Security News

Yubico Security Keys with a Crypto Flaw
2019-07-01 10:55

Wow, is this an embarrassing bug: Yubico is recalling a line of security keys used by the U.S. government due to a firmware flaw. The company issued a security advisory today that warned of an...

White House mulls just banning strong end-to-end crypto. Plus: More bad stuff in infosec land
2019-07-01 05:57

We'll be over there bashing our head on the wall while you read this Roundup As June turns over to July, here are some additional bits of security news besides our regular infosec coverage.…

Epyc crypto flaw? AMD emits firmware fix for server processors after Googler smashes RAM encryption algorithms
2019-06-26 20:16

SEV code cracked to leak secret keys Microchip slinger AMD has issued a firmware patch to fix the encryption in its Secure Encrypted Virtualization technology (SEV), used to defend the memory of...

macOS Crypto-Miner Emulates Linux
2019-06-21 14:46

New crypto-currency mining malware is targeting systems running macOS, and works by emulating Linux, Malwarebytes security researchers have discovered. read more

RAMBleed picks up Rowhammer, smashes DRAM until it leaks apps' crypto-keys, passwords, other secrets
2019-06-11 22:26

Boffins blast boards to boost bits Bit boffins from Australia, Austria, and the US have expanded upon the Rowhammer memory attack technique to create more dangerous variation called RAMBleed that...

Someone slipped a vuln into crypto-wallets via an NPM package. Then someone else siphoned off $13m in coins to protect it from thieves
2019-06-07 05:56

What a wild ride, eh Komodo? Blockchain biz Komodo this week said it had used a vulnerability discovered by JavaScript package biz NPM to take control of some older Agama cryptocurrency wallets to...

Mozilla returns crypto-signed website packaging spec to sender – yes, it's Google
2019-05-30 20:58

Ad giant's site slurping tech complicates web security model, could give more power to search engines and social networks, Firefox maker warns Mozilla has published a series of objections to web...

Chinese software nasty enslaves stadium-load of servers, puts them to work digging up digital dosh in crypto-mines
2019-05-30 09:04

Nanshou malware hijacked more than 50,000 MS-SQL boxes with rootkits More than 50,000 servers around the world have been infected with malware that installs crypto-coin-mining scripts and advanced...

Firefox Now Has Fingerprinting and Crypto-mining Protection
2019-05-21 20:33

Mozilla this week released Firefox 67 to the stable channel with improved protection against tracking and with fingerprinting and crypto-mining protection capabilities.  read more

Crypto-chaps on scam rap in a flap over Slack chat tap, want court case zapped: 'Attorney-client priv info' in messages
2019-05-01 21:16

Duo also ask for two-year delay in celeb-studded ICO trial Two men accused of running a cryptocurrency scam have asked for the entire case to be thrown out – because prosecutors may have...