Security News

California Kills Phone Decryption Bill, But Bigger Battles Loom (Threatpost)
2016-04-15 11:00

While civil liberties advocates celebrate the defeat of California bill AB 1681, they caution that the fight to protect encryption from government regulation is not over.

Apple Deprecates QuickTime For Windows, Won’t Patch New Flaws (Threatpost)
2016-04-14 20:48

The Zero Day Initiative has publicly disclosed a pair of serious vulnerabilities in Apple QuickTime for Windows that will not be patched because Apple is deprecating the product.

The Time Has Come to Hack the Planet (Threatpost)
2016-04-14 19:54

In this Threatpost Op-Ed, Katie Moussouris explains the significance of the newly free availability of ISO Standard 29147 Vulnerability disclosure, and why it keeps an important dialogue open...

Katie Moussouris on Hack the Pentagon, Embracing Hackers (Threatpost)
2016-04-14 19:00

Mike Mimoso talks to Katie Moussouris about her newly launched consultancy Luta Security, the Hack the Pentagon bug bounty program, and more.

Banking Trojans Nymaim, Gozi Merge to Steal $4M (Threatpost)
2016-04-14 17:43

“Double-headed beast” Trojan, GozNym, drains $4 million from banks in past two weeks.

Latest Chrome Update Addresses Two High-Severity Vulnerabilities (Threatpost)
2016-04-14 12:00

Google updated Chrome to version 50.0.2662.75, patching 20 vulnerabilities, including two high-severity bugs that qualified for rewards.

Decryption Tool Stifles Jigsaw Ransomware (Threatpost)
2016-04-13 21:25

Jigsaw ransomware makes big data-destructing threats to victims, but its bark may be worse than its bite now that security experts have found a way for victims to decrypt systems for free.

Qbot Malware Morphs Quickly to Evade Detection (Threatpost)
2016-04-13 17:28

Researchers spot new wave of Qbot infections that can shape-shift every six hours to evade detection.

Broken IBM Java Patch Prompts Another Disclosure (Threatpost)
2016-04-13 15:30

Current versions of IBM SDK 7 and SDK 8 remain vulnerable to a 2013 Java vulnerability. Security Explorations discovered the original patch is broken and disclosed details on the flaw and a...

CBS Sports App Transmitted Data Unencrypted (Threatpost)
2016-04-13 13:00

CBS recently fixed a vulnerability in its popular Sports application that could have exposed users to man-in-the-middle attacks and inadvertently leaked personal data.