Security News

Furious Apple revokes Facebook's enty app cert after Zuck's crew used it for privacy slurping
2019-01-30 20:09

Internal FB apps in chaos, lawmakers on warpath Facebook has yet again vowed to "do better" after it was caught secretly bypassing Apple's privacy rules to pay teenagers to install a data-slurping...

Dozens of .gov HTTPS certs expire, websites offline, FBI on ice, IT security slows... Yup, it's day 20 of Trump's govt shutdown
2019-01-11 02:02

Hackers may be rubbing their hands with glee The IT impact of the ongoing partial US federal government shutdown has begun to show up in the form of degraded computer security. According to...

Great, you've moved your website or app to HTTPS. How do you test it? Here's a tool to make local TLS certs painless
2019-01-09 08:04

Breathe easier knowing you've tested your software properly A Google cyrptoboffin is close to releasing a tool that will hopefully make all of us more secure online.…

Route security, Cisco cert expiration, ETSI and middleboxes
2018-11-09 15:20

Oh, and IETF standards got sloshed this week Cisco admins, you thought your week was over, right? Sorry: if you have kit that runs Adaptive Security Appliance software or the Firepower Extensible...

Mozilla grants distrusted Symantec certs a stay of execution, claims many sites yet to make switch
2018-10-11 11:34

Delay 'in the overall best interest' of Firefox users Mozilla has postponed its plans to distrust all legacy digital certificates from Symantec, spreading dismay in security circles.…

It's a cert: Hundreds of big sites still unprepared for starring role in that Chrome 70's show
2018-10-09 16:48

Bloody SSL...it's the final countdown Hundreds of high-profile websites are still unprepared for the total disavowal of legacy Symantec-issued digital certificates that will kick in with the...

How to nab a HTTPS cert for a stranger's website: Step one, shatter those DNS queries...
2018-09-06 10:01

Domain validation systems fooled by boffins Updated Researchers in Germany have discovered how to obtain HTTPS security certificates for web domains they don't own – even if the certs are...

’No questions asked’ Windows code cert slingers 'fuel trade' in digitally signed malware
2018-06-26 06:09

Oh it's for a calculator app? OK, wink wink, say no more Trusted code-signing certificates are being sold to miscreants by allegedly unscrupulous vendors, fueling a growth in digitally signed...

US-CERT warns of more North Korean malware
2018-06-18 03:02

'Typeframe' springs from the same den as 'Hidden Cobra' The United States Department of Homeland Security's Computer Emergency Response Team (US-CERT) has warned against another malware campaign...

New Features Added to CERT Tapioca Tool
2018-05-25 05:30

The CERT Coordination Center (CERT/CC) at Carnegie Mellon University this week announced the launch of a new version of the network traffic analysis tool CERT Tapioca. read more