Security News

Bug in Symantec’s anti-virus engine can lead to system compromise (Help Net Security)
2016-05-17 15:48

Google Project Zero researcher Tavis Ormandy has unearthed a critical remote code execution vulnerability in the anti-virus engine powering Symantec’s endpoint security products (including...

SAP vulnerability exploited to compromise enterprises worldwide (Help Net Security)
2016-05-11 21:50

A SAP vulnerability, patched over five years ago, is being leveraged to exploit SAP systems of many large-scale global enterprises, US-CERT warns. At least 36 organizations in the US, the UK,...

Misunderstanding Indicators of Compromise (Threatpost)
2016-04-21 13:00

In this Threatpost op-ed, Dave Dittrich and Katherine Carpenter explain the dangers of conflating measurable events, or observables, with indicators of compromise, which require context and other...

APT Targeting Tibetans Packs Four Vulnerabilities in One Compromise (Threatpost)
2016-04-19 11:00

Tibetans along with journalists and human rights workers in Hong Kong and Taiwan have been targeted in campaigns using phishing emails laced with Microsoft RTF attachments that exploit four...

Facebook Fixes Instagram Vulnerability That Opened 1M Accounts to Compromise (Threatpost)
2016-03-28 18:58

Facebook was quick to fix an issue earlier this month that could’ve let an attacker break into four percent of all active, locked accounts.

Emergency Java update plugs system compromise hole (Help Net Security)
2016-03-24 16:50

Oracle has issued an emergency security update for Java to plug a critical flaw (CVE-2016-0636) that could be exploited by luring users to visit a web page hosting the exploit. Oracle has chosen...

Patched Apple Bug Paved Way to Root Compromises (Threatpost)
2016-03-24 14:18

Apple patched an OS X vulnerability in a kernel driver that could give attackers root-level privileges on a Mac computer, researchers at Cisco Talos said.