Saturday, October 28, 2017

Google Chrome Updated

Google have released a version 62.0.3202.75 of their Chrome web browser. New version contains one security fix. More information about changes in Google Chrome Releases blog.

New PHP Versions Released

PHP development team has released 7.1.11, 7.0.25 and 5.6.32 versions of the PHP scripting language. All PHP users are recommended to upgrade their versions to the latest release of the correspondent branch.

Changelogs:
Version 7.1.11
Version 7.0.25
Version 5.6.32

Saturday, October 21, 2017

Google Chrome Updated

Google have released a version 62.0.3202.62 of their Chrome web browser. New version contains 35 security fixes. More information about changes in Google Chrome Releases blog.

Oracle Critical Patch Update For Q4 of 2017

Oracle have released updates for their products that fix 252 security issues (including 22 Java fixes) in total. The updates are a part of Oracle's quarterly released critical patch update (CPU).

Detailed list of vulnerabilities with patching instructions can be read from Oracle CPU Advisory.

Next Oracle CPU is planned to be released in January 2018.

Adobe Flash Player Update Available

Adobe have released updated versions of their Flash Player. The new versions fix critical vulnerabilities that could potentially allow an attacker to take control of the affected system.

Affected versions:
- Users of Adobe Flash Player 27.0.0.159 and earlier versions for Windows should update to Adobe Flash Player 27.0.0.170

- Users of Adobe Flash Player 27.0.0.159 and earlier versions for Macintosh should update to Adobe Flash Player 27.0.0.170

- Users of Adobe Flash Player 27.0.0.159 and earlier versions for Linux should update to Adobe Flash Player 27.0.0.170

- Flash Player integrated with Google Chrome will be updated by Google via Chrome update

- Flash Player integrated with Internet Explorer 11 (on Windows 8.1 and Windows 10) and Microsoft Edge (Windows 10) will be updated via Windows Update


More information can be read from Adobe's security bulletin.

Monday, October 16, 2017

Microsoft Security Updates For October 2017

Microsoft have released security updates for October 2017.

Summary of the updates (filter by inserting 09/13/2017 to the From field and 10/16/2017 to the To field) here.

Wednesday, October 11, 2017

Mozilla Thunderbird Update Available

Mozilla have released an updated version of their Thunderbird email client containing fixes to security vulnerabilities. Some of the fixed vulnerabilities are categorized as critical.

Affected versions:
Mozilla Thunderbird versions earlier than 52.4

Fresh version can be obtained via inbuilt updater or by downloading from the product site.

Monday, October 9, 2017

Symantec Intelligence Report: September 2017

Symantec have published their Intelligence report that sums up the latest threat trends for September 2017.

The report can be viewed here.

Wednesday, October 4, 2017

3 Zero-Day Plugin Vulnerabilities Exploited In The Wild

According to security company Wordfence's blog post hackers have been exploiting three zero-days to install backdoors on WordPress sites. The zero-days affect three WordPress plugins which are Appointments, Flickr Gallery and RegistrationMagic-Custom Registration Forms.

Affected versions:
-Appointments earlier than version 2.2.2
-Flickr Gallery earlier than version 1.5.3
-RegistrationMagic-Custom Registration Forms earlier than version 3.7.9.3



More information in the Wordfence blog.

Sites using affected plugins should update to the latest versions available. Also, it's recommended to disable those plugins that are not needed.

New PHP Versions Released

PHP development team has released 7.1.10 and 7.0.24 versions of the PHP scripting language. All PHP users are recommended to upgrade their versions to the latest release of the correspondent branch.

Changelogs:
Version 7.1.10
Version 7.0.24