Security News

D-Link accidentally leaks code-signing certs in its firmware (Help Net Security)
2015-09-18 10:52

Malware peddlers don't always have to steal or buy (from sellers on underground forums) legitimate and valid code-signing certificates to sign their malware with - sometimes the certificates can be fo...

CERT Warns of Slew of Bugs in Belkin N600 Routers (Threatpost)
2015-08-31 20:06

The CERT/CC is warning users that some Belkin home routers contain a number of vulnerabilities that could allow an attacker to spoof DNS responses, intercept credentials sent in cleartext, access...

CERT Warns of Hard-Coded Credentials in DSL SOHO Routers (Threatpost)
2015-08-26 14:33

DSL routers from a number of manufacturers contain hard-coded credentials that could allow a hacker to access the devices via telnet services and remotely control them.

Researcher Says LG App Update Mechanism Doesn’t Verify SSL Cert (Threatpost)
2015-06-29 19:01

Many smartphones manufactured by LG contain a vulnerability that can allow an attacker to replace an APK file with a malicious file of his choice. The problem is the result of several conditions...

Let's Encrypt CA to issue its first cert (Help Net Security)
2015-06-17 12:28

Let's Encrypt, a non-profit certificate authority (CA) set up by the Electronic Frontier Foundation, Mozilla, Cisco, Akamai, IdenTrust, and researchers at the University of Michigan, is finally ready ...

Stolen Foxconn certs used to sign malware used in Kaspersky Lab attack (Help Net Security)
2015-06-16 14:14

After last week's revelation that their corporate network has been hit by APT actors wielding a newer version of the infamous, Stuxnet-related Duqu attack toolkit, Kaspersky Lab researchers have share...