Get a Pentest and security assessment of your IT network.

News

When The ‘Fix It’ Doesn’t Fix It

Microsoft issued an emergency fix for a zero-day IE bug that allows for remote code execution. Researchers found they could bypass the fix-it Microsoft issued last week in response to active “watering-hole” attacks exploiting IE 8. Microsoft is aware of the researchers’ findings, but it is still recommending that users apply the fix. IE 9 and IE 10 don’t include the bug, which some researchers say is a “use-after-free” vulnerability. “This seems like a bad fix,” says Veracode’s Chris Wysopal, CTO.”]

Source: https://www.darkreading.com/attacks-breaches/when-the-fix-it-doesn-t-fix-it

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2