Security News

Windows 10 Security Feature Broken, US-CERT Warns
2017-11-21 13:03

Entropy Alert: Non-Random ASLR Leaves Systems Open To Buffer Overflow AttacksRecent versions of Windows have a security problem: They're not random enough, US-CERT warns. The problem centers on...

US-CERT Warns of ASLR Implementation Flaw In Windows
2017-11-20 22:30

US-CERT is warning of a vulnerability in Microsoft’s implementation of Address Space Layout Randomization that affects Windows 8, Windows 8.1 and Windows 10.

US-CERT: North Korean Hackers Targeting Three Sectors
2017-11-15 19:03

Malware Takes Aim at Financial Services, Aerospace and Telecommunications IndustriesSince last year, North Korean hackers have been targeting businesses in the financial services, aerospace and...

US-CERT Warns of Crypto Bugs in IEEE Standard
2017-11-06 18:15

Weak cryptography in the IEEE P1735 electronics standard allow attackers to recover valuable intellectual property in plaintext from SoCs and integrated circuits.

Don't Delay: Replace Symantec TLS/SSL Certs Now
2017-09-12 16:33

Google Will Slowly Start Pulling the Rug From Under Symantec's Digital CertificatesA major operation to cleanse websites of digital certificates created under questionable circumstances is...

Using Symantec's TLS/SSL Certs? Start Replacing Them. Now.
2017-09-12 13:33

Google Will Slowly Start Pulling the Rug From Under Symantec's Digital CertificatesA major operation to cleanse websites of digital certificates created under questionable circumstances is...

ICS-CERT Warns of CAN Bus Vulnerability (Security Week)
2017-07-31 12:01

The United States Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) issued an alert on Friday to warn relevant industries about a vulnerability affecting the Controller Area...

Google drops the boom on WoSign, StartCom certs for good (ArsTechnica)
2017-07-20 21:57

Citing “certificate misissuance,” Google to expire all certs from offenders by September.

Free Certs Come With a Cost (Threatpost)
2017-07-17 15:44

Leading certificate authority Let’s Encrypt is facing criticism that its rapid growth and eagerness to encrypt internet communications is happening at a cost.

Inadequate Boundary Protections Common in Critical Infrastructure: ICS-CERT (Security Week)
2017-07-14 13:11

The assessments conducted by the U.S. Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) in 2016 showed that inadequate boundary protection has remained the most prevalent...