Security News > 2017 > August

Spambot Contains ‘Mind-Boggling’ Amount of Email, SMTP Credentials (Threatpost)
2017-08-30 16:10

Researchers accessed the Onliner spambot and found 711 million records, including email addresses, email and password combinations, and SMTP credentials and configuration files.

Drone maker DJI launches bug bounty program (Help Net Security)
2017-08-30 13:49

Chinese consumer drone maker DJI has announced that it’s starting a bug bounty program and has invited researchers to discover and responsibly disclose issues that could affect the security of its...

When AI and security automation become foolish and dangerous (Help Net Security)
2017-08-30 13:30

There is a looming fear across all industries that jobs are at risk to artificial intelligence (AI), which can perform those same jobs better and faster than humans. A recent Forrester report...

Breach at Used Tech Goods Seller CeX Exposes Two Million Customers (Security Week)
2017-08-30 13:09

CeX, a second-hand technology goods chain, is notifying up to 2 million of its online customers that their personal details may have been compromised. read more

Why Are We So Stupid About Allowing Overused Passwords? (InfoRiskToday)
2017-08-30 13:03

Organizations Should Blacklist Commonly Used Passwords - But Not All of ThemPassword security guidance: Do block users from picking commonly used passwords. But to avoid a usability nightmare,...

Leveraging social media in advanced threat intelligence (Help Net Security)
2017-08-30 13:00

In this podcast recorded at Black Hat USA 2017, Christian Lees, CISO at InfoArmor, discusses how leveraging social media helps to understand the motives and threat landscape from threat actors....

Snapping Links in the Kill Chain: Lessons Learned from a Stealth Pilot (Security Week)
2017-08-30 11:45

"Adversaries have to build a kill chain. We're not trying to prevent every aspect of that chain, just snap one of those links."  read more

Proof that HMAC-DRBG has No Back Doors (Schneier on Security)
2017-08-30 11:37

New research: "Verified Correctness and Security of mbedTLS HMAC-DRBG," by Katherine Q. Ye, Matthew Green, Naphat Sanguansin, Lennart Beringer, Adam Petcher, and Andrew W. Appel. Abstract: We have...

The NSA's 2014 Media Engagement and Outreach Plan (Schneier on Security)
2017-08-30 11:15

Interesting post-Snowden reading, just declassified. (U) External Communication will address at least one of "fresh look" narratives: (U) NSA does not access everything. (U) NSA does not collect...

Gazer: A New Backdoor Targets Ministries and Embassies Worldwide (The Hackers News)
2017-08-30 10:19

Security researchers at ESET have discovered a new malware campaign targeting consulates, ministries and embassies worldwide to spy on governments and diplomats. Active since 2016, the malware...