Security News > 2017

Google Patches 29 Critical Android Vulnerabilities Including Holes in Mediaserver, Qualcomm (Threatpost)
2017-01-04 18:33

Google patched a critical hole in its problematic Android Mediaserver component that could have allowed an attacker to use email, web browsing, and MMS processing of media files to remotely execute code.

Costin Raiu on the Importance of Using YARA (Threatpost)
2017-01-04 14:30

Kaspersky Lab's Costin Raiu talks about the benefits of taking the YARA training class available at SAS 2017.

Are We Becoming More Moral Faster Than We're Becoming More Dangerous? (Schneier on Security)
2017-01-04 13:42

In The Better Angels of Our Nature, Steven Pinker convincingly makes the point that by pretty much every measure you can think of, violence has declined on our planet over the long term. More...

What developers and managers are saying about application security challenges (Help Net Security)
2017-01-04 12:30

Despite showing moves toward earlier and more frequent security testing throughout the development process, there are still hurdles development and security teams must overcome when it comes to...

Box.com Plugs Account Data Leakage Flaw (Threatpost)
2017-01-03 21:28

Confidential documents and data belonging to Box.com users were accessible via search engine queries. Box.com has "fixed" the issue.

Vermont Grid ‘Hack’ Latest Tumble Down Attribution Rabbit Hole (Threatpost)
2017-01-03 20:56

The rush to connect a security incident at a Vermont utility to Russian government hackers is more evidence of the challenges around attribution.

Pentagon Subcontractor Inadvertently Leaks 11 Gigs of Sensitive Data (Threatpost)
2017-01-03 20:40

A security researcher claims that data belonging to doctors deployed in the United States Special Operations Command was left unsecured online.

More attacks, new technologies: Cybersecurity predictions for the year ahead (Help Net Security)
2017-01-03 13:00

Every day, the cybersecurity landscape changes. Each new device connected to the network presents a new target for attackers that needs to be secured, and each new social media post creates new...

Class Breaks (Schneier on Security)
2017-01-03 12:50

There's a concept from computer security known as a class break. It's a particular security vulnerability that breaks not just one system, but an entire class of systems. Examples might be a...

Enhanced security facilitates your safe move to the cloud (Help Net Security)
2017-01-03 12:45

If you haven’t moved at least some of your data to the cloud, you will. It’s inevitable at this point. Even the most highly secured organizations have some of their data on the cloud. What happens...