Security News > 2017 > August

A repair shop could completely hack your phone—and you wouldn’t know it (ArsTechnica)
2017-08-18 12:27

Booby-trapped touchscreens can log passwords, install malicious apps, and more.

Locky Ransomware Returns With Two New Variants (InfoRiskToday)
2017-08-18 11:48

Crypto-Locking Diablo and Lukitus Variants Distributed via Big Spam CampaignsLocky is back. After falling off the radar last year, the ransomware is once again being distributed via massive spam...

Unfixable Automobile Computer Security Vulnerability (Schneier on Security)
2017-08-18 11:40

There is an unpatchable vulnerability that affects most modern cars. It's buried in the Controller Area Network (CAN): Researchers say this flaw is not a vulnerability in the classic meaning of...

Unpatched Code Execution Flaws in Foxit Reader Disclosed (Security Week)
2017-08-18 11:17

Trend Micro’s Zero Day Initiative (ZDI) has disclosed the details of two remote code execution vulnerabilities affecting Foxit Reader. The vendor has decided not to patch the flaws as it believes...

New Exploit Kit: A Closer Look (InfoRiskToday)
2017-08-18 10:48

The latest edition of the ISMG Security Report leads with a closer look at a new exploit kit and whether it represents a resurgence in these types of criminal packages. Also featured: a discussion...

Facebook Awards $100,000 Prize for Spear-Phishing Detection Method (Security Week)
2017-08-18 09:45

Facebook announced on Thursday the winners of its 2017 Internet Defense Prize. A team of researchers from the University of California, Berkeley, and the Lawrence Berkeley National Laboratory...

Android Trojan Now Targets Non-Banking Apps that Require Card Payments (The Hackers News)
2017-08-18 00:56

The infamous mobile banking trojan that recently added ransomware features to steal sensitive data and lock user files at the same time has now been modified to steal credentials from Uber and...

Hacker Publishes iOS Secure Enclave Firmware Decryption Key (Threatpost)
2017-08-18 00:32

A hacker identified only as xerub published the decryption key unlocking the iOS Secure Enclave Processor.

Cisco Patches Privilege Escalation Bugs in APIC (Threatpost)
2017-08-17 19:55

Cisco patched two high-severity vulnerabilities in its Cisco Application Policy Infrastructure Controller (APIC) that could allow an attacker to elevate privileges on the host machine.

Drupal Patches Critical Access Bypass in Core Engine (Threatpost)
2017-08-17 19:50

A critical flaw in Drupal CMS platform could allow unwanted access to the platform allowing a third-party to view, create, update or delete entities.