Security News

iOS 9.3.4 Patches Critical Code Execution Flaw (Threatpost)
2016-08-08 13:00

Apple patched a critical iOS memory corruption vulnerability privately disclosed by jailbreak specialists Pangu Team.

PLC-Blaster Worm Targets Industrial Control Systems (Threatpost)
2016-08-05 20:49

Researchers create a self-propagating worm that can infect a Siemens’ PLC and can be programmed to bring an industrial control platform to its knees.

Gunter Ollmann on the Future of Ransomware, Exploit Kits, and IoT (Threatpost)
2016-08-05 16:00

Gunter Ollmann, CSO at Vectra networks, talks to Mike Mimoso about ransomware as a prototype for malware going forward, as well as the long-term future of exploit kits and whether IoT is something...

Apple Launches Bug Bounty with Maximum $200,000 Reward (Threatpost)
2016-08-05 00:30

Apple closed out Black Hat today with a long-awaited announcement that next month it will launch a bug bounty.

Lack of Encryption Leads to Large Scale Cookie Exposure (Threatpost)
2016-08-04 22:14

Two academics discussed just how woefully inadequate some services are encryption-wise in a talk at Black Hat on Thursday.

How Bugs Lead to a Better Android (Threatpost)
2016-08-04 22:05

Google explained during a Black Hat talk its approach to patching Android vulnerabilities and lessons learned post-Stagefright.

Miller, Valasek Deliver Final Car Hacking Talk (Threatpost)
2016-08-04 19:26

Charlie Miller and Chris Valasek explained at Black Hat today how they were able to control steering and the parking brake on a Jeep Cherokee at speed. The two said the talk would be their last on...

Never Trust a Found USB Drive, Black Hat Demo Shows Why (Threatpost)
2016-08-04 15:41

This Black Hat demo sheds light on how quickly an attacker can gain a foothold inside a network by luring victims with malicious “lost” USB drives.

Joshua Drake on Android Security Post-Stagefright (Threatpost)
2016-08-04 15:00

Joshua Drake of Zimperium Labs talks to Mike Mimoso about the last year post-Stagefright, the effectiveness of Google’s monthly patching cycle, and some of the security enhancements forthcoming in...

Researchers Go Inside a Business Email Compromise Scam (Threatpost)
2016-08-04 14:00

Dell SecureWorks today published a report at Black Hat USA 2016 on a Nigerian Business Email Compromise scam called "wire-wire", or “waya-waya.”