Security News

Threatpost News Wrap, June 24, 2016 (Threatpost)
2016-06-24 13:00

Mike Mimoso and Chris Brook recap the news of the week, including a Bitcoin phishing campaign, the Kaspersky Lab ransomware report, misconfigured email servers, and a decline in Angler exploit kit traffic.

Popular Anime Site Infected, Redirecting to Exploit Kit, Ransomware (Threatpost)
2016-06-24 11:00

Jkanime, a popular site that streams anime videos, has been infected with malware that redirects to the Neutrino Exploit Kit and CryptXXX ransomware infections.

Necurs Botnet is Back, Updated With Smarter Locky Variant (Threatpost)
2016-06-23 20:10

After a mysterious three weeks off the grid, Necurs has returned to spewing massive volumes of email containing improved versions of the potent Locky ransomware and Dridex banking Trojan.

Mobile Advertising Firm Found Tracking Users To Pay $950K (Threatpost)
2016-06-23 16:06

A mobile advertising company that settled charges with the Federal Trade Commission this week will pay nearly $1M after it was determined the company tracked customers – including children –...

Carbonite Triggers Password Reset for 1.5M Customers After Reuse Attack (Threatpost)
2016-06-23 15:08

Online backup firm Carbonite is forcing all of its 1.5 million users to change their passwords after reporting it was targeted in a password reuse attack.

Unpatched Remote Code Execution Flaw Exists in Swagger (Threatpost)
2016-06-23 13:43

Researchers at Rapid7 found a vulnerability in the Swagger Code Generator that could execute arbitrary code embedded in a Swagger document.

WordPress Security Update Patches Two Dozen Flaws (Threatpost)
2016-06-23 12:00

WordPress updated to version 4.5.3, a security release for all versions.

Let’s Encrypt Celebrates Big HTTPS Milestone (Threatpost)
2016-06-23 11:00

Certificate authority Let’s Encrypt is celebrating a major milestone in the young nonprofit’s existence issuing its 5 millionth certificate this month.

Patched libarchive Vulnerabilities Have Big Reach (Threatpost)
2016-06-22 20:27

Libarchive was patched against three memory-related vulnerabilities, putting pressure on admins to ensure third-party software that also uses the library is patched.

Nuclear, Angler Exploit Kit Activity Has Disappeared (Threatpost)
2016-06-22 19:30

Researchers who study exploit kits are reporting that two major kits, Angler and Nuclear, may no longer be available.