Security News

Latest Windows UAC Bypass Permits Code Execution (Threatpost)
2016-08-15 19:35

Researcher Matt Nelson disclosed another Windows UAC bypass that makes use of Event Viewer to hijack registry entries and run code.

Westin, Marriott, Sheraton Hotels Hit By Payment Card Malware (Threatpost)
2016-08-15 16:57

Twenty hotels belonging to HEI Hotels and Resorts have been implicated in a data breach that may have leaked payment data from tens of thousands point of sale purchases.

EU Struggles to Determine Growing Cost of Cyberattacks (Threatpost)
2016-08-12 19:41

EU group attempts to pin down what the rising cost of cyberattacks are on the European Union and come up short on answers as they call for a unified approach to assessing cyber risks and attack mitigation.

Undocumented SNMP String Exposes Rockwell PLCs to Remote Attacks (Threatpost)
2016-08-12 17:00

Industrial control system operators running Rockwell MicroLogix 1400 PLCs have been warned about a vulnerability that exposes these devices in critical industries to attack.

Academics Devise New Way to Steal Data from Air-Gapped Computers (Threatpost)
2016-08-12 15:01

Researchers can exfiltrate data from air-gapped computers using malware to steal it and transmit it to a receiver by manipulating the mechanical movements of a computer’s hard-disk drive.

Key Fob Hack Allows Attackers To Unlock Millions Of Cars (Threatpost)
2016-08-12 13:00

Researchers claim a hack of Volkswagen’s keyless entry systems leave millions of cars vulnerable to attack by and “unskilled adversary.”

New Gmail Alerts Warn of Unauthenticated Senders (Threatpost)
2016-08-11 18:10

Google is rolling out new Gmail security features that warn users if the system could not authenticate the sender of a message.

Microsoft Mistakenly Leaks Secure Boot Key (Threatpost)
2016-08-11 15:31

Microsoft inadvertently published a Secure Boot "golden key" policy that allows for self-signed or unsigned binaries to be loaded on Windows devices.

Bluetooth Hack Leaves Many Smart Locks, IoT Devices Vulnerable (Threatpost)
2016-08-11 15:27

Researchers are sounding an alarm over the growing number of Bluetooth devices used for keyless entry and mobile point-of-sales systems that are vulnerable to man-in-the-middle attacks.

vBulletin Patches Serious Flaw in Forum Software (Threatpost)
2016-08-10 19:25

A serious vulnerability has been patched in forum software made by vBulletin that could allow attackers to scan servers hosting the package and possibly execute arbitrary code.