Get a Pentest and security assessment of your IT network.

Cyber Security

BitDefender fixes bug allowing attackers to run commands remotely

A new Bitdefender vulnerability has been discovered in its Safepay browser component. The vulnerability is called CVE-2020-8102 and affects versions prior to 24.0.20.116. A security blogger demonstrated the vulnerability via a PoC in which he had a locally running web server presenting a valid SSL certificate on the first request but switching to an invalid one right after. This tricks the application into sharing security tokens between that (potentially malicious) page and any other website hosted on the same server.

Source: https://www.bleepingcomputer.com/news/security/bitdefender-fixes-bug-allowing-attackers-to-run-commands-remotely/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security