Security News > 2017 > August

Signed Mughthesec Adware Hijacking Macs for Profit (Threatpost)
2017-08-09 18:25

Mughthesec, a variant of the OperatorMac adware, has been turning hijacked Macs into revenue-generating machines for the authors.

Microsoft fixes 25 critical issues in August Patch Tuesday (Help Net Security)
2017-08-09 17:40

The Microsoft August 2017 Patch Tuesday update has landed and contains patches for 48 vulnerabilities, 25 of which are for critical issues. 27 of the vulnerabilities can be exploited to achieve...

To Manage Risk Understand Adversaries, Not Just Activity in Your Environment (Security Week)
2017-08-09 16:48

Six years ago the US National Institute of Standards and Technology (NIST) put forth a framework for information security continuous monitoring (ISCM), defined as maintaining ongoing awareness of...

Understanding your responsibility and security in the cloud (Help Net Security)
2017-08-09 16:42

In this podcast recorded at Black Hat USA 2017, Chris Drake, CEO at Armor, talks about the difference between security of the cloud and security in the cloud. Here’s a transcript of the podcast...

Mozilla Fixes 29 Vulnerabilities in Firefox, Makes Flash Click-To-Activate (Threatpost)
2017-08-09 16:39

Mozilla fixed three critical vulnerabilities and made Flash click-to-activate by default when it released Firefox 55 on Tuesday

Fighting Against Fileless Attacks (InfoRiskToday)
2017-08-09 15:33

Crowdstrike's Dan Larson on Evolving Threats and DefensesAbout half of today's cyberattacks are malware-free and don't involve having to write any files to disk, says Dan Larson of Crowdstrike....

Mamba Ransomware Resurfaces in Brazil, Saudi Arabia (Threatpost)
2017-08-09 14:06

Researchers at Kaspersky Lab have seen a resurgence of Mamba ransomware pop up recently in Brazil and Saudi Arabia.

IRS Warns of Fake Tax Software Update Scheme (InfoRiskToday)
2017-08-09 13:33

Agency Continues to Battle Identity Theft AttemptsJust in time for the seasonal upgrading of tax software, the IRS is warning of phishing emails purporting to be software updates, but which try to...

NIST Publishes Cybersecurity Workforce Framework (Security Week)
2017-08-09 13:26

NIST Proposes Ways for Organizations to Improve How to Identify, Recruit, Revelop, and Retain Cybersecurity Talent read more