Security News > 2017 > January

Retailers largely lack on-site security and IT expertise (Help Net Security)
2017-01-19 12:30

A new Cybera survey of more than 50 retail professionals found that many retailers lack the necessary IT staff at the store level to ensure proper solution implementation and security. Key...

Heartbeat as Biometric Password (Schneier on Security)
2017-01-19 12:22

There's research in using a heartbeat as a biometric password. No details in the article. My guess is that there isn't nearly enough entropy in the reproducible biometric, but I might be...

Brian Krebs Uncovers Murai Botnet Author (Schneier on Security)
2017-01-18 23:06

Really interesting investigative story....

Fruitfly: Unusual Mac backdoor used for tightly targeted attacks? (Help Net Security)
2017-01-18 21:43

Researchers have found and analyzed a Mac backdoor that is unusual in many ways. The malware – detected as OSX.Backdoor.Quimitchin by Malwarebytes but dubbed Fruitfly by Apple – is believed to...

Carbanak Using Google Services for Command and Control (Threatpost)
2017-01-18 21:25

Carbanak has surfaced again with new campaigns using Google hosted services such as Forms and Sheets as command and control channels.

Docker Patches Container Escape Vulnerability (Threatpost)
2017-01-18 19:26

Docker has patched a privilege escalation vulnerability that could lead to container escapes, allowing a hacker to affect operations of a host from inside a container.

Samsung SmartCam can be easily hijacked (Help Net Security)
2017-01-18 19:05

At least one type of Samsung SmartCam cameras can be taken over by remote attackers who just need to know the vulnerable camera’s IP address. The remote code execution vulnerability that can be...

Oracle Patches 270 Vulnerabilities in Year’s First Critical Patch Update (Threatpost)
2017-01-18 18:26

Oracle patched 270 vulnerabilities, many remotely exploitable, across 45 different products as part of its quarterly Critical Patch Update (CPU) on Tuesday.

UK users bombarded with scammy offers via Facebook, WhatsApp (Help Net Security)
2017-01-18 14:42

Since the beginning of the year, survey scammers have mounted a veritable onslaught against Facebook and WhatsApp users from the UK. The lure comes in the form of a fake free gift card or voucher...

Open source cybersecurity framework for the automotive industry (Help Net Security)
2017-01-18 14:15

A consortium of researchers announced the development of a universal, free, and open source framework to protect wireless software updates in vehicles. The team issued a challenge to security...