Security News

FBI Drops its Case Against Apple (Threatpost)
2016-03-22 00:08

The FBI has dropped its case against Apple less than a day before a scheduled court hearing and showdown over its demands that Apple help unlock a terrorist’s iPhone.

BinDiff Now Free, To Delight of Security Researchers (Threatpost)
2016-03-21 20:56

Google's decision to make BinDiff free is being applauded by security researchers.

Apple Patches Serious iMessage Crypto Flaws (Threatpost)
2016-03-21 19:56

Johns Hopkins University researchers disclosed crypto vulnerabilities in iOS that put iMessage security at risk to advanced attackers.

FBI Warning Of Car Hacks A Good Start, Say Security Experts (Threatpost)
2016-03-21 18:32

Security experts applaud the FBI's car-hack warning, but say more needs to be done by the government and car makers to protect drivers.

Yahoo Deploys Passwordless Account Key Tool (Threatpost)
2016-03-21 17:20

Yahoo deployed a stable version of its Account Key mechanism on Friday in hopes of eliminating the password on the company’s mobile apps.

Home Depot Agrees To $19.5 Million Settlement To End 2014 Breach Nightmare (Threatpost)
2016-03-18 20:57

Home Depot agreed to pay $19.5 million to compensate the 40 million cardholders it said were impacted by a massive 2014 data breach.

Pwn2Own Day Two: Safari, Edge Go Down And Winner Crowned (Threatpost)
2016-03-18 14:54

Tencent Security Team Sniper (KeenLab and PC Manager) takes top honors and is Master of Pwn for Pwn2Own 2016 earning $142,500.

Stagefright Variant ‘Metaphor’ Puts Millions Of Samsung, LG and HTC Phones At Risk (Threatpost)
2016-03-17 22:41

Millions of Android users are at risk of a new Metaphor exploit that can take over Samsung, LG and HTC phones in under 20 seconds.

Mitre Takes On Critics, Set To Revamp CVE Vulnerability Reporting (Threatpost)
2016-03-17 19:07

Mitre Corporation will introduce a pilot program for classifying CVEs in response to critics who contend the agency is failing to keep pace with a massive influx CVE number requests.

Scores of Serial Servers Plagued by Lack of Authentication, Encryption (Threatpost)
2016-03-17 16:04

Thousands of serial servers connected to the internet aren't password protected and lack encryption, leaving any data that transfers between them and devices they're connected to open to snooping,...