Security News

RAA Ransomware Composed Entirely of JavaScript (Threatpost)
2016-06-14 16:06

Researchers this week claim they’ve noticed a new strain of ransomware unlike any they’ve seen prior – a type composed entirely of JavaScript.

Meaningful Surveillance Reform Risks Defeat (Threatpost)
2016-06-14 14:20

Meaningful surveillance reform risks defeat if the reintroduction of the Massie-Lofgren amendment to a DoD spending bill is derailed because new US House rule changes.

D-Link Patches Weak Crypto in mydlink Devices (Threatpost)
2016-06-14 14:03

IoT security company Firmalyzer found that mydlink devices from D-Link use weak versions of SSL for remote connections. D-Link has updated its firmware.

Let’s Encrypt Accidentally Spills 7,600 User Emails (Threatpost)
2016-06-13 20:32

Certificate authority Let’s Encrypt blamed a bug for accidentally disclosing the email addresses of a couple thousand of its users this weekend.

Siemens Firmware Updates Patch SIMATIC Vulnerabilites (Threatpost)
2016-06-13 18:13

Siemens has provided firmware updates addressing vulnerabilities in the SIMATIC WinCC flexible and the SIMATIC S7-300 CPU family.

51 Million iMesh Accounts Available on Black Market (Threatpost)
2016-06-13 16:54

Fifty-one million iMesh accounts are for sale on Dark Web for $700, bringing the number of user accounts tied to recent breaches to over 700 million.

One Year After Hack, IRS Debuts Updated Get Transcript Service (Threatpost)
2016-06-13 16:31

More than a year after hackers managed to manipulate the system the Internal Revenue Service has reinstated its Get Transcript service.

Netgear Router Update Removes Hardcoded Crypto Keys (Threatpost)
2016-06-11 13:00

Netgear on Friday released firmware updates for two of its router products lines, patching a hardcoded cryptographic key and an authentication bypass flaw that were reported six months ago.

Decryption Utilities Unlock Files Encrypted by All TeslaCrypt Versions (Threatpost)
2016-06-10 16:16

Cisco released a decryption utility that unlocks files encrypted by all four versions of TeslaCrypt; Kaspersky Lab has also published a similar decryptor.

Threatpost News Wrap, June 10, 2016 (Threatpost)
2016-06-10 14:00

The news from the week is discussed, including how recent data breaches have fed off password reuse and how a university paid $20K after a ransomware attack.