Security News

Web body mulls halving HTTPS cert lifetimes. That screaming in the distance is HTTPS cert sellers fearing orgs will bail for Let's Encrypt
2019-08-13 01:43

Expensive renewals once a year... or free certificates any time? Tough choice CA/Browser Forum – an industry body of web browser makers, software developers, and security certificate issuers – is...

Mozilla boots alleged snoop troupe from its root cert coop: UAE-based DarkMatter thrown onto CA blocklist
2019-07-10 01:33

Maker of Firefox fires fox from hen house guard duty Mozilla on Tuesday added digital certificates belonging to security biz DarkMatter and its subsidiaries to Firefox's OneCRL blocklist, based on...

US-Cert alert! Thanks to a massive bug, VPN now stands for "Vigorously Pwned Nodes"
2019-04-12 21:00

Multiple providers leaving storage cookies up for grabs The US-Cert is raising alarms following the disclosure of a serious vulnerability in multiple VPN services.…

US CERT Warns of N. Korean 'Hoplight' Trojan
2019-04-12 15:18

Hidden Cobra, Also Known as Lazarus, Appears to Be Behind the MalwareU.S. CERT has issued a fresh warning about a newly discovered Trojan called Hoplight that is connected to a notorious APT group...

DXC security exec: Yes, I'd have thought we'd spend more on certs and laptop kit for staff, too
2019-03-26 09:08

Boss makes staggering admission during conf-call to discuss impact of latest cost purge: $60m to be cut from infosec division Exclusive A senior exec within DXC Technology's global security...

Google Play Touts Certs in Quest For Enterprise Security
2019-03-22 20:22

Google has snagged three security and privacy certifications for Google Play as it tries to appeal to enterprises despite numerous malicious apps and security issues.

Open-source 64-ish-bit serial number gen snafu sparks TLS security cert revoke runaround
2019-03-13 18:12

64 bits of cert ID on the wall, 64 bits of ID. Take the top bit down, don't pass it around, 63 bits of cert ID on the wall... A bunfight over a controversial UAE mobile security company led to the...

Open-source keygen snafu sparks 63-bit TLS cert revoke runaround
2019-03-13 18:12

What a difference a bit makes. 64 little flowers... brought the revokes and the scowls A mailing list bunfight over a controversial UAE mobile security company led to the discovery that millions...

Week in review: Critical Chrome zero-day, TLS certs for sale on dark web, RSA Conference 2019
2019-03-10 19:30

Here’s an overview of some of last week’s most interesting news and articles: RSA Conference 2018 coverage Check out what you missed at the infosec event of the year. How malware traverses your...

CERT/CC Warns of Vulnerabilities in Marvell Avastar Wireless SoCs
2019-02-08 16:57

The CERT Coordination Center (CERT/CC) has issued a vulnerability note providing information on a series of security issues impacting Marvell Avastar wireless system on chip (SoC) models.