Security News

Dashlane, Researcher at Odds Over Potential Privilege Escalation Vulnerability (Threatpost)
2017-07-24 18:54

Researcher Paulos Yibelo said that Dashlane elected not to patch a vulnerability he disclosed more than a year ago in all versions of the password manager application.

Hacker Admits to Mirai Attack Against Deutsche Telekom (Threatpost)
2017-07-24 18:32

A hacker that goes by the name “BestBuy” admitted to a German court that he was behind an attack last year that knocked over a million Deutsche Telekom customers offline.

macOS Fruitfly Backdoor Analysis Renders New Spying Capabilities (Threatpost)
2017-07-24 13:00

This week at Black Hat, Mac malware expert Patrick Wardle will describe how he used a custom-built command and control server to analyze new spying capabilities in a variant of the FruitFly backdoor.

Trickbot Malware Now Targets US Banks (Threatpost)
2017-07-21 17:50

Researchers with IBM and Flashpoint warn the Trickbot Trojan is growing more potent and now targeting U.S. banks.

Motivation Mystery Behind WannaCry, ExPetr (Threatpost)
2017-07-21 16:31

A shift in APT tactics is emerging as characterized by the destructive ExPetr attacks hidden in ransomware, and WannaCry, which also failed to turn a profit.

Apple Patches BroadPwn Bug in iOS 10.3.3 (Threatpost)
2017-07-20 18:08

Apple released iOS 10.3.3 Wednesday that serves as a cumulative patch update for multiple vulnerabilities including the high-profile BroadPwn bug.

US, European Law Enforcement Shutter Massive AlphaBay Market (Threatpost)
2017-07-20 16:32

U.S. authorities along with law enforcement Europe and Asia announced today the takedown of the dark web’s largest illicit market, AlphaBay.

Tor Project Opens Bounty Program To All Researchers (Threatpost)
2017-07-20 12:42

The Tor Project is launching a public bug bounty program to encourage security researchers to responsibly report issues they find in the software.

Senator Calls For Use Of DMARC To Curb Phishing (Threatpost)
2017-07-19 19:46

Senator Ron Wyden is pushing to mandate government-wide use of the email authentication protocol DMARC “to ensure that hackers cannot send emails that impersonate federal agencies.”

Modified Versions of Nukebot in Wild Since Source Code Leak (Threatpost)
2017-07-19 13:56

Criminals have made use of the leaked source code for the Nukebot banking Trojan, crafting modified versions of the malware to target banks in the U.S. and France.