Today apple released updates for iTunes, iOS, Safari, OS X El Capitan, tvOS, and watchOS. It is advised that all users of these products install the updates immediately as there were numerous critical vulnerabilities fixed.
May's Microsoft Patch Tuesday is here and there are 16 security updates for Microsoft products. Included in these updates are patches for 8 vulnerabilities labeled as critical because they allow an attacker to perform remote code execution on the vulnerable product.
Adobe has released security updates for Adobe Reader, Acrobat, and Coldfusion. With a whopping 92 vulnerabilities in Reader and Acrobat, with many of them being critical, it is essential that everyone install the latest available update. Furthermore, Adobe released an advisor about a vulnerability currently being used in Adobe Flash
Yesterday US-Cert released a security alert about two new critical vulnerabilities in in QuickTime for Windows. As Apple has announced that they are no longer supporting QuickTime and will not be fixing these vulnerabilities, it is suggested that you uninstall this program from your computer.
Adobe has released an emergency update to resolve critical vulnerabilities in their Adobe Flash Player product. The new version is 21.0.0.213 and resolves critical vulnerabilities that could allow an attacker to remotely take control of your computer.
Adobe released an updated security advisory yesterday regarding a critical vulnerability (CVE-2016-1019) that exists in Adobe Flash Player 21.0.0.197 and earlier versions. Though an emergency update may be released tomorrow, all Flash users are advised to immediately upgrade to the latest version.
A security update has been released for QuickTime that resolves numerous remote code execution and application termination vulnerabilities. QuickTime 7.7.9 has been released to fix these updates and all users are advised to install it immediately.
A security advisory has been released by VMware for a Windows-based guest privilege escalation vulnerability that affects VMware ESXi, Fusion, Player, and Workstation. It is suggested that all users of these products upgrade to the latest patch immediately.
A new zero-day vulnerability was discovered for the Grub bootloader that allows attackers to bypass Grub password authentication. A security notice released by researchers Hector Marco & Ismael Ripoll states that Grub versions 1.98 (December, 2009) through 2.02 (December, 2015) are affected by this bug.