Security News

WordPress Infections Leading to TeslaCrypt Ransomware (Threatpost)
2016-02-05 12:00

A massive string of WordPress compromises are redirecting victims to the Nuclear Exploit Kit and Teslacrypt ransomware.

Government Promises Comment Period on Next Wassenaar Draft (Threatpost)
2016-02-04 20:51

A National Security Council member promised Rep. Jim Langevin that a final U.S. rule on the Wassenaar Arrangement would not happen without another public comment period.

Netgear Management System Vulnerable to RCE, Path Traversal Attacks (Threatpost)
2016-02-04 18:05

Netgear's Network Management System suffers from two vulnerabilities, an arbitrary file upload and a path traversal, which could let a remote attacker execute code and download files.

Google Safe Browsing Extends to Deceptive Embedded Content (Threatpost)
2016-02-04 12:31

Google again has enhanced its Safe Browsing service with protection against deceptive embedded content.

Chromodo Browser Disables Same-Origin Policy (Threatpost)
2016-02-03 18:19

Security vendor Comodo has been caught in an embarrassing gaffe. The Chromodo browser installed by default with Comodo Internet Security disables the same-origin policy.

WordPress Update Fixes SSRF, Open Redirect Vulnerability (Threatpost)
2016-02-03 17:11

WordPress' latest version, 4.4.2, fixes a handful of bugs and vulnerabilities in the content management system.

eBay Vulnerability Exposes Users to Phishing, Data Theft (Threatpost)
2016-02-02 21:56

Researchers are warning that visitors to eBay.com could be tricked into opening a page on the site that could expose them to phishing attacks and data theft.

URLZone Back, Targeting Banks in Japan (Threatpost)
2016-02-02 18:00

The gang behind the banking Trojan URLZone has become more active over the past few months and taken aim at banks across Europe and beginning last month, Japan.

Socat Warns Weak Prime Number Could Mean It’s Backdoored (Threatpost)
2016-02-02 15:43

Socat published a security advisory warning users that a hard-coded 1024 Diffie-Hellman prime number was not prime, and that an attacker could listen and recover secrets from a key exchange.

Toys Patched Against Flaws That Put Children’s Data, Safety At Risk (Threatpost)
2016-02-02 14:00

Researchers at Rapid7 disclosed details on patched vulnerabilities in the Web APIs of toys from Fisher-Price and hereO that exposed the personal data of children.