальных атаках. Главный вывод исследования следующий: организаторы атак стали гораздо активнее использовать недавно обнаруженные уязвимости. Средний срок между появлением информации об уязвимости до начала ее эксплуатации для данного набора багов составил всего 5 дней. В предыдущем отчете за 2021 и 2022 годы этот показатель составлял 32 дня, а в начале 2021 года — и вовсе 44 дня. Более того, из 138 реально эксплуатируемых проблем в ПО 70% были впервые эксплуатированы до выпуска патчей (в 2021–2022 годах эта цифра составляла 62%).
-
Security Week 2443: уязвимости нулевого дня в реальных атаках
На прошлой неделе подразделение Mandiant компании Google выпустило отчет , в котором сделана попытка проанализировать реальную эксплуатацию уязвимостей в атаках. Это достаточно важная метрика: далеко не все уязвимости, информация о которых так или иначе становится доступной, могут быть эксплуатированы для нанесения реального ущерба. Исследователи Google ограничили анализ уязвимостями, обнародованными в 2023 году. Из них был выделен набор из 138 багов, которые использовались в реальных атаках. Главный вывод исследования следующий: организаторы атак стали гораздо активнее использовать недавно обнаруженные уязвимости. Средний срок между появлением информации об уязвимости до начала ее эксплуатации для данного набора багов составил всего 5 дней. В предыдущем отчете за 2021 и 2022 годы этот показатель составлял 32 дня, а в начале 2021 года — и вовсе 44 дня. Более того, из 138 реально эксплуатируемых проблем в ПО 70% были впервые эксплуатированы до выпуска патчей (в 2021–2022 годах эта цифра составляла 62%).
-
Security Week 2443: уязвимости нулевого дня в реальных атаках
На прошлой неделе подразделение Mandiant компании Google выпустило отчет , в котором сделана попытка проанализировать реальную эксплуатацию уязвимостей в атаках. Это достаточно важная метрика: далеко не все уязвимости, информация о которых так или иначе становится доступной, могут быть эксплуатированы для нанесения реального ущерба. Исследователи Google ограничили анализ уязвимостями, обнародованными в 2023 году. Из них был выделен набор из 138 багов, которые использовались в реальных атаках. Главный вывод исследования следующий: организаторы атак стали гораздо активнее использовать недавно обнаруженные уязвимости. Средний срок между появлением информации об уязвимости до начала ее эксплуатации для данного набора багов составил всего 5 дней. В предыдущем отчете за 2021 и 2022 годы этот показатель составлял 32 дня, а в начале 2021 года — и вовсе 44 дня. Более того, из 138 реально эксплуатируемых проблем в ПО 70% были впервые эксплуатированы до выпуска патчей (в 2021–2022 годах эта цифра составляла 62%).
-
Security Week 2443: уязвимости нулевого дня в реальных атаках
На прошлой неделе подразделение Mandiant компании Google выпустило отчет , в котором сделана попытка проанализировать реальную эксплуатацию уязвимостей в атаках. Это достаточно важная метрика: далеко не все уязвимости, информация о которых так или иначе становится доступной, могут быть эксплуатированы для нанесения реального ущерба. Исследователи Google ограничили анализ уязвимостями, обнародованными в 2023 году. Из них был выделен набор из 138 багов, которые использовались в реальных атаках. Главный вывод исследования следующий: организаторы атак стали гораздо активнее использовать недавно обнаруженные уязвимости. Средний срок между появлением информации об уязвимости до начала ее эксплуатации для данного набора багов составил всего 5 дней. В предыдущем отчете за 2021 и 2022 годы этот показатель составлял 32 дня, а в начале 2021 года — и вовсе 44 дня. Более того, из 138 реально эксплуатируемых проблем в ПО 70% были впервые эксплуатированы до выпуска патчей (в 2021–2022 годах эта цифра составляла 62%).
-
Mozilla fixes Firefox zero-day actively exploited in attacks
https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-zero-day-actively-exploited-in-attacks/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Actively_Exploited #CVE_2024_9680 #Firefox #Use_After_Free #Vulnerability #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Mozilla fixes Firefox zero-day actively exploited in attacks
https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-zero-day-actively-exploited-in-attacks/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Actively_Exploited #CVE_2024_9680 #Firefox #Use_After_Free #Vulnerability #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Mozilla fixes Firefox zero-day actively exploited in attacks
https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-zero-day-actively-exploited-in-attacks/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Actively_Exploited #CVE_2024_9680 #Firefox #Use_After_Free #Vulnerability #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Mozilla fixes Firefox zero-day actively exploited in attacks
https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-zero-day-actively-exploited-in-attacks/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Actively_Exploited #CVE_2024_9680 #Firefox #Use_After_Free #Vulnerability #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Google now pays $250k for KVM zero-day vulnerabilities
https://www.bleepingcomputer.com/news/security/google-now-pays-250-000-for-kvm-zero-day-vulnerabilities/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Bug_Bounty_Program #Google #KVM #kvmCTF #Vulnerability_Rewards_Program #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Google now pays $250k for KVM zero-day vulnerabilities
https://www.bleepingcomputer.com/news/security/google-now-pays-250-000-for-kvm-zero-day-vulnerabilities/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Bug_Bounty_Program #Google #KVM #kvmCTF #Vulnerability_Rewards_Program #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Google now pays $250k for KVM zero-day vulnerabilities
https://www.bleepingcomputer.com/news/security/google-now-pays-250-000-for-kvm-zero-day-vulnerabilities/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Bug_Bounty_Program #Google #KVM #kvmCTF #Vulnerability_Rewards_Program #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Google now pays $250k for KVM zero-day vulnerabilities
https://www.bleepingcomputer.com/news/security/google-now-pays-250-000-for-kvm-zero-day-vulnerabilities/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Bug_Bounty_Program #Google #KVM #kvmCTF #Vulnerability_Rewards_Program #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
After several years of warning after warning after advisory after advisory and calls to repeatedly update or remove and NOT USE CHROME by the Department of Homeland Security, it should be inconceivable that anyone does - but they do.
Sometimes these are patched with automatic updates before horrific and catastrophic results occur, sometimes not. To be frank, part of the problem stems from the fact that Chrome is the largest attack surface out there where browsers are concerned, but notwithstanding it being the fav target are also serious privacy concerns that aren't shared by other chromium based browsers.
To be fair, many exploits are indeed shared by other chromium based browsers, but not most, while some are related to other browser capabilities, like WebRTC, but it's still best to just ditch Chrome and never look back.
Here's more coverage on vulnerabilities issued less than a month ago. It took 3 seconds to bring this up, and no, not using Google, which didn't reveal this when I tried that search engine in a subsequent search, lolz. Why would they return SERPs that poo poo their own product?
This one did come up in a google search
There's truly only one way to ensure safety - unplug. But there's a lot of simple things you can do to exact a reasonable level of security, so why not observe some of those best practices? It's not like it will cramp your style.
Anyway, that's my two cents. h/t to @darnell for raising awareness of this latest brokewell. Make sure you take the time to visit the link he's provided for you too.
There are plenty of #Browsers that run on #Android (to name a few, alphabetized):
- Brave Browser
- Chromium
- DuckDuckGo
- Firefox
- Kiwi
- VivaldiIMO, No one should be running Chrome - Desktop or otherwise. It's a privacy nightmare even when there aren't CERT warnings circulating.
#tallship #brokewell #zero_day #CISA #CERT #DHS
⛵
.
RE: https://one.darnell.one/users/darnell/statuses/112371221294882180
-
After several years of warning after warning after advisory after advisory and calls to repeatedly update or remove and NOT USE CHROME by the Department of Homeland Security, it should be inconceivable that anyone does - but they do.
Sometimes these are patched with automatic updates before horrific and catastrophic results occur, sometimes not. To be frank, part of the problem stems from the fact that Chrome is the largest attack surface out there where browsers are concerned, but notwithstanding it being the fav target are also serious privacy concerns that aren't shared by other chromium based browsers.
To be fair, many exploits are indeed shared by other chromium based browsers, but not most, while some are related to other browser capabilities, like WebRTC, but it's still best to just ditch Chrome and never look back.
Here's more coverage on vulnerabilities issued less than a month ago. It took 3 seconds to bring this up, and no, not using Google, which didn't reveal this when I tried that search engine in a subsequent search, lolz. Why would they return SERPs that poo poo their own product?
This one did come up in a google search
There's truly only one way to ensure safety - unplug. But there's a lot of simple things you can do to exact a reasonable level of security, so why not observe some of those best practices? It's not like it will cramp your style.
Anyway, that's my two cents. h/t to @darnell for raising awareness of this latest brokewell. Make sure you take the time to visit the link he's provided for you too.
There are plenty of #Browsers that run on #Android (to name a few, alphabetized):
- Brave Browser
- Chromium
- DuckDuckGo
- Firefox
- Kiwi
- VivaldiIMO, No one should be running Chrome - Desktop or otherwise. It's a privacy nightmare even when there aren't CERT warnings circulating.
#tallship #brokewell #zero_day #CISA #CERT #DHS
⛵
.
RE: https://one.darnell.one/users/darnell/statuses/112371221294882180
-
After several years of warning after warning after advisory after advisory and calls to repeatedly update or remove and NOT USE CHROME by the Department of Homeland Security, it should be inconceivable that anyone does - but they do.
Sometimes these are patched with automatic updates before horrific and catastrophic results occur, sometimes not. To be frank, part of the problem stems from the fact that Chrome is the largest attack surface out there where browsers are concerned, but notwithstanding it being the fav target are also serious privacy concerns that aren't shared by other chromium based browsers.
To be fair, many exploits are indeed shared by other chromium based browsers, but not most, while some are related to other browser capabilities, like WebRTC, but it's still best to just ditch Chrome and never look back.
Here's more coverage on vulnerabilities issued less than a month ago. It took 3 seconds to bring this up, and no, not using Google, which didn't reveal this when I tried that search engine in a subsequent search, lolz. Why would they return SERPs that poo poo their own product?
This one did come up in a google search
There's truly only one way to ensure safety - unplug. But there's a lot of simple things you can do to exact a reasonable level of security, so why not observe some of those best practices? It's not like it will cramp your style.
Anyway, that's my two cents. h/t to @darnell for raising awareness of this latest brokewell. Make sure you take the time to visit the link he's provided for you too.
There are plenty of #Browsers that run on #Android (to name a few, alphabetized):
- Brave Browser
- Chromium
- DuckDuckGo
- Firefox
- Kiwi
- VivaldiIMO, No one should be running Chrome - Desktop or otherwise. It's a privacy nightmare even when there aren't CERT warnings circulating.
#tallship #brokewell #zero_day #CISA #CERT #DHS
⛵
.
RE: https://one.darnell.one/users/darnell/statuses/112371221294882180
-
Security researchers collect awards for Tesla exploits at Pwn2Own Automotive
https://www.bleepingcomputer.com/news/security/tesla-hacked-24-zero-days-demoed-at-pwn2own-automotive-2024/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tesla #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Security researchers collect awards for Tesla exploits at Pwn2Own Automotive
https://www.bleepingcomputer.com/news/security/tesla-hacked-24-zero-days-demoed-at-pwn2own-automotive-2024/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tesla #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Security researchers collect awards for Tesla exploits at Pwn2Own Automotive
https://www.bleepingcomputer.com/news/security/tesla-hacked-24-zero-days-demoed-at-pwn2own-automotive-2024/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tesla #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Tesla hacked, 24 zero-days demoed at Pwn2Own Automotive 2024
https://www.bleepingcomputer.com/news/security/tesla-hacked-24-zero-days-demoed-at-pwn2own-automotive-2024/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tesla #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Tesla hacked, 24 zero-days demoed at Pwn2Own Automotive 2024
https://www.bleepingcomputer.com/news/security/tesla-hacked-24-zero-days-demoed-at-pwn2own-automotive-2024/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tesla #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Tesla hacked, 24 zero-days demoed at Pwn2Own Automotive 2024
https://www.bleepingcomputer.com/news/security/tesla-hacked-24-zero-days-demoed-at-pwn2own-automotive-2024/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tesla #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Tesla hacked, 24 zero-days demoed at Pwn2Own Automotive 2024
https://www.bleepingcomputer.com/news/security/tesla-hacked-24-zero-days-demoed-at-pwn2own-automotive-2024/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Automotive #Exploit #Hacking #Japan #Pwn2Own #Tesla #Tokyo #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
New Microsoft Exchange zero-days allow RCE, data theft attacks
https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Exchange #Information_Disclosure #Microsoft #RCE #Remote_Code_Execution #Vulnerability #Zero_Day_Initiative #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
New Microsoft Exchange zero-days allow RCE, data theft attacks
https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Exchange #Information_Disclosure #Microsoft #RCE #Remote_Code_Execution #Vulnerability #Zero_Day_Initiative #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Signal says there is no evidence rumored zero-day bug is real
https://www.bleepingcomputer.com/news/security/signal-says-there-is-no-evidence-rumored-zero-day-bug-is-real/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Chat #Encrypted_Messaging #Signal #Vulnerability #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Signal says there is no evidence rumored zero-day bug is real
https://www.bleepingcomputer.com/news/security/signal-says-there-is-no-evidence-rumored-zero-day-bug-is-real/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Chat #Encrypted_Messaging #Signal #Vulnerability #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
Signal says there is no evidence rumored zero-day bug is real
https://www.bleepingcomputer.com/news/security/signal-says-there-is-no-evidence-rumored-zero-day-bug-is-real/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Chat #Encrypted_Messaging #Signal #Vulnerability #Zero_Day #virus_removal #malware_removal #computer_help #technical_support -
WinRAR zero-day exploited since April to hack trading accounts
https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/
#ycombinator #computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Actively_Exploited #Archive #Malware #Software #Vulnerability #WinRAR #Zero_Day #Zip #virus_removal #malware_removal #computer_help #technical_support