Security News

Free Tool Detects, Exploits DLL Hijacking Vulnerabilities
2017-10-04 16:05

DLL hijacking is not a new attack vector. It's been around for 20 years or more. It's not easy, but it's very effective. Once achieved it provides stealth and persistence -- precisely those...

Session Hijacking Bug Exposed GitLab Users Private Tokens (Threatpost)
2017-08-31 21:00

GitLab, the popular web-based Git repository manager, fixed a vulnerability recently that could have opened its users up to session hijacking attacks.

Siemens Fixes Session Hijacking Bug in LOGO!, Warns of Man-in-the-Middle Attacks (Threatpost)
2017-08-30 17:11

Siemens fixed a session hijacking vulnerability in its LOGO! logic module Wednesday but says a second issue, one that could help facilitate a man-in-the-middle attack, has no fix currently.

Signed Mughthesec Adware Hijacking Macs for Profit (Threatpost)
2017-08-09 18:25

Mughthesec, a variant of the OperatorMac adware, has been turning hijacked Macs into revenue-generating machines for the authors.

Exposed Verizon customer data could be a shortcut for hijacking many online accounts (Help Net Security)
2017-07-13 03:04

Chris Vickery, director of cyber risk research at UpGuard, has discovered more sensitive information exposed on an unprotected “bucket” on an Amazon AWS server. This time it includes – among other...

Vulnerabilities Expose Oracle OAM 10g to Remote Session Hijacking (Threatpost)
2017-07-12 12:18

Version 10g of Oracle Access Manager suffers from vulnerabilities that could allow an attacker to hijack sessions.

Google’s plan to foil screen-hijacking malware in Android O (Help Net Security)
2017-05-10 20:11

74% of ransomware, 57% of adware, and 14% of banker malware abuse a specific app permission to target nearly 40 percent of all Android users – by overlaying screens, displaying fraudulent ads and...

Session Hijacking, Cookie-Stealing WordPress Malware Spotted (Threatpost)
2017-05-10 20:03

Researchers spotted a strain of cookie stealing malware, injected into a legitimate JavaScript file, masquerading as a WordPress core domain.