Security News > 2017 > November

Bargain Prices: Compromised Credentials for $3 a Pop
2017-11-07 09:18

The ISMG Security Report leads with a discussion about the sale of compromised remote desktop protocol credentials for as little as $3 on darknet marketplaces. Also, grading the performance of DHS...

Newly Uncovered 'SowBug' Cyber-Espionage Group Stealing Diplomatic Secrets Since 2015
2017-11-07 08:15

A previously unknown hacking and cyber-espionage group that has been in operation since at least 2015 have conducted a series of highly targeted attacks against a host of government organizations...

Built-in Keylogger Found in MantisTek GK2 Keyboards—Sends Data to China
2017-11-07 06:16

"The right keyboard can make all the difference between a victory and a defeat in a video game battlefield." If you are a gamer, you can relate to the above quote. But what if your winning weapon...

IEEE P1735 Encryption Is Broken—Flaws Allow Intellectual Property Theft
2017-11-07 02:31

Researchers have uncovered several major weaknesses in the implementation of the Institute of Electrical and Electronics Engineers (IEEE) P1735 cryptography standard that can be exploited to...

Fraud Tied to Billing Software? Lawsuit Raises the Issue
2017-11-06 22:03

Whistle-Blower Claims Epic Systems Software Enables Double-BillingA whistle-blower false claims lawsuit filed against electronic health records vendor Epic Systems raises the issue of whether the...

Security, privacy issues we need to solve before non-medical implants become pervasive
2017-11-06 21:18

The cybernetic revolution is happening, and it’s imperative that civil liberties and privacy issues are addressed by system designers, innovators, regulators, and legislators, says James Scott, a...

New GIBON Ransomware Emerges
2017-11-06 19:58

A newly discovered ransomware family called "GIBON" is targeting all files on machines that it has managed to infect, except those located in the Windows folder. read more

US-CERT Warns of Crypto Bugs in IEEE Standard
2017-11-06 18:15

Weak cryptography in the IEEE P1735 electronics standard allow attackers to recover valuable intellectual property in plaintext from SoCs and integrated circuits.

Qakbot, Emotet Increasingly Targeting Business Users: Microsoft
2017-11-06 18:00

The Quackbot and Emotet information stealing Trojans have been showing renewed activity over the past several months and are increasingly targeting enterprises, small and medium businesses, and...

Tor Browser flaw leaks users’ real IP address
2017-11-06 16:53

The Tor Project has issued an emergency security bugfix release of Tor Browser, to prevent user IP address leakage due to a still unpatched Firefox bug. The bug is present only in the macOS and...