Security News

Range of Mousejack Attack More Than Doubles (Threatpost)
2016-04-19 13:30

Researchers at Bastille said they’ve more than doubled the range with which an attacker can exploit the Mousejack vulnerability.

APT Targeting Tibetans Packs Four Vulnerabilities in One Compromise (Threatpost)
2016-04-19 11:00

Tibetans along with journalists and human rights workers in Hong Kong and Taiwan have been targeted in campaigns using phishing emails laced with Microsoft RTF attachments that exploit four...

Google Alerts, Direct Webmaster Communication Get Bugs Fixed Quickly (Threatpost)
2016-04-18 21:32

Google determined that Safe Browsing warnings correlate with quicker remediation times, though not as quick as direct contact with webmasters who have registered with Google Search Console.

New MIT Scanner Finds Web App Flaws in a Minute (Threatpost)
2016-04-18 19:51

A Berkeley postdoctoral researcher and former MIT student will soon unveil Space, a static-analysis web-application security tool that can find vulnerabilities in a minute.

3.2 Million Servers Vulnerable to JBoss Attack (Threatpost)
2016-04-18 18:11

Cisco Talos said that 3.2 million servers are vulnerable to the JBoss flaw used as the initial point of compromise in the recent SamSam ransomware attacks.

Google Aims For Transparency With New Chrome Web Store Policies (Threatpost)
2016-04-18 16:11

Google put app developers on notice last week, urging them to comply with a new set of privacy policies designed to better promote transparency it plans on enforcing this summer.

Microsoft Wins Widespread Support in Privacy Clash With Government (Threatpost)
2016-04-15 19:22

Privacy advocates are cheering Microsoft’s lawsuit against the US government over data requests.

VMware Patches Critical Session-Handling Vulnerability (Threatpost)
2016-04-15 17:52

VMware fixed a critical vulnerability in one of its products this week that could’ve led to a man in a middle attack if exploited by an attacker.

Short URLs a Big Problem for Cloud Collaboration, Stored Data (Threatpost)
2016-04-15 15:31

A newly published research paper exposes weaknesses in short URLs used by cloud-based services such as OneDrive that put supposedly private data at risk.

Threatpost News Wrap, April 15, 2016 (Threatpost)
2016-04-15 15:08

Mike Mimoso and Chris Brook recap the news of the week, including the Badlock bust, encryption legislation, and cryptoworm ransomware. Mike also discusses last week's Infiltrate Con.