Security News > 2018 > April

The eternal struggle: Security versus users
2018-04-09 12:00

There’s an old joke that a job in security is a safe place to be grumpy. From what I’ve seen over my career, that is often true. Security people seem to cherish their reputation for being...

5 Facebook facepalms (just last week)
2018-04-09 11:52

Facebook has been in the news of late for all the wrong reasons, and it's only getting worse.

Cinema voucher-pusher tells customers: Cancel your credit cards, we've been 'attacked'
2018-04-09 11:49

Website taken down 'for the foreseeable future' Updated Worker perks-flinger Sodexo has told a number of customers to cancel their credit cards following "a targeted attack" on its cinema vouchers...

Critical Code Execution Flaw Found in CyberArk Enterprise Password Vault
2018-04-09 11:46

A critical remote code execution vulnerability has been discovered in CyberArk Enterprise Password Vault application that could allow an attacker to gain unauthorized access to the system with the...

Hacker mines up to $1 million in Verge after exploiting major bug
2018-04-09 11:42

According to a forum post, a malicious miner appeared to have found a way to subject Verge to a widely-hypothesised blockchain takeover called a “51% attack”.

Thousands of Google employees call for company to cancel Pentagon work
2018-04-09 11:38

Google's helping the Pentagon to build AI for drones, and a vocal group of employees have asked the company to drop the project.

Obscure E-Mail Vulnerability
2018-04-09 11:30

This vulnerability is a result of an interaction between two different ways of handling e-mail addresses. Gmail ignores dots in addresses, so [email protected] is the same as...

April Patch Tuesday forecast: Expect updates for Adobe Flash, others
2018-04-09 11:30

Springtime is here! Although up here in Minnesota you wouldn’t believe it as we received snowfalls that rivaled anything in the past 34 years! As spring arrives you think of all the things you...

There's security – then there's barbed wire-laced pains in the arse
2018-04-09 08:38

How do you strike a balance with compliance and UX? If IT has a reputation as the gatekeeper, the security department is the one providing the locks and barbed wire.…

Here's how hackers are targeting Cisco Network Switches in Russia and Iran
2018-04-09 06:48

Since last week, a new hacking group, calling itself 'JHT,' hijacked a significant number of Cisco devices belonging to organizations in Russia and Iran, and left a message that reads—"Do not mess...