Security News > 2015 > July

Pinterest Fixes Validation Vulnerability in API (Threatpost)
2015-07-01 16:41

Pinterest recently fixed an issue in the API of its web app that could have allowed remote attackers to compromise emails and carry out session hijacking and phishing attacks.

LifeLock Patches XSS That Could’ve Led to Phishing (Threatpost)
2015-07-01 15:48

Researchers identified a cross-site scripting vulnerability in a page on the LifeLock website that could allow an attacker to create an authentic-looking login page for the service and harvest...

Patched Apple QuickTime Vulnerability Details Disclosed (Threatpost)
2015-07-01 14:09

Researchers at Cisco Talos released details on a use-after-free vulnerability in Apple QuickTime that could lead to remote code execution.

Class-Action Suit Alleges OPM Officials Failed to Protect Employees’ Data (Threatpost)
2015-07-01 14:02

A class-action lawsuit filed by a government employees’ union against the Office of Personnel Management as a result of the massive data breach at OPM that affects more than 18 million people...

4,900 new Android malware strains discovered every day (Help Net Security)
2015-07-01 13:13

G DATA security experts discovered 440,267 new Android malware strains in the first quarter of 2015, which means that a new mobile malware strain for Android was discovered every 18 seconds. "New...

Researchers point out the holes in NoScript's default whitelist (Help Net Security)
2015-07-01 13:03

Security researchers Linus Särud and Matthew Bryant hav recently discovered some pretty big holes in NoScript, a popular Firefox plugin that prevents executable web content such as JavaScript, Java, F...

(IN)SECURE Magazine issue 46 released (Help Net Security)
2015-07-01 12:36

(IN)SECURE Magazine is a free digital security publication discussing some of the hottest information security topics. Issue 46 has been released today. Table of contents:The Art of War applied...

Office of Personnel Management Data Hack (Schneier on Security)
2015-07-01 11:32

I don't have much to say about the recent hack of the US Office of Personnel Management, which has been attributed to China (and seems to be getting worse all the time). We know that government...

Security updates for OS X, iOS fix bucketload of serious bugs (Help Net Security)
2015-07-01 08:30

Apple has released security updates for Safari, OS X Yosemite (and previous OS X versions), and iOS. The OS X update contains fixes for 77 vulnerabilities, many of which can be exploited by attacke...

Researchers eliminate coding errors by using good code from "donor" apps (Help Net Security)
2015-07-01 07:25

The main appeal of open source software is in the fact that its source code can be reviewed by anyone and, theoretically, stealthy backdoors and unintentional errors should be spotted and removed quic...