Security News

BlackEnergy APT Group Spreading Malware via Tainted Word Docs (Threatpost)
2016-01-28 12:00

Attackers have begun using rigged Microsoft Word documents propagated via spearphishing emails to spread the BlackEnergy Trojan.

Israeli Electric Authority Hit by ‘Severe Cyber Attack,’ Likely Ransomware (Threatpost)
2016-01-27 17:55

Israel’s Electric Authority was hit by what officials are calling a “severe cyber attack." Conflicting reports argue the agency was hit by ransomware.

MiniUPnP Vulnerability Clears Way for Stack Smashing Attack (Threatpost)
2016-01-27 16:00

Cisco has demonstrated an attack against Stack Smashing Protection in Linux systems that is facilitated by a critical vulnerability in MiniUPnP.

Mozilla Patches Critical Vulnerabilities in Firefox 44 (Threatpost)
2016-01-27 15:35

Mozilla has patched a number of critical vulnerabilities in Firefox 44 and Firefox Extended Release 38.6, which were released this week.

Amazon Certificate Manager Brings Free SSL Certs to AWS Users (Threatpost)
2016-01-26 18:14

Amazon's new Certificate Manager is providing SSL certificates for free to AWS customers but experts warn it's only a matter of time before they're exploited.

Government Agencies Audit for Juniper Backdoor (Threatpost)
2016-01-26 15:25

Government agencies have until Feb. 4 to audit their IT infrastructure for the use of backdoored Juniper Networks’ Netscreen firewalls.

Magento Update Addresses XSS, CSRF Vulnerabilities (Threatpost)
2016-01-25 21:31

Magento patched 20 flaws last week, including a stored cross-site scripting (XSS) vulnerability that could have let an attacker take over a site.

Scarlet Mimic Group Behind Four Year Campaign Against Tibetan, Uyghur Activists (Threatpost)
2016-01-25 19:24

Researchers believe a single group, Scarlet Mimic, is responsible for a series of attacks over the years to spy on Tibetan and Uyghur activists.

OpenSSL to Patch Two Vulnerabilities This Week (Threatpost)
2016-01-25 17:59

OpenSSL announced that it will release updates for 1.0.2f and 1.0.1r that patch two high-severity vulnerabilities.

FreeBSD Patches Kernel Panic Vulnerability (Threatpost)
2016-01-25 17:13

FreeBSD has patched a kernel panic vulnerability is versions compiled to support IPv6 and SCTP.