Security News > 2017

Justine Bone on St. Jude Vulnerabilities and Medical Device Security (Threatpost)
2017-01-19 14:00

MedSec CEO Justine Bone talks to Mike Mimoso about the St. Jude Medical vulnerabilities, the considerations her company and Muddy Waters made in short selling St. Jude stock, and the current state...

Growing risk associated with mobile and IoT application security (Help Net Security)
2017-01-19 12:45

Despite widespread concern about the security of mobile and Internet of Things applications, organizations are ill-prepared for the risks they pose, according to research conducted by the Ponemon...

Retailers largely lack on-site security and IT expertise (Help Net Security)
2017-01-19 12:30

A new Cybera survey of more than 50 retail professionals found that many retailers lack the necessary IT staff at the store level to ensure proper solution implementation and security. Key...

Heartbeat as Biometric Password (Schneier on Security)
2017-01-19 12:22

There's research in using a heartbeat as a biometric password. No details in the article. My guess is that there isn't nearly enough entropy in the reproducible biometric, but I might be...

Brian Krebs Uncovers Murai Botnet Author (Schneier on Security)
2017-01-18 23:06

Really interesting investigative story....

Fruitfly: Unusual Mac backdoor used for tightly targeted attacks? (Help Net Security)
2017-01-18 21:43

Researchers have found and analyzed a Mac backdoor that is unusual in many ways. The malware – detected as OSX.Backdoor.Quimitchin by Malwarebytes but dubbed Fruitfly by Apple – is believed to...

Carbanak Using Google Services for Command and Control (Threatpost)
2017-01-18 21:25

Carbanak has surfaced again with new campaigns using Google hosted services such as Forms and Sheets as command and control channels.

Docker Patches Container Escape Vulnerability (Threatpost)
2017-01-18 19:26

Docker has patched a privilege escalation vulnerability that could lead to container escapes, allowing a hacker to affect operations of a host from inside a container.

Samsung SmartCam can be easily hijacked (Help Net Security)
2017-01-18 19:05

At least one type of Samsung SmartCam cameras can be taken over by remote attackers who just need to know the vulnerable camera’s IP address. The remote code execution vulnerability that can be...

Oracle Patches 270 Vulnerabilities in Year’s First Critical Patch Update (Threatpost)
2017-01-18 18:26

Oracle patched 270 vulnerabilities, many remotely exploitable, across 45 different products as part of its quarterly Critical Patch Update (CPU) on Tuesday.