Security News > 2016

Congressional Group Says Encryption Backdoors Are a Bad Idea (Threatpost)
2016-12-22 11:00

Members of the bipartisan encryption working group released a year-end report concluding that encryption backdoor laws would do more harm than good.

New Wave of Hailstorm Spam Pelts Inboxes (Threatpost)
2016-12-21 18:12

Spammers are turning to an old technique known as hailstorm to slip past anti-spam and anti-malware filters to deliver Dridex banking malware and Locky ransomware.

Encryption Working Group Annual Report from the US House of Representatives (Schneier on Security)
2016-12-21 15:25

The Encryption Working Group of the House Judiciary Committee and the House Energy and Commerce Committee has released its annual report. Observation #1: Any measure that weakens encryption works...

Panasonic, IOActive Clash on Vulnerability Report (Threatpost)
2016-12-21 14:00

Panasonic Avionics has pushed back against research released Tuesday by IOActive disclosing vulnerabilities in in-flight entertainment systems.

Wassenaar Renegotiation Will Be in Trump Administration’s Hands (Threatpost)
2016-12-20 20:34

Now that a proposed revision to the Wassenaar Arrangement has been rejected, it will be up to the Trump administration to decide whether to attempt to renegotiate again.

New Decryptor Unlocks CryptXXX v3 Files (Threatpost)
2016-12-20 15:50

Researchers have neutralized the threat of the latest strain of CryptXXX v.3 ransomware, releasing a decryption tool for unlocking files.

Fraudulent Video Ad Bot Rakes in Close to $5 Million Daily (Threatpost)
2016-12-20 14:00

An cybercrime group from Russia earns $3 million to $5 million daily through defrauding major U.S. websites of video ad revenue.

In-Flight Entertainment System Flaws Put Passenger Data at Risk (Threatpost)
2016-12-20 13:10

IOActive researchers disclosed vulnerabilities in Panasonic Avionics In-Flight Entertainment systems that could be abused to manipulate flight data shown to passengers, or steal their personal information.

Mitigating internal risk: Three steps to educate employees (Help Net Security)
2016-12-20 12:15

IT security is usually focused on how to prevent outsiders with malicious intent from causing harm to your IT systems and data. While this is a valid concern, people within organizations who...

Google Releases Crypto Test Suite (Schneier on Security)
2016-12-20 12:12

Google has released Project Wycheproof a test suite designed to test cryptographic libraries against a series of known attacks. From a blog post: In cryptography, subtle mistakes can have...