The difficulty of detecting zero days in the wild and incomplete patches for the ones that are found is making life easier for attackers.
Developers have patched a serious heap buffer overflow in Libgcrypt that could be triggered easily when data is decrypted.
Researchers from Qualys uncovered a major vulnerability in an application that allows administrators to delegate limited root access to regular users. While most major Linux distributions have released fixed versions of sudo, administrators still have to verify their systems are protected.
The NSA warned that Russian state attackers are targeting a recent VMware vulnerability, which NSA discovered and disclosed.
The latest research out of Kenna Security and Cyentia Institute compared how quickly defenders could remediate vulnerabilities and how quickly attackers could exploit the vulnerability in the wild.