Security News > 2018 > February

Realistic, well-positioned Reddit clone is out to grab users’ login credentials
2018-02-06 21:09

A convincing clone of the popular social news aggregation and discussion site Reddit has been spotted on the reddit.co domain. The author is obviously counting on users not to spot it for what it...

Behavioral Analytics' Role in Health Data Security
2018-02-06 20:33

Healthcare entities are increasingly considering user and entity behavioral analytics tools because their previous breach prevention and detection efforts have fallen short, says security expert...

TLS-Abusing Covert Data Channel Bypasses Network Defenses
2018-02-06 19:37

Researchers from Fidelis Cybersecurity have discovered a new method of abusing the X.509 public key certificates standard for covert channel data exchange following initial system compromise.  read more

Adobe Patches Flash Zero-Day Exploited by North Korean Hackers
2018-02-06 17:00

Adobe updated Flash Player on Tuesday to address a zero-day vulnerability exploited by what experts believe to be a North Korean hacker group in attacks aimed at individuals in South Korea. read more

Flaw in Grammarly’s extensions opened user accounts to compromise
2018-02-06 16:44

A vulnerability in the Grammarly Chrome and Firefox extensions allowed websites to read users’ authentication tokes and use to them to log in to the users’ Grammarly accounts and access all the...

SSL Increasingly Abused by Malware, Phishing: Report
2018-02-06 16:10

There has been a significant increase in the number of phishing and malware attacks abusing SSL and TLS technology, according to Zscaler’s SSL Threat Report for the second half of 2017. read more

One Computer Can Knock Almost Any WordPress Site Offline
2018-02-06 16:07

As if there aren't enough ways to attack a WordPress site, an Israeli researcher has published details of how almost anyone can launch a denial of service (DoS) attack against almost any WordPress...

Cisco issues new, complete fixes for critical flaw in enterprise security appliances
2018-02-06 16:03

Cisco researchers have identified additional attack vectors and features that are affected by the “perfect 10” remote code execution and denial of service vulnerability they attempted to patch...

Windows 10 Ransomware Protection Easily Bypassed, Researcher Says
2018-02-06 15:36

It’s rather trivial to bypass the anti-ransomware feature that Microsoft introduced in its Windows 10 Fall Creators Update, a security researcher claims.  read more

Cisco Issues New Patches for Critical Firewall Software Vulnerability
2018-02-06 15:34

The vulnerability has a CVSS base score of 10.0, the highest possible, and now affects 15 products.