Security News > 2017 > March

SAP Vulnerability Puts Business Data at Risk for Thousands of Companies (Threatpost)
2017-03-22 15:48

Researchers at ERPScan today disclosed details and a proof-of-concept exploit for a SAP GUI remote code execution vulnerability patched last week.

LastPass extensions can be made to cough up passwords, deliver malware (Help Net Security)
2017-03-22 15:40

LastPass Chrome and Firefox extensions contain flaws that could allow malicious websites to steal victims’ passwords or execute commands on their computer. The flaws were discovered by Google...

LastPass Fixes Ormandy RCE Bug; Two Outstanding Vulnerabilities Remain (Threatpost)
2017-03-22 15:08

LastPass has reportedly fixed one of three bugs in the password manager discovered by Google research Tavis Ormandy in the last week.

Deception security doesn’t have to be onerous or expensive (Help Net Security)
2017-03-22 15:00

When talking about deception security, most infosec pros’ mind turns to honeypots and decoy systems – additional solutions that companies have to buy, deploy, and manage. But there are other ways...