Security News > 2019 > May

Several Vulnerabilities Found in GE Power Meter Software
2019-05-06 17:34

The GE Communicator software is affected by several vulnerabilities, including the presence of hardcoded credentials and privilege escalation flaws, ICS-CERT revealed last week. read more

Qakbot Trojan Updates Persistence, Evasion Mechanism
2019-05-06 17:11

The Qakbot banking Trojan has updated its persistence mechanism in recent attacks and also received changes that potentially allow it to evade detection, Talos’ security researchers say. Also...

Flaws in D-Link Cloud Camera Expose Video Streams
2019-05-06 17:09

Vulnerabilities in the D-Link DCS-2132L cloud camera can be exploited by attackers to tap into video or audio streams, but could also potentially provide full access to the device.

U.S. Charges Ukrainian for Malvertising
2019-05-06 17:06

A Ukrainian national was indicted in the United States for his role in a years-long, international scheme to infect computers with malware via online advertisements, or malvertising.  read more

Certificate issue disabling add-ons in Firefox and Tor Browser finally fixed
2019-05-06 16:49

Mozilla forces third party add-ons to be digitally signed, though an expired certificate disabled these, causing confusion among users of Firefox and the Tor Browser over the weekend.

Welcome to the Age of the Investigations Platform
2019-05-06 16:40

Remember when we used to believe we could prevent every attack? We focused on prevention, layering defenses so that if one layer failed another would be there to stop the attack. As the years...

Avengers: Endgame Sites Promise Digital Downloads, Deliver Info-Harvesting
2019-05-06 16:00

Web scammers are going after Marvel fans as the movie passes the $2.2 billion box-office mark, making it the second-highest grossing film of all time, behind only Avatar.

Despite Doxing, OilRig APT Group Remains a Threat
2019-05-06 15:33

Researchers Describe What They've Learned From Data DumpDespite a doxing of its targets and tools in March, the advanced persistent threat group known as OilRig remains a significant threat to...

High-Severity PrinterLogic Flaws Enable Remote Code Execution
2019-05-06 15:13

The three flaws enable an unauthenticated attacker to launch remote code execution attacks on printers.