Security News

Google Domain Enables HSTS Protection (Threatpost)
2016-08-01 17:54

Google ensures HTTPS connections to its domains with support for HTTP Strict Transport Security, or HSTS.

New Technique Checks Mitigation Bypasses Earlier (Threatpost)
2016-08-01 17:00

Researchers at Endgame are expected at Black Hat to introduce Hardware Assisted Control Flow Integrity (HA-CFI), which leverages features in the micro-architecture of Intel processors for security.

WPAD Flaws Leak HTTPS URLs (Threatpost)
2016-08-01 13:00

Sniffing HTTPS URLs with malicious PAC files gets easier with a new technique that exploits flaws in the Web Proxy AutoDiscovery protocol.

AdGholas Malvertising Campaign Leveraged Steganography, Filtering (Threatpost)
2016-07-29 17:57

For over a year attackers were able to carry out a malvertising campaign that managed to draw between one and five million client hits a day, according to researchers. The scam infected thousands...

New Trojan SpyNote Installs Backdoor on Android Devices (Threatpost)
2016-07-29 16:21

A new SpyNote Trojan can give bad guys control over your phone from the camera, microphone to eavesdropping on phone calls.

Threatpost News Wrap, July 29, 2016 (Threatpost)
2016-07-29 14:45

Mike Mimoso and Chris Brook discuss the news of the week, including a wireless keyboard vulnerability - KeySniffer, NIST's statement on 2FA, a LastPass remote compromise bug, and a new Tor paper.

Google Details Linux Kernel Defenses, New and Old (Threatpost)
2016-07-28 17:23

Developers with Android’s Security Team peeled back some of the layers on the mobile operating system this week; describing the lengths Google goes to protect the Linux kernel.

Petya Sabotages Rival Ransomware Chimera, Leaks Decryption Keys (Threatpost)
2016-07-28 16:16

Petya ransomware developers leak competitor Chimera's decryption keys in an attempt to drive new business to a new Petya and Mischa offering.

LastPass Patches Ormandy Remote Compromise Flaw (Threatpost)
2016-07-28 12:58

LastPass has patched a vulnerability in its Firefox add-on that allows attackers complete remote compromise of the password manager

White House Beefs Up Cyber Threat Response Action Plan (Threatpost)
2016-07-27 20:54

A new White House directive outlines the U.S. cyber threat response strategy along with issuing a color-coded cyber threat schema.