Security News

Apple Updates Xcode’s Git Implementation (Threatpost)
2016-05-04 19:02

Apple has updated its Xcode development environment, patching two vulnerabilities in its implementation of git.

Identity Thieves Used Leaked PII to Steal ADP Payroll Info (Threatpost)
2016-05-04 17:34

Cybercriminals accessed a W-2 portal maintained by payroll company ADP recently to glean sensitive information about employees at a handful of companies.

Public Exploits Available for ImageMagick Vulnerabilities (Threatpost)
2016-05-04 16:17

Public exploits are available for critical ImageMagick vulnerabilities, increasing the risk to websites that use the open source image-processing software.

10-Year-Old Instagram Bug Hunter Earns $10,000 (Threatpost)
2016-05-04 16:15

Facebook says a 10-year-old is the youngest ever to earn a bug bounty for reporting Instagram API bug.

Google Expands Default HTTPS to Blogspot (Threatpost)
2016-05-03 21:17

On Tuesday Google flipped the switch on default HTTPS support for its blog publishing service Blogspot, upping the security ante for millions of its bloggers.

Brazilian Judge Overturns 72-Hour WhatsApp Suspension (Threatpost)
2016-05-03 20:55

A judge in Brazil has overturned another judge's ruling that phone companies there block the popular messaging app WhatsApp from operating for 72 hours.

Brazilian Judge Orders 72-Hour WhatsApp Suspension (Threatpost)
2016-05-03 20:55

A judge in Brazil has again demanded that phone companies there block the popular messaging app WhatsApp from operating for 72 hours.

Linux Foundation Badge Program to Boost Open Source Security (Threatpost)
2016-05-03 18:01

A new CII Best Practices Badge program will help companies, interested in adopting open source technologies evaluate projects based on security, quality and stability.

OpenSSL Patches Two High-Severity Vulnerabilities (Threatpost)
2016-05-03 16:17

The latest batch of OpenSSL security patches were released today, with a pair of high-severity issues and four low-severity issues addressed in OpenSSL 1.0.1t and OpenSSL 1.0.2h.

FreedomPop Account Hijacking Flaws Remain Unpatched (Threatpost)
2016-05-03 15:36

A serious vulnerability in mobile provider FreedomPop has yet to be patched and can be leveraged with online banking flaws to put customer accounts at risk.