Security News

Uber.com Backup Bug Nets Researcher $9K (Threatpost)
2017-01-26 16:16

A researcher earned $9K for identifying a XXE vulnerability in third party backup software used by Uber.

High-Severity Chrome Vulnerabilities Earn Researcher $32K in Rewards (Threatpost)
2017-01-26 14:00

Researcher Mariusz Mlynski found and disclosed four high-severity vulnerabilities in Chrome’s Blink rendering engine, earning himself $32,000 through the Chrome Rewards program.

Researchers predict upsurge of Android banking malware (Help Net Security)
2017-01-23 19:55

Android users, beware: source code and instructions for creating a potent Android banking Trojan have been leaked on a hacker forum, and researchers are expecting an onslaught of malware based on...

Coalition of Cryptographers, Researchers Urge Guardian to Retract WhatsApp Story (Threatpost)
2017-01-20 20:31

A coalition of researchers and cryptographers are urging the Guardian to retract a story it published last week which suggested the encrypted messaging app WhatsApp contained a backdoor.

Facebook, Researcher at Odds Over Messenger Issue (Threatpost)
2017-01-19 15:46

Facebook dismisses a researcher who says multimedia content sent via Facebook Messenger can be intercepted by a third party under certain conditions.

Accurate cross-browser fingerprinting is possible, researchers show (Help Net Security)
2017-01-17 20:09

A group of researchers have come up with a browser fingerprinting technique that can allow interested parties to “identify” users across different browsers (on the same machine). The group –...

Tales of WordPress Plugin Insecurity Overblown, Researchers Say (Threatpost)
2016-12-16 15:00

The insecurity of WordPress plugins has been well documented, especially over the last year, but in the grand scheme of things, it's not as bad as it seems, experts claim.

Yahoo Mail XSS Bug Worth Another $10K to Researcher (Threatpost)
2016-12-09 13:00

Finnish security researcher Jouko Pynnonen found a second stored cross-site scripting vulnerability in Yahoo Mail in less than a year, both of which earned him $10,000 bug bounties.

Researchers Question Security in AMD’s Upcoming Zen Chips (Threatpost)
2016-12-08 18:22

Two German researchers are calling into question the security afforded by AMD’s Secure Encrypted Virtualization feature debuting in the chip maker's upcoming Zen server chips.

Researchers identify domain-level service credential exploit (Help Net Security)
2016-11-17 13:00

CyberArk Labs unveiled new research detailing what it considers to be a significant risk across all Windows endpoints, including those on Windows 10 with Credential Guard enabled. The exploit...