Microsoft has released out-of-band patches for Internet Explorer and Microsoft Defender products. The IE zero-day bug is marked critical and is actively exploited in the wild.
A security researcher recently detected a zero-day CSRF vulnerability CVE-2019-12922 in phpMyAdmin 184.108.40.206, which allows the deletion of any server in the Setup page.
Microsoft issued the September 2019 Security Updates that include 79 unique vulnerability fixes, 17 of those rated critical. In addition, two of the patches address two 0-day Privileged Escalation vulnerabilities CVE-2019-1214 and CVE-2019-1215.
A group of hackers have been using compromised websites to launch watering hole attacks against iPhone users who visit the websites. The attacks also use five different exploit chains and exploit 0-day vulnerabilities that don't require any user interaction.
Mozilla has released a security update that fixes a critical vulnerability in Firefox 67.0.3 and Firefox ESR 60.7.1.
A security researcher released details on a new zero-day vulnerability that impacts the TP-Link All-in-One SR20 Smart Home Router and Hub.
Microsoft issued the November 2018 Security Updates that include 62 unique vulnerability fixes, 12 of them rated critical.
A security researcher released the details of a VirtualBox vulnerability that affects VirtualBox 5.2.20 and earlier versions.
Cisco has just released a security advisory for a high severity zero-day denial of service (DOS) vulnerability that impacts Cisco's Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software.
A local privilege escalation vulnerability in the Advanced Local Procedure Call (ALPC) interface of Windows task scheduler was discovered.