Security News

ROBOT Attack: 19-Year-Old Bleichenbacher Attack On RSA Encryption Reintroduced
2017-12-12 17:18

A 19-year-old vulnerability has been re-discovered in the RSA implementation from at least 8 different vendors—including F5, Citrix, and Cisco—that can give remote attackers access to encrypted...

Google Patches Critical Encryption Bug Impacting Pixel, Nexus Phones
2017-12-06 19:48

As part of its December Android and Pixel/Nexus security updates, Google has issued patches addressing a bevy of flaws, 11 of which are rated critical.

Amazon Adds New Encryption, Security Features to S3
2017-11-08 14:07

Amazon announced this week that it has added five new security and encryption features to its Simple Storage Service (S3), including one that alerts users of publicly accessible buckets. read more

U.S. Government Warns of Weakness in IEEE Encryption Standard
2017-11-07 19:22

The United States Department of Homeland Security’s US-CERT has issued an alert to warn on cryptographic weaknesses impacting the IEEE P1735 standard, which describes methods for encrypting...

New Amazon S3 encryption and security features introduced
2017-11-07 17:32

Amazon Web Services has announced the availability of five new encryption and security features for the Amazon S3 cloud storage service. These include: Default object encryption; Permission...

IEEE P1735 Encryption Is Broken—Flaws Allow Intellectual Property Theft
2017-11-07 02:31

Researchers have uncovered several major weaknesses in the implementation of the Institute of Electrical and Electronics Engineers (IEEE) P1735 cryptography standard that can be exploited to...

FBI Increases Its Anti-Encryption Rhetoric
2017-10-27 19:45

Earlier this month, Deputy Attorney General Rod Rosenstein gave a speech warning that a world with encryption is a world without law -- or something like that. The EFF's Kurt Opsahl takes it apart...

DUHK Attack Lets Hackers Recover Encryption Key Used in VPNs & Web Sessions
2017-10-24 11:08

DUHK — Don't Use Hard-coded Keys — is a new 'non-trivial' cryptographic implementation vulnerability that could allow attackers to recover encryption keys that secure VPN connections and web...

Week in review: Vulnerable encryption, Mac backdoor, Flash Player 0day exploited in the wild
2017-10-23 02:00

Here’s an overview of some of last week’s most interesting news and articles: Vulnerability in code library allows attackers to work out private RSA keys Researchers have discovered a security...

Researchers Say Faulty Code Jeopardizes Encryption Keys
2017-10-18 12:48

Major Manufacturers Have Patched to Prevent 'ROCA' AttackResearchers say they've identified faulty cryptographic code in microchips made since 2012 by Infineon Technologies, posing risks to...