Security News > 2017 > August

More on My LinkedIn Account (Schneier on Security)
2017-08-18 19:14

I have successfully gotten the fake LinkedIn account in my name deleted. To prevent someone from doing this again, I signed up for LinkedIn. This is my first -- and only -- post on that account:...

Two Foxit Reader RCE zero-day vulnerabilities disclosed (Help Net Security)
2017-08-18 18:44

Trend Micro’s Zero Day Initiative has released details about two remote code execution zero-day flaws affecting popular freemium PDF tool Foxit Reader. The first one (CVE-2017-10951) is a command...

Vendor Exposes Backup of Chicago Voter Roll via AWS Bucket (Threatpost)
2017-08-18 17:55

Voter registration data belonging to the entirety of Chicago’s electoral roll—1.8 million records—was found a week ago in an Amazon Web Services bucket.

Decryption Key for Apple's SEP Firmware Posted Online (Security Week)
2017-08-18 17:41

What appears to be the decryption key for Apple's Secure Enclave Processor (SEP) firmware was posted online by a hacker going by the name of xerub. read more

Scottish Parliament Repels Brute-Force Email Hackers (InfoRiskToday)
2017-08-18 17:18

Attackers Probe for Weak Passwords; No Accounts CompromisedHackers have been targeting the Scottish Parliament in a "brute force cyberattack" aimed at guessing users' email passwords. Security...

U.S. Military to Create Separate Unified Cyber Warfare Command (Security Week)
2017-08-18 17:11

President Donald Trump ordered the US military on Friday to elevate its cyber warfare operations to a separate command, signaling a new strategic emphasis on electronic and online offensive and...

Hackers Can Hijack Phones via Replacement Screens: Researchers (Security Week)
2017-08-18 17:07

Touchscreens and other components that are often replaced in smartphones and tablets can hide malicious chips capable of giving attackers complete control over the device, warned researchers at...

Patching Against the Next WannaCry Vulnerability (CVE-2017-8620)
2017-08-18 16:43

This month's Microsoft patch updates include one particular vulnerability that is raising concerns: CVE-2017-8620, which affects all versions of Windows from 7 onwards. Microsoft explained, "in an...

China Opens its First 'Cyber Court' (Security Week)
2017-08-18 16:33

China's first "cyber court" was launched on Friday to settle online disputes, as the legal system attempts to keep up with the explosion of mobile payment and e-commerce. read more

It’s Not Exactly Open Season on the iOS Secure Enclave (Threatpost)
2017-08-18 16:00

Despite yesterday's leak of the Apple iOS Secure Enclave decryption key, experts are urging calm over claims of an immediate threat to user data.