Security News

No Simple Fix for Password Reuse (Threatpost)
2016-06-08 14:24

The result of the recent LinkedIn, Tumblr and Myspace breaches will be a virtual crime wave as hackers take stolen credentials and unlock other accounts across the web, say experts.

Google To Deprecate SSLv3, RC4 in Gmail IMAP/POP Clients (Threatpost)
2016-06-08 12:28

Google will next week begin a gradual deprecation of unsafe crypto protocol SSLv3 and cipher RC4 in Gmail IMAP/POP clients.

The Illusion Of An Encrypted Internet (Threatpost)
2016-06-07 16:56

Rapid7 released its National Exposure Index, which measures the top 30 ports and protocols on IPv4 and quantifies unsecured services running on the Internet.

Uber Pays Researcher $10K for Login Bypass Exploit (Threatpost)
2016-06-07 16:48

Uber patched a bug in its site recently that could have allowed an attacker to log into some of its sites without a password and further compromise its internal network.

Facebook Messenger Vulnerability Patched (Threatpost)
2016-06-07 14:14

Facebook has patched a vulnerability in its desktop and mobile Messenger apps that allows an attacker to modify chats and expose victims to malware and fraud.

Mitsubishi Hybrid SUV Hack Puts Drivers At Risk, Says Researcher (Threatpost)
2016-06-07 12:00

Researchers discover a vulnerability in Mitsubishi's Outlander Hybrid SUV that allows hackers to disable the anti-theft alarm from a laptop and control the car's heat and AC.

Password Autocorrect Without Compromising Security (Threatpost)
2016-06-06 18:15

Academics have developed a framework for typo-tolerant passwords that significantly enhances usability without compromising security.

Latest Android Security Bulletin Heavy on Critical Qualcomm Flaws (Threatpost)
2016-06-06 18:00

Google's monthly Android Security Bulletin patches eight critical vulnerabilities, including a half-dozen in various Qualcomm drivers, Mediaserver, and libwebm.

100M ‘Russian Facebook’ Credentials For Sale (Threatpost)
2016-06-06 17:27

Hackers infiltrated the European social network VK.com at some point over the last several years and made off with credentials for 100 million of its users.

New Angler Exploits Bypass EMET Mitigations (Threatpost)
2016-06-06 17:21

New Microsoft Silverlight and Adobe Flash exploits included in the Angler Exploit Kit have the ability to bypass Microsoft EMET on Windows machines.