Security News

Effects of the 2011 DigiNotar Attack (Schneier on Security)
2016-12-29 12:50

Nice article on the 2011 DigiNotar attack and how it changed security practices in the CA industry....

PHPMailer Bug Leaves Millions of Websites Open to Attack (Threatpost)
2016-12-27 18:22

A critical PHPMailer bug tied to the way websites handle email and feedback forms is leaving millions of websites hosted on popular web-publishing platforms such as WordPress, Drupal and Joomla...

Highly lucrative Ransomware as a Service attacks poised to accelerate in 2017 (Help Net Security)
2016-12-19 12:30

Ransomware can be likened to global warming. It’s been around for years, but it’s now becoming an epidemic which needs serious attention. According to a recent survey conducted by Osterman...

SQL Injection Attack is Tied to Election Commission Breach (Threatpost)
2016-12-17 14:00

A hacker offered to sell an unpatched system vulnerability in the U.S. Election Assistance Commission website on the Dark Web for “thousands” of dollars.

Corporate Office 365 users hit with clever phishing attack (Help Net Security)
2016-12-14 15:01

Corporate Office 365 users are being targeted by phishers using a clever new trick to bypass email filters and the default security protections of the Microsoft service. The attack comes in the...

DDoS attacks via WordPress now come with encryption (Help Net Security)
2016-12-14 13:51

Kaspersky Lab experts have noted an emerging trend – a growth in the number of attacks using encryption. Such attacks are highly effective due to the difficulty in identifying them amongst the...

Adobe Patches 31 Vulnerabilities, Flash Zero-Day Under Attack (Threatpost)
2016-12-13 18:00

As part of Patch Tuesday Adobe patched a zero-day vulnerability in Flash Player the company claims is being used in targeted attacks against Internet Explorer users on Windows.

Solar Power Firm Patches Meters Vulnerable to Command Injection Attacks (Threatpost)
2016-12-08 13:30

Locus Energy has patched 100,000 of its residential and commercial power meters that were vulnerable to command injection attacks and code execution.

Next year, attacks will differentiate to penetrate new vulnerable surfaces (Help Net Security)
2016-12-08 13:00

The upcoming year will include an increased breadth and depth of attacks, with malicious threat actors differentiating their tactics to capitalize on the changing technology landscape, according...

PoS attacks: Undetected vulnerabilities lay in wait (Help Net Security)
2016-12-08 12:45

Attivo Networks issued a report detailing severe vulnerabilities in the nation’s POS systems that could lead to large breaches during the Holiday shopping period and on into next year. The report,...