Security News

The Changing Face of Pseudo-Darkleech (Threatpost)
2016-07-05 18:31

The chameleon-like pseudo-Darkleech campaign, responsible for prolific exploit kit attacks and ransomware infections, has again made a change to its code that will frustrate researchers.

Chinese Ad Firm Raking in $300K a Month Through Adfraud, Android Malware (Threatpost)
2016-07-05 17:44

The same group of cybercriminals behind YiSpecter, a strain of iOS malware uncovered last year, are also behind a new type of Android malware, HummingBad.

Scope of ThinkPwn UEFI Zero Day Expands (Threatpost)
2016-07-05 16:02

The scope of the ThinkPwn UEFI vulnerability disclosed last week has grown past Lenovo and HP laptop firmware to motherboards sold by Gigabyte.

Locky Variant Zepto Debuts with Big Spam Push (Threatpost)
2016-07-01 18:29

Researchers are keeping a close eye on new ransomware called Zepto that is either a variant of the Locky ransomware or something altogether new.

Siemens Patches Password Reconstruction Vulnerability in SICAM PAS (Threatpost)
2016-07-01 17:05

The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) warned users several builds of energy automation software this week.

LizardStresser IoT Botnet Part of 400Gbps DDoS Attacks (Threatpost)
2016-06-30 23:00

LizardStresser botnet hijacks 1,300 internet-accessible video cameras, enlisting them as pawns in 400Gbps DDoS attacks targeting Brazilian banks and several U.S. gaming firms.

Massachusetts General Hospital Confirms Third-Party Breach (Threatpost)
2016-06-30 21:06

A breach at Massachusetts General Hospital has potentially compromised the information of roughly 4,300 dental patients, the hospital warned Wednesday.

Foxit Patches 12 Vulnerabilities in PDF Reader (Threatpost)
2016-06-30 17:52

Foxit patched a dozen vulnerabilities in its PDF reader software this week, more than half of which could be used to directly execute arbitrary code on vulnerable installations of the product.

Conficker Used in New Wave of Hospital IoT Device Attacks (Threatpost)
2016-06-30 15:48

Conficker returns from obsolescence to help hijack medical devices and steal patient records.

FTC Closes 70 Percent of Data Breach Investigations, Weighing PCI-DSS Standard (Threatpost)
2016-06-29 21:03

The FTC closes roughly 70 percent of the investigations it opens and is weighing how to better handle PCI-DSS and other standards, an agency official said this week.