Security News

Apple Must Forever Threat Model Against Itself (Threatpost)
2016-02-25 19:45

The ongoing dispute between the FBI and Apple has brought out the fact that Apple must be part of its own threat model going forward.

Drupal Update Fixes 10 Vulnerabilities, One Critical (Threatpost)
2016-02-25 17:30

Drupal addressed 10 vulnerabilities in the CMS this week, including a critical access bypass issue and another issue that could lead to remote code execution.

Judge Confirms DoD Funded Research to Decloak Tor Users (Threatpost)
2016-02-25 15:51

The Tor Project is dismayed at a District Court judge's confirmation that the government paid Carnegie Mellon University to research how to unmask users on the Tor network.

CTB-Locker/Critroni Finds New Legs Targeting Websites (Threatpost)
2016-02-24 22:29

Researchers are the latest variant of CTB-Locker "CTB-Locker for Websites" because it targets websites, encrypt their content, and demands a 0.4 bitcoin ($425) ransom for access to the decryption key.

FTC And Asus Settle Router Security Case (Threatpost)
2016-02-24 19:24

The U.S. Federal Trade Commission announced a settlement with ASUSTeK Computer over sloppy security settings tied to its routers.

Five-Year ‘Dust Storm’ APT Campaign Targets Japanese Critical Infrastructure (Threatpost)
2016-02-24 19:11

A five-year campaign focused on extracting sensitive information from Japanese oil, gas, and electric utilities through multiple backdoors was outlined by researchers on Wednesday.

Apple Attorney Reveals Dozen Other iPhone Requests from FBI (Threatpost)
2016-02-24 17:46

Apple attorney Marc J. Zwillinger unsealed a response to the court that shows Apple has received a dozen requests to unlock users’ devices since October.

uKnowKids Goes On Attack After Database Of 1,700 Kids Found Insecure (Threatpost)
2016-02-24 14:30

The CEO of uKnowKids attacks a security researcher for alerting him to an insecure database of kids and corporate secrets.

Operation Blockbuster Coalition Ties Destructive Attacks to Lazarus Group (Threatpost)
2016-02-24 13:00

A group of security companies today published evidence linking the Sony hack, Dark Seoul and Operation Troy to the Lazarus Group.

Rogue iOS App Gets Boot After Slipping into App Store (Threatpost)
2016-02-23 16:40

Apple removed an iOS application from its Chinese iTunes App Store that offered Chinese iOS users the ability download pirated apps on non-jailbroken devices.