Security News

RIPPER ATM Malware Uses Malicious EVM Chip (Threatpost)
2016-08-29 17:32

RIPPER malware forces ATMs to churn out cash for crooks via a malicious EVM bankcard attack.

Dropbox Forces Password Reset for Older Users (Threatpost)
2016-08-29 13:58

Online storage service Dropbox began notifying users over the weekend that if they haven't updated their password since 2012, they'll be prompted to update it the next time they log in.

Pacemaker Hacking Fears Rise With Critical Research Report (Threatpost)
2016-08-26 18:55

Researcher warn medical devices made by St. Jude Medical are at risk of attacks via SSH certificate reuse vulnerabilities and static credentials that can easily give hackers root access to key...

Threatpost News Wrap, August 26, 2016 (Threatpost)
2016-08-26 13:00

Mike Mimoso and Chris Brook discuss the news of the week, including the latest on ShadowBrokers and Cisco, Sweet32, decryptors for the Wildfire ransomware, and some gaming forum breaches.

Emergency iOS Update Patches Zero Days Used by Government Spyware (Threatpost)
2016-08-25 21:33

Apple rushed an emergency iOS update that patches three zero days being exploited in spyware sold to oppressive governments to monitor human rights activists and journalists.

France, Germany Call for European Decryption Law (Threatpost)
2016-08-25 19:30

France's and Germany's Interior Minister are urging the EU to consider implementing a law to get companies to decrypt encrypted communications.

Keystroke Recognition Uses Wi-Fi Signals To Snoop (Threatpost)
2016-08-25 18:19

Researchers develop WiKey technology that can sniff out keystrokes with 97.5 percent accuracy using an off-the-shelf Wi-Fi router and a $200 laptop.

VMware Patches Flaws in Identity and Cloud Products (Threatpost)
2016-08-25 16:12

VMware this week patched its Identity Manager and vRealize Automation products against privilege escalation and remote code execution vulnerabilities.

Tor Update Fixes ReachableAddresses Problem (Threatpost)
2016-08-25 13:22

Tor updated its software to 0.2.8.7 and fixed a number of issues, including a bug in the ReachableAddresses option that possibly degrades anonymity.

Cisco Begins Patching Equation Group ASA Zero Day (Threatpost)
2016-08-24 21:53

Cisco today began the process of patching a zero-day vulnerability in its Adaptive Security Appliance (ASA) software exposed in the ShadowBrokers data dump.