Security News

You’ll never guess where Russian spies are hiding their control servers (ArsTechnica)
2017-06-06 22:40

Turla uses social media and clever programming techniques to cover its tracks.

SSH Configuration on Nexpose Servers Allowed Weak Encryption Algorithms (Threatpost)
2017-06-02 16:46

Rapid7 warned this week that its Nexpose appliances were shipped with a SSH configuration that could have let obsolete algorithms be used for key exchange.

Unprotected Hadoop Servers Expose 5 PB of Data: Shodan (Security Week)
2017-06-02 16:46

Hadoop servers that are not securely configured expose vast amounts of data, according to an analysis conducted using the Internet search engine Shodan. read more

WikiLeaks says CIA’s “Pandemic” implant turns servers into malware carriers (ArsTechnica)
2017-06-01 20:08

Latest Vault 7 release exposes operation that infects PCs inside targeted networks.

US Defense Contractor left Sensitive Files on Amazon Server Without Password (The Hackers News)
2017-05-31 11:20

Sensitive files linked to the United States intelligence agency were reportedly left on a public Amazon server by one of the nation's top intelligence contractor without a password, according to a...

Vulnerability opens FreeRADIUS servers to unauthenticated attackers (Help Net Security)
2017-05-30 15:41

A vulnerability in the free, open source FreeRADIUS server could be exploited by remote attackers to bypass authentication via PEAP or TTLS. There is currently no indication that the flaw is being...

Yahoo Retires ImageMagick After Bugs Leak Server Memory (Threatpost)
2017-05-23 18:00

Researcher Chris Evans reported a new bug and showed how also used a previously known flaw in ImageMagick to leak Yahoo server data and steal images and authentication secrets.