Security News

Mozilla Patches Certificate Pinning Vulnerability in Firefox (Threatpost)
2016-09-21 12:58

A remote code execution in Firefox caused by the expiration of certificate pins was patched by Mozilla in Firefox 49 and Firefox ESR 45.4.

Apple Squashes 68 Security Bugs With Sierra Release (Threatpost)
2016-09-20 21:14

With the introduction of macOS Sierra 10.12, Apple has patched dozens of security vulnerabilities and also tackled a few Safari 10 bugs to boot.

Mamba Ransomware Encrypts Hard Drives Rather Than Files (Threatpost)
2016-09-20 19:29

A new ransomware strain called Mamba opts to encrypts hard drives rather than individual files and folders stored on the local disk.

Experts Want Transparency From Government’s Vulnerabilities Equities Process (Threatpost)
2016-09-20 18:41

Security and policy experts make another call for additional transparency around the government's Vulnerabilities Equities Process and the zero days it has in its possession.

Tesla Fixes Critical Remote Hack Vulnerability (Threatpost)
2016-09-20 17:06

Researchers were able to remotely brake Tesla model cars as well as freeze control panels and open the rear hatch while driving.

Android Banking Trojan First to Gain Root Privileges (Threatpost)
2016-09-20 15:40

The first mobile banking Trojan that obtains root privileges on Android devices has been seen in the wild.

Vulnerability Patched in WordPress Theme That Allows Unrestricted Uploads (Threatpost)
2016-09-20 14:22

A vulnerability has been patched in a popular WordPress theme called Neosense that allows an attacker to upload code without authentication.

Mozilla Patching Firefox Certificate Pinning Vulnerability (Threatpost)
2016-09-19 20:03

Mozilla is expected tomorrow to patch a critical certificate pinning vulnerability in Firefox’s automated update process for extensions.

Facebook Fixes Vulnerability That Led to Account Takeover, Pays Researcher $16K (Threatpost)
2016-09-19 19:04

Facebook quickly resolved a vulnerability in its Business Manager late last month that could have let an attacker take over any Facebook page.

Spyware Targeting Overseas Travelers Removed from Google Play (Threatpost)
2016-09-19 18:03

Spyware targeting overseas travelers seeking embassy information gets the boot from Google Pay store after a security firm identifies four rogue apps.