Tag

Vulnerability Disclosure

All articles tagged with #vulnerability disclosure

AI-Assisted Discovery Reveals Flaw in US Festival Ticketing Network
security19 days ago

AI-Assisted Discovery Reveals Flaw in US Festival Ticketing Network

Security researcher Ian Carroll used Anthropic’s Claude Opus 4.7 to uncover a vulnerability in Front Gate Tickets’ system that could grant a super-admin the ability to issue any festival tickets and access millions of customer and staff records. The flaw was patched within 24 hours, and there’s no evidence of exploitation, illustrating both AI’s potential to uncover web vulnerabilities and the risks of centralized festival-ticketing platforms.

Microsoft’s Digital Crimes Unit at Center of Z-day Disclosure Controversy
cybersecurity1 month ago

Microsoft’s Digital Crimes Unit at Center of Z-day Disclosure Controversy

Microsoft is facing backlash from security researchers after signaling that its Digital Crimes Unit will pursue cases against individuals who publicly disclose Windows zero-day vulnerabilities, arguing such disclosures endanger customers. The controversy centers on Nightmare Eclipse’s six disclosed exploits; Microsoft contends coordinated disclosure is essential, while critics warn the stance could chill research and highlight First Amendment and CFAA debates. The piece situates the dispute within broader tensions over vulnerability disclosure, state-backed hacking, and how security researchers should responsibly report flaws.

Microsoft's crackdown on public zero-days fuels security researcher feud
tech1 month ago

Microsoft's crackdown on public zero-days fuels security researcher feud

Microsoft is facing backlash over its handling of zero-day exploits after a security researcher going by Nightmare Eclipse publicly posted exploit code. Microsoft says it plans to file a criminal case for failing to coordinate disclosure and has disabled Nightmare Eclipse's GitHub, GitLab, and MSRC accounts. Security researcher Kevin Beaumont notes that Microsoft has hired people with public zero-day histories and even buys exploits, raising questions about the company’s stance on “responsible disclosure” and highlighting a broader clash between vendors and researchers over vulnerability reporting.

Microsoft Faces Backlash After Threatening Legal Action Over Windows Bugs
technology1 month ago

Microsoft Faces Backlash After Threatening Legal Action Over Windows Bugs

Microsoft drew sharp criticism from the cybersecurity community after threatening legal action against Nightmare Eclipse, a researcher who published six unpatched Windows zero-days outside the MSRC disclosure process, including a BlueHammer privilege-escalation proof-of-concept. Microsoft says coordinated disclosure protects customers, while researchers argue it stifles bug reporting; the dispute has led to the takedown of the researcher’s GitHub/GitLab pages and MSRC accounts, with promises of further disclosures and a broader debate over disclosure policies.

Hacked from Across the Globe: Yarbo Robotic Mowers Reveal Widespread Security Flaws
technology2 months ago

Hacked from Across the Globe: Yarbo Robotic Mowers Reveal Widespread Security Flaws

A security researcher demonstrates that Yarbo’s all-in-one robot lawn mowers can be hijacked remotely due to universal hardcoded root passwords and a built-in backdoor, giving access to owners’ GPS data, Wi‑Fi credentials, and camera/video feeds across thousands of devices worldwide. The demo shows remote control over mowers, potential spying on homes, and even the risk of turning devices into botnets. Yarbo says it’s working on fixes, stronger access controls, and a possible bug‑bounty program, while acknowledging security concerns and ongoing investigations.

Apple Denies Bug Bounty to Kaspersky Lab
technology2 years ago

Apple Denies Bug Bounty to Kaspersky Lab

Apple declined to pay a bug bounty to Kaspersky Lab after the Russian cybersecurity firm disclosed four zero-day vulnerabilities in iPhone software, which were allegedly used to spy on Kaspersky employees and Russian diplomats. Kaspersky suggested the vulnerabilities might have been state-sponsored, but Apple denied any collaboration with governments for spying purposes. The refusal comes amid heightened tensions between the US and Russia following the invasion of Ukraine.

"Ransomware Attack on JetBrains TeamCity Exposes Critical Vulnerability"
cybersecurity2 years ago

"Ransomware Attack on JetBrains TeamCity Exposes Critical Vulnerability"

Security researchers have observed active exploit attempts using vulnerabilities in JetBrains' TeamCity, leading to ransomware deployment. The vulnerabilities are being actively exploited in the wild, with attackers breaking into CI/CD servers and creating hundreds of accounts for later use. Due to uncoordinated disclosure between JetBrains and researchers at Rapid7, all the information required for an attacker to develop a working exploit was made public on the same day the patches were released. This has sparked a debate within the cybersecurity community about the best approach to vulnerability disclosure. Users of on-prem versions of TeamCity prior to 2023.11.4 are advised to apply the patches immediately to mitigate the risk of exploitation.