Security News > 2017 > January

Threatpost News Wrap, January 27, 2017 (Threatpost)
2017-01-27 07:00

The Star Wars Twitter botnet, the return of Lavabit, a critical Cisco Webex flaw, and the St. Louis Library ransomware story are discussed.

Can you trust your Android VPN client? (Help Net Security)
2017-01-26 21:41

Do you trust your Android VPN client to keep your data secure and your online browsing private? Perhaps you shouldn’t. A group of researchers has analyzed 283 Android apps from Google Play that...

Duress Codes for Fingerprint Access Control (Schneier on Security)
2017-01-26 20:03

Mike Specter has an interesting idea on how to make biometric access-control systems more secure: add a duress code. For example, you might configure your iPhone so that either thumb or forefinger...

Facebook Touts ‘Safer’ Security Key Login (Threatpost)
2017-01-26 19:38

Facebook is letting users tie a physical security key to their account as an added layer of security.

VirLocker ransomware is back, but can be defeated (Help Net Security)
2017-01-26 19:03

VirLocker (aka VirLock, aka VirRansom) is a virulent piece of machine-locking ransomware that has been around for quite some time. It’s actually quite a surprise that it is not more widespread,...

Bill Calls for Study of Cybersecurity Standards for Cars (Threatpost)
2017-01-26 18:55

A bipartisan bill was introduced this week in the House calling for the NHTSA to conduct a study that would determine appropriate cybersecurity standards for motor vehicles.

Analysis of new Shamoon infections (Help Net Security)
2017-01-26 17:24

All of the initial analysis pointed to Shamoon emerging in the Middle East. This however was not the end of the story since the campaign continues to target organizations in the Middle East from a...

Uber.com Backup Bug Nets Researcher $9K (Threatpost)
2017-01-26 16:16

A researcher earned $9K for identifying a XXE vulnerability in third party backup software used by Uber.

Google to Block .js Attachments in Gmail (Threatpost)
2017-01-26 14:53

Citing security concerns, Google announced that it will soon block JavaScript (.js) file attachments in Gmail.

High-Severity Chrome Vulnerabilities Earn Researcher $32K in Rewards (Threatpost)
2017-01-26 14:00

Researcher Mariusz Mlynski found and disclosed four high-severity vulnerabilities in Chrome’s Blink rendering engine, earning himself $32,000 through the Chrome Rewards program.