Security News > 2017 > September

Backdoor Masquerades as Popular WordPress Plugin
2017-09-29 14:10

A fake WordPress plugin containing a backdoor attempts to trick users into believing it is a version of a popular plugin that has over 100,000 installs. read more

Legitimate VMware Binary Abused for Banking Trojan Distribution
2017-09-29 13:45

A recently discovered banking Trojan campaign has been abusing a legitimate VMware binary to trick security products into allowing malicious binaries to load, Cisco researchers reveal. read more

New infosec products of the week​: September 29, 2017
2017-09-29 13:15

Fortanix launches runtime encryption using Intel SGX Fortanix’ Self-Defending Key Management Service (SDKMS) is a cloud service delivering runtime encryption technology to protect applications and...

Threatpost News Wrap, September 29, 2017
2017-09-29 13:00

The macOS Keychain attack, Signal's new private contact discovery service, the Deloitte hack, and a handful of mobile stock trading app vulnerabilities are discussed.

Activists targeted with barrage of creative phishing attempts
2017-09-29 13:00

More often than not, the human element is the weakest link in the security chain. This fact is heavily exploited by cyber attackers, and makes phishing and spear-phishing attempts the most likely...

Senate Passes MAIN STREET Cybersecurity Act for Small Business
2017-09-29 12:49

The U.S. Senate has passed the MAIN STREET Cybersecurity Act on Sept. 28, which will require NIST to "disseminate clear and concise resources to help small business concerns identify, assess,...

NIST Unveils Plan to Get C-Suite Involved in Risk Management
2017-09-29 12:48

Leading the latest edition of the ISMG Security Report: an interview with the National Institute of Standards and Technology's Ron Ross on revised guidance to get C-suite executives to help shape...

Inadequate IT processes continue to create major security and compliance risks
2017-09-29 12:45

The results of a study of more than 900 IT security professionals, conducted by Dimensional Research, spotlights how common security best practices – such as timely removal of access to corporate...

Monero Miner Infects Hundreds of Windows Servers
2017-09-29 12:38

Hundreds of servers have been infected with Monero mining malware after miscreants managed to exploit a vulnerability in Microsoft IIS 6.0, ESET warns. read more

Company directors are increasingly involved with cybersecurity
2017-09-29 12:30

According to a new survey by BDO USA, 79% of public company directors report that their board is more involved with cybersecurity than it was 12 months ago and 78% say they have increased company...