Security News

Accurate cross-browser fingerprinting is possible, researchers show (Help Net Security)
2017-01-17 20:09

A group of researchers have come up with a browser fingerprinting technique that can allow interested parties to “identify” users across different browsers (on the same machine). The group –...

DNSChanger Exploit Kit Hijacks Routers, Not Browsers (Threatpost)
2016-12-15 18:56

An exploit kit called DNSChanger is attacking routers, not browsers, through a malvertising campaign.

Alpha Version of Sandboxed Tor Browser Released (Threatpost)
2016-12-12 18:47

A sandboxed alpha version of the Tor Browser was released over the weekend and while there are still some rough edges and bugs, it could be a step toward protecting Tor users from recent...

Google Fixes 12 High-Severity Flaws In Chrome Browser (Threatpost)
2016-12-02 16:45

Chrome 55.0.2883.75 for Windows, Mac, and Linux was released Thursday and patched 36 vulnerabilities, including 12 high-severity flaws eligible for bounties.

Mozilla Patches Firefox Zero Day Used to Unmask Tor Browser Users (Threatpost)
2016-12-01 17:00

Mozilla released a new version of Firefox on Wednesday to address a zero day vulnerability that was actively being exploited to de-anonymize Tor Browser users.

Actively exploited Firefox, Tor Browser 0-day patched, update now! (Help Net Security)
2016-12-01 15:48

Mozilla and the Tor Project have released security updates that fix the Firefox 0-day flaw that was spotted being exploited to de-anonymize Tor Browser users. It is still unknown who started...

Firefox Scrambles to Patch Zero Day Actively Exploiting Tor Browser (Threatpost)
2016-11-30 17:44

A zero-day vulnerability in Firefox, similar to one created by the FBI in 2013, is actively being exploited in the Tor Project’s anonymizing TorBrowser.

Final warning: Popular browsers will soon stop accepting SHA-1 certificates (Help Net Security)
2016-11-17 17:20

Starting with Chrome 56, planned to be released to the wider public at the end of January 2017, Google will remove support for SHA-1 certificates. Other browser makers plan to do the same. “The...

Ransoc browser locker/ransomware blackmails victims (Help Net Security)
2016-11-17 13:30

An unusual combination of browser locker and ransomware, dubbed Ransoc by researchers, is targeting users who visit adult sites. Ransoc targets victims’ reputation The malware is delivered via...

TrickBot Banking Trojan Adds New Browser Manipulation Tools (Threatpost)
2016-11-08 22:16

The banking Trojan TrickBot is evolving fast, according to researchers, and within weeks will expand its victim list and attack scope.