Security News

Android Ransomware Attacks Using Towelroot, Hacking Team Exploits (Threatpost)
2016-04-25 19:36

Drive-by exploits install ransomware on outdated Android devices using a stolen Hacking Team exploit and the first weaponized Towelroot attack.

One Million Access Facebook Over Tor (Threatpost)
2016-04-25 19:11

Facebook reports that for the first time in a given 30-day period, more than one million people access the social network over Tor.

Attackers Behind GozNym Trojan Set Sights on Europe (Threatpost)
2016-04-25 18:35

The banking malware GozNym has spread into Europe and begun plaguing banking customers in Poland with redirection attacks, IBM said.

Bangladesh Bank Hackers Accessed SWIFT System to Steal, Cover Tracks (Threatpost)
2016-04-25 16:03

Hackers behind the $81 million heist in February at Bangladesh Bank used a malware toolkit to access the financial institution’s SWIFT payment system

MIT Launches Experimental Bug Bounty Program (Threatpost)
2016-04-22 18:32

The Massachusetts Institute of Technology announced this week that it will launch its own experimental bug bounty program.

Experts Weigh-In Over FBI $1.3 Million iPhone Zero-Day Payout (Threatpost)
2016-04-22 17:55

Was the Federal Bureau of Investigation justified in paying over $1.3 million for a hacking tool that opened the iPhone 5c of San Bernardino terrorist?

Threatpost News Wrap, April 22, 2016 (Threatpost)
2016-04-22 14:21

Mike Mimoso and Chris Brook discuss the news of the week, including BlackBerry CEO's stance on lawful access principles, the FBI/Apple hearing, Viber adding end-to-end crypto, Teslacrypt, and more.

Core Windows Utility Can Be Used to Bypass AppLocker (Threatpost)
2016-04-22 00:38

A researcher has discovered that Windows’ Regsvr32 can be used to download and run JavaScript and VBScript remotely from the Internet, bypassing AppLocker’s whitelisting protections.

PoS Attacks Net Crooks 20 Million Stolen Bank Cards (Threatpost)
2016-04-21 19:31

A report released Thursday shines a bright light on point-of-sales system attack targeting hospitality and retail businesses that could of given earned cyber crooks a $400 million payday.

Adobe Patches DOM-XSS Flaw in Analytics AppMeasurement for Flash Library (Threatpost)
2016-04-21 17:08

Adobe today patched a DOM-based cross-site scripting vulnerability in the Adobe Analytics AppMeasurement for Flash library.