Security News > 2017 > August

Session Hijacking Bug Exposed GitLab Users Private Tokens (Threatpost)
2017-08-31 21:00

GitLab, the popular web-based Git repository manager, fixed a vulnerability recently that could have opened its users up to session hijacking attacks.

Stealthy backdoor used to spy on diplomats across Europe (Help Net Security)
2017-08-31 19:46

A new, sophisticated backdoor Trojan has been used to spy on targets in embassies and consulates across Southeastern Europe and former Soviet Union republics. ESET researchers have analyzed and...

Bugs in Arris Modems Distributed by AT&T Vulnerable to Trivial Attacks (Threatpost)
2017-08-31 18:58

Trivially exploitable vulnerabilities in several Arris home modems, routers and gateways distributed to consumers and small businesses through AT&T’s U-verse service have been discovered.

Attackers exploited Instagram API bug to access users’ contact info (Help Net Security)
2017-08-31 17:54

Instagram has confirmed that “one or more individuals obtained unlawful access to a number of high-profile Instagram users’ contact information — specifically email address and phone number — by...

FDA Recalls 465K Pacemakers Tied to MedSec Research (Threatpost)
2017-08-31 17:26

Abbott Laboratories releases software fixes for pacemakers that could allow an attacker to wirelessly access the devices and steal personal data, drain the battery and disrupt normal...

CIA's "AngelFire" Modifies Windows' Boot Sector to Load Malware (Security Week)
2017-08-31 17:04

Wikileaks on Thursday published documents detailing AngelFire, a tool allegedly used by the U.S. Central Intelligence Agency (CIA) to load and execute implants on Windows-based systems. read more

700 Million Records Found on Server Powering Onliner Spambot (Security Week)
2017-08-31 16:59

A Paris-based malware researcher known as Benkow has discovered more than 700 million records used by the Onliner spambot on a misconfigured server. The records comprise a large number of email...

Former Columbia Sportswear IT Worker Admits to Illegally Accessing Company Network (Security Week)
2017-08-31 16:41

A former employee of Columbia Sportswear pleaded guilty on Wednesday to intentionally accessing the Columbia Sportswear IT network without authorization. read more

Scottish Hospitals Hit by Bitpaymer Ransomware (InfoRiskToday)
2017-08-31 16:33

New Variant of Crypto-Locking Ransomware Evaded DefensesHospitals in Lanarkshire, Scotland, are continuing to recover following an outbreak involving a new variant of Bitpaymer ransomware....