Security News

SWIFT Warns of Second Bank Attack via PDF Malware (Threatpost)
2016-05-13 16:12

News of yet another attack involving a bank and SWIFT, the financial network used by thousands of banks to transfer funds, came to light Thursday.

Latest Petya Ransomware Strain Comes with a Failsafe: Mischa (Threatpost)
2016-05-13 15:07

The latest Petya ransomware attacks come with a twist; if Petya is not granted privileges to encrypt the Master File Table, it instead installs Mischa ransomware.

Corruption, Code Execution Vulnerabilities Patched in Open Source Archiver 7-Zip (Threatpost)
2016-05-12 19:11

Several vulnerabilities were fixed this week in the file archiver 7-Zip which could have led to arbitrary code execution and file corruption.

Emergency Flash Update Patches Public Zero Day (Threatpost)
2016-05-12 16:55

Adobe pushed out an emergency Flash Player update, patching a zero-day vulnerability. Adobe said a public exploit exists for CVE-2016-4117.

Five Vulnerabilities Fixed In Chrome Browser, Google Pays $20K to Bug Hunters (Threatpost)
2016-05-12 15:58

Google is urging Windows, Mac and Linux users to update their Chrome browser to fix five security holes - two rates as high.

Motion Filed Asking FBI To Disclose Tor Browser Zero Day (Threatpost)
2016-05-12 12:56

Mozilla filed a motion asking the courts to compel the government to turn over details on a zero-day vulnerability in the Tor Browser used to hack visitors to a child pornography website.

Wendy’s Comes Clean On Data Breach (Threatpost)
2016-05-11 21:57

Fast-food chain Wendy’s disclosed 300 of its restaurants were hit with malware tied to a PoS system attack.

Microsoft Zero Day Exposes 100 Companies to PoS Attack (Threatpost)
2016-05-11 17:43

100 North American firms fell victim to a Microsoft zero day exploit targeting retail, restaurant and hospitality verticals.

Viking Horde Malware Co-Ops Android Devices for Ad Fraud (Threatpost)
2016-05-11 16:43

The Viking Horde Android malware campaign can leverage victims' phones for ad fraud, carry out DDoS attacks, send spam, and more, researchers warn.

Attackers Targeting Critical SAP Flaw Since 2013 (Threatpost)
2016-05-11 16:37

Researchers at Onapsis and DHS CERT today published reports describing a critical SAP Invoker Servlet vulnerability that has been used to attack 36 global enterprises spanning 15 critical industries.