Security News

Morale Remains Low Around Health and Fitness App Security (Threatpost)
2016-01-14 20:48

According to a recent survey, 86 percent of health apps had at least two critical vulnerabilities and 55 percent of health app users expected their apps to be hacked in the next six months.

OpenSSH Patches Critical Flaw That Could Leak Private Crypto Keys (Threatpost)
2016-01-14 19:33

OpenSSH patched a critical vulnerability that could be exploited by an attacker to force a client to leak private cryptographic keys.

Cisco Patches Hardcoded Password, DoS Vulnerabilities in Software, Devices (Threatpost)
2016-01-14 16:15

Cisco patched two critical vulnerabilities that could lead to complete compromise of any devices running its software, and a hardcoded password issue.

Denial-of-Service Flaw Patched in DHCP (Threatpost)
2016-01-13 15:00

The Internet Systems Consortium (ISC) on Tuesday patched a denial-of-service vulnerability in numerous versions of DHCP.

Curious Tale of a Microsoft Silverlight Zero Day (Threatpost)
2016-01-13 14:01

A Silverlight vulnerability patched yesterday by Microsoft could be tied to a Russian hacker who tried to sell a similar zero day to the Hacking Team.

Microsoft Patches Six Critical Flaws With First Update of 2016 (Threatpost)
2016-01-12 20:41

Microsoft only released nine bulletins for its first Patch Tuesday of 2016, but six of them are marked critical and seven can lead to remote code execution.

Adobe Patches Code Execution Flaws in Reader, Acrobat (Threatpost)
2016-01-12 17:24

Adobe today patched 17 remote code execution vulnerabilities in Acrobat and Reader.

New RAT Trochilus Skilled at Espionage, Evading Detection (Threatpost)
2016-01-12 17:14

Researchers have uncovered a new RAT that can evade sandbox analysis, is adept at carrying out espionage, and is being used in targeted threat operations.

Inexpensive Webcam Turned into Backdoor (Threatpost)
2016-01-12 15:39

Researchers at Vectra Networks describe an attack against an inexpensive webcam and how they were able to turn it into a network backdoor.

Questions Linger as Juniper Removes Backdoored Dual_EC RNG (Threatpost)
2016-01-11 21:48

Juniper Networks has removed the backdoored Dual_EC DRBG algorithm from its ScreenOS operating system, but new developments show Juniper deployed Dual_EC long after it was known to be backdoored.