Security News

Security Firm Under Fire Over Disclosure of AMD Chip Flaws
2018-03-14 11:32

AMD is investigating claims that its processors are affected by more than a dozen serious vulnerabilities, and the company that found the flaws is facing backlash over its disclosure method....

AMD Chipset Flaws Are Real, But Experts Question Disclosure
2018-03-14 11:18

Was AMD Ambushed?A set of vulnerabilities in AMD chipsets that gives attackers enduring persistence on machines appears to be legitimate. But experts are questioning the motivations of the Israeli...

Information Disclosure, DoS Flaws Patched in libcurl
2018-01-25 17:55

The developers of the popular multiprotocol data transfer library libcurl informed users on Wednesday that the latest version addresses two vulnerabilities. read more

Lawmakers Raise Questions About Disclosure of CPU Flaws
2018-01-25 06:10

The U.S. House Energy and Commerce Committee on Wednesday sent letters to several tech giants, raising questions about how the disclosure of the CPU vulnerabilities known as Spectre and Meltdown...

China May Delay Vulnerability Disclosures For Use in Attacks
2017-11-16 20:24

The NSA and CIA exploit leaks have thrown the spotlight on US government stockpiles of 0-day exploits -- and possibly led to this week's government declassification of the Vulnerabilities Equities...

White House Releases VEP Disclosure Rules
2017-11-16 19:19

The White House released a charter document on Wednesday outlining how the U.S. government will disclose cyber security flaws and when it will keep them secret.

SEC Chair Wants More Cyber Risk Disclosure From Public Firms
2017-09-26 17:48

Jay Clayton Testifies Before Senate Banking Committee on SEC, Equifax BreachesPublicly traded companies should do a better job of disclosing cyber risks they face in their filings with the...

SEC Chairman Seeks More Cyber Risk Disclosure (InfoRiskToday)
2017-09-06 13:32

Wall Street Regulator Eyes Cyber Shortfalls, Plus Initial Coin OfferingsThe head of the U.S. Securities and Exchange Commission says publicly traded businesses must better describe their...

US DOJ publishes guidelines for setting up a vulnerability disclosure program (Help Net Security)
2017-08-02 21:35

Instituting a vulnerability disclosure program (aka bug bounty program) that won’t blow up in the organization’s face can be a daunting task. Some will prefer to enlist outside experts to advise...