Security News

Eddie Bauer Confirms Payment Card Breach of US, Canadian Stores (Threatpost)
2016-08-22 15:56

Clothing store Eddie Bauer has become the latest retail store to acknowledge that malware has led to a breach of its point of sale systems.

New Brazilian Banking Trojan Uses Windows PowerShell Utility (Threatpost)
2016-08-19 17:00

A new sophisticated banking Trojan targeting Brazilians via a malicious .PIF file that changes browser proxy settings.

Multiple Vulnerabilities Identified in ‘Utterly Broken’ BHU Routers (Threatpost)
2016-08-19 16:57

Researchers have identified a router so fraught with vulnerabilities and so “utterly broken” that it can be exploited to do pretty much anything.

Threatpost News Wrap, August 19, 2016 (Threatpost)
2016-08-19 13:00

Mike Mimoso and Chris Brook discuss the news of the week, including the Shadow Brokers debacle, the VeraCrypt audit, Pokemon ransomware, and a browser address bar vulnerability.

EFF Blasts Microsoft Over ‘Malicious’ Windows 10 Rollout Tactics (Threatpost)
2016-08-18 20:38

EFF holds nothing back when it comes to criticism over Microsoft’s Get Windows 10 app along with new Windows 10 privacy policies.

OIG Report Finds Vulnerabilities in Medicaid Services Agency (Threatpost)
2016-08-18 16:55

Vulnerabilities in Centers for Medicare & Medicaid Services could result in the disclosure of personally identifiable information and the “disruption of critical operations,” a government watchdog...

GPG Patches 18-Year-Old Libgcrypt RNG Bug (Threatpost)
2016-08-18 16:39

New versions of GPG and its crypto library Libgcrypt were released on Wednesday addressing a vulnerability that could allow an attacker to predict Libgcrypt RNG output.

Locky Targets Hospitals In Massive Wave Of Ransomware Attacks (Threatpost)
2016-08-18 15:34

A massive wave of Locky ransomware delivered via DOCM attachments is targeting the healthcare sector this month.

Unsecured DNSSEC Easily Weaponized, Researchers Warn (Threatpost)
2016-08-18 12:18

Researchers this week described how a DNSSEC-based flood attack could easily knock a website offline.

Cisco Acknowledges ASA Zero Day Exposed by ShadowBrokers (Threatpost)
2016-08-17 20:06

Cisco today acknowledged two vulnerabilities in its Adaptive Security Appliance that were leaked in the ShadowBrokers data dump of Equation Group exploits.