Security News > 2017 > October

Google Bug Tracker Exposed Details of Unpatched Vulnerabilities
2017-10-31 08:55

A bug bounty hunter has earned more than $15,000 from Google after finding several potentially serious vulnerabilities related to the company’s Issue Tracker, including one that exposed the...

Firefox 58 to Block Canvas Browser Fingerprinting By Default to Stop Online Tracking
2017-10-31 03:36

Do you know? Thousands of websites use HTML5 Canvas—a method supported by all major browsers that allow websites to dynamically draw graphics on web pages—to track and potentially identify users...

FireEye Releases Managed Password Cracking Tool
2017-10-31 02:23

FireEye on Monday released a tool designed to help red teams manage password cracking tasks across multiple GPU servers. Called GoCrack, the open source tool provides an easy-to-use, web-based...

Highly Critical Flaw (CVSS Score 10) Lets Hackers Hijack Oracle Identity Manager
2017-10-31 01:01

A highly critical vulnerability has been discovered in Oracle's enterprise identity management system that can be easily exploited by remote, unauthenticated attackers to take full control over...

Cryptocurrency-mining script planted in apps on Google Play
2017-10-30 21:50

Coinhive’s cryptocurrency-mining script has found its way into mobile apps offered on Google Play. Trend Micro researchers have spotted two apps that have been equipped with it: The first...

Google’s reCaptcha Cracked Again
2017-10-30 21:11

Google's reCaptcha service has been cracked by researchers who devised an automated attack called unCaptcha that can break the service with 85 percent accuracy.

Firefox will soon block canvas-based browser fingerprinting attempts
2017-10-30 20:55

Starting with Firefox 58, users will be able to refuse websites’ requests for information extracted via the HTML5 canvas element, which can be used to fingerprint their browsers. What is browser...

Flaw in Google Bug Tracker Exposed Reports About Unpatched Vulnerabilities
2017-10-30 20:39

Google’s Issue Tracker contained until recently a vulnerability that would allow an external party access to any unpatched bug listed and described in the database.

Sage Ransomware Gets Anti-Analysis Capabilities
2017-10-30 19:30

The Sage ransomware, which emerged toward the beginning of this year, has added new functionality that allows it to escalate privileges and evade analysis, Fortinet warns. read more

Which Insurance Would Cover a Breach-Related Injury?
2017-10-30 18:18

Litigation attorney Patricia Carreiro offers an analysis of whether malpractice or cyber insurance coverage - or neither - would come into play if a patient was injured as a result of a...