Security News > 2017 > September

Google Expands HSTS Preload List
2017-09-29 12:29

Google this week announced the addition of more of its top-level domains (TLDs) to the HTTPS Strict Transport Security (HSTS) preload list. read more

Macs Not Receiving EFI Firmware Security Updates as Expected
2017-09-29 12:00

Researchers at Duo Security are expected today at Ekoparty to reveal data and a paper that shows Mac users are not receiving EFI firmware updates at expected.

Whole Foods Market Investigates Hack Attack
2017-09-29 11:18

Payment Card Data Stolen From Taprooms and Restaurants, Supermarket Chain SaysUpscale supermarket chain Whole Foods Market says it's investigating a payment card breach affecting dozens of...

Deloitte Hacked
2017-09-29 11:13

The large accountancy firm Deloitte was hacked, losing client e-mails and files. The hackers had access inside the company's networks for months. Deloitte is doing its best to downplay the...

Millions of Up-to-Date Apple Macs Remain Vulnerable to EFI Firmware Hacks
2017-09-29 10:57

"Always keep your operating system and software up-to-date." This is one of the most popular and critical advice that every security expert strongly suggests you to follow to prevent yourself from...

NIST Unveils Plan to Get C-Suite Involvement in IT Risk Mgt.
2017-09-29 10:47

Leading the latest edition of the ISMG Security Report: an interview with the National Institute of Standards and Technology's Ron Ross on revised guidance to get C-suite executives to help shape...

Sophisticated Phishing Attacks Target Internet Freedom Activists
2017-09-29 10:36

The Electronic Frontier Foundation (EFF) revealed on Wednesday that employees of Internet freedom NGOs “Free Press” and “Fight for the Future” have been targeted in sophisticated spear-phishing...

Beware: Apple's Password Manager Has A Zero-Day Flaw
2017-09-29 10:17

Attackers Can Steal Clear-Text Credentials From the Keychain, Researcher WarnsA zero-day vulnerability in Apple's built-in password manager can be exploited, allowing attackers to steal all stored...

DNSSEC Key Rollover Delayed to Prevent Users Going Offline
2017-09-29 09:03

The Internet Corporation for Assigned Names and Numbers (ICANN) announced this week that the replacement of the root zone key signing key (KSK) for the Domain Name System Security Extensions...