Security News

Microsoft Adds .NET Core, ASP.NET to Bug Bounty Program (Threatpost)
2016-09-02 20:23

Microsoft adds .NET Core and ASP.NET to its bug bounty program offering bug hunters payouts that range from $500 to $15,000.

Android Patch Fixes Nexus 5X Critical Vulnerability (Threatpost)
2016-09-02 16:49

Google patched an undocumented vulnerability that allowed attackers to bypass Nexus 5X device's lock screen via a forced memory dump that exposed the device owner's password.

Apple Patches Trident Vulnerabilities in OS X, Safari (Threatpost)
2016-09-02 14:00

Apple has patched the Trident vulnerabilities in OS X and Safari. The flaws were originally disclosed in iOS and used to spy on a UAE human rights activist.

Threatpost News Wrap, September 2, 2016 (Threatpost)
2016-09-02 13:00

Mike Mimoso, Tom Spring, and Chris Brook discuss the news of the week, including the MedSec/Muddy Waters story, how the Angler EK was traced back to the Lurk Gang, Fairware hitting Linux servers,...

Malvertising Campaign Pushing Neutrino Exploit Kit Shut Down (Threatpost)
2016-09-01 18:46

Researchers uncovered a global malvertising campaign exposing potentially millions of users to the risk of being hit with CrypMIC ransomware delivered via the Neutrino Exploit Kit.

Insecure Redis Instances at Core of Attacks Against Linux Servers (Threatpost)
2016-09-01 17:08

Attackers are targeting insecure Redis instances, exposed to the internet, to access Linux servers and delete web files and folders in exchange for ransom.

Chrome 53 Fixes Address Spoofing Vulnerability, 32 Other Bugs (Threatpost)
2016-09-01 15:52

Google patched 33 bugs in total in Chrome 53, almost half of which are branded high severity by the company.

Patched ColdFusion Flaw Exposes Applications to Attack (Threatpost)
2016-09-01 13:15

Adobe pushed hotfixes to ColdFusion 11 and 10 installations addressing a XXE vulnerability that can be exploited processing OOXML documents.

SWIFT Warns Banks Of More Cyberattacks (Threatpost)
2016-09-01 11:00

Banks face persistent, sophisticated and sustained cyberattacks from hackers looking to exploit the SWIFT messaging network, according to reports.

OneLogin SecureNotes Breach Exposes Data in Cleartext (Threatpost)
2016-08-31 19:04

OneLogin confirmed this week an attacker took advantage of a bug in its system and was able to view sensitive notes, thought to be secure, posted by users.