Microsoft has issued a “top up” security bulletin for a fix that didn’t quite make it into the November 2014 Patch Tuesday. The vulnerability can be used to turn any user into a domain administrator, and it’s been exploited in the wild…
Tag Archives: EoP
Patch Tuesday wrap-up, November 2014: Microsoft joins the “security hole in HTTPS” club
Here’s what you need to know about the September 2014 Patch Tuesday updates from Microsoft and Adobe…
Patch Tuesday wrap-up, September 2014 – why even a single-bit data leak is worth fixing
Here’s what you need to know about the September 2014 Patch Tuesday updates from Microsoft and Adobe…
Patch Tuesday wrap-up, August 2014: RCE + ASLR bypass + EoP == patch early, patch all!
Patch Tuesday is here again. Paul Ducklin explains how this month’s vulnerabilities can work together for harm, and why *all* the updates matter, not just the ones that ended up with a “critical” or “severe” tag…
Patch Tuesday wrap-up, July 2014 – Adobe fixes “Rosetta”, plus a new risky file type on Windows…
Patch Tuesday for July 2014 is just behind us in the case of Microsoft and Adobe, and just ahead of us in the case of Oracle. Paul Ducklin tells you what you need to know…
Patch Tuesday for July 2014 – 6 bulletins, 2 RCEs, 3 EoPs and get ready to reboot
Here’s what to expect from Microsoft in the July 2014 edition of Patch Tuesday, scheduled to ship on Tuesday 08 July 2014…
Apple ships updates, including Snow Leopard (ONLY KIDDING!)
Apple just published its latest round of updates for iOS, Apple TV, Safari and OS X, including dozens of security fixes. OS X Snow Leopard users…we’re afraid you missed out once again.
As one security hole closes, another one opens! 60 Sec Security [VIDEO]
How many years was that security hole in Linux ? How many security patches for XP? How many lock screen holes in iOS? How much do Google specs cost? Find out in this week’s 60 Second Security video…
Linux “got root” kernel bug patched after five years at large
Here’s a kernel bug in Linux that turned out to have been sitting there, Heartbleed style, awaiting discovery and exploitation for several years. Paul Ducklin digs in…
Patch Tuesday wrap-up, May 2014 – Adobe and Microsoft both patch multiple remotable holes
Patch Tuesday updates from both Microsoft and Adobe are out. There aren’t any huge surprises this month, but both companies have critical patches for remote code execution holes…