Security News

It’s Not Exactly Open Season on the iOS Secure Enclave (Threatpost)
2017-08-18 16:00

Despite yesterday's leak of the Apple iOS Secure Enclave decryption key, experts are urging calm over claims of an immediate threat to user data.

Threatpost News Wrap, August 18, 2017 (Threatpost)
2017-08-18 13:30

Mike Mimoso and Tom Spring discuss this week's security news, including a discussion on recent hijacking of popular Chrome extensions and Adobe's decision to end-of-life Flash Player.

Hacker Publishes iOS Secure Enclave Firmware Decryption Key (Threatpost)
2017-08-18 00:32

A hacker identified only as xerub published the decryption key unlocking the iOS Secure Enclave Processor.

Cisco Patches Privilege Escalation Bugs in APIC (Threatpost)
2017-08-17 19:55

Cisco patched two high-severity vulnerabilities in its Cisco Application Policy Infrastructure Controller (APIC) that could allow an attacker to elevate privileges on the host machine.

Drupal Patches Critical Access Bypass in Core Engine (Threatpost)
2017-08-17 19:50

A critical flaw in Drupal CMS platform could allow unwanted access to the platform allowing a third-party to view, create, update or delete entities.

Rowhammer Attacks Come to MLC NAND Flash Memory (Threatpost)
2017-08-17 17:48

IBM researchers have demonstrated a filesystem-level version of the Rowhammer attack against MLC NAND flash memory.

Locky Ransomware Variant Slips Past Some Defenses (Threatpost)
2017-08-16 21:41

Ransomware called IKARUSdilapidated is managing to slip into unsuspecting organizations as an unknown file.

Flash’s Final Countdown Has Begun (Threatpost)
2017-08-16 17:59

The impending demise of Adobe Flash will create legacy challenges similar to Windows XP as companies begin to wean themselves off the vulnerable code base.

Maersk Shipping Reports $300M Loss Stemming from NotPetya Attack (Threatpost)
2017-08-16 17:33

A.P. Moller -Maersk said June's NotPetya wiper malware attacks would cost the world's largest shipping container company $300M USD in lost revenue.

Google Removes Chrome Extension Used in Banking Fraud (Threatpost)
2017-08-16 15:14

Google has removed the Interface Online Chrome extension from the Chrome Web Store. The plugin was used by criminals in Brazil to target corporate users with the aim of stealing banking credentials.