Security News

Authorities Arrest Eight in Tyupkin ATM Malware Takedown (Threatpost)
2016-01-11 17:36

European authorities dismantled a cybercrime ring last week responsible for a series of ATM attacks that ultimately led to "substantial [financial] losses across Europe.”

GM Vulnerability Disclosure Program Lacks Rewards (Threatpost)
2016-01-11 14:19

General Motors' new vulnerability disclosure program does not come with a monetary reward, but the automaker promises not to sue researchers looking for flaws in its products and services.

Older IE Versions Losing Security Support on Tuesday (Threatpost)
2016-01-08 18:41

Tuesday's impending deadline ending security support for Internet Explorer 8, 9 and 10 is putting companies on notices about moving off older versions of the browser.

Threatpost News Wrap, January 8, 2016 (Threatpost)
2016-01-08 17:10

Mike Mimoso and Chris Brook discuss the week in news: How the Dutch are opening encryption with open arms, the end of support for IE 8, 9, and 10, and the latest bounty offered up by Zerodium.

Mozilla Warns of SHA-1 Deprecation Side Effects (Threatpost)
2016-01-07 19:04

Mozilla warns Firefox users that the browser's rejection of new SHA-1 certificates is keeping some users behind security scanners and antivirus software from reaching HTTPS sites.

Time Warner Cable Urges 320,000 Customers to Change Passwords (Threatpost)
2016-01-07 18:54

Roughly 320,000 Time Warner Cable customers are being urged to change their email passwords this week after the company announced Wednesday that hackers may have gained access to them.

WordPress 4.4.1 Update Resolves XSS Vulnerability (Threatpost)
2016-01-07 17:08

Developers at WordPress are warning users of the content management system to download and apply the most recent update, pushed yesterday, to address a cross-site scripting vulnerability.

SLOTH Attacks Up Ante on SHA-1, MD5 Deprecation (Threatpost)
2016-01-07 15:50

Researchers have demonstrated new collision attacks against SHA-1 and MD5 implementations in TLS, IKE and SSH.

All Drupal Versions Susceptible to Code Execution, Credential Theft Vulnerabilities (Threatpost)
2016-01-06 21:34

A number of issues exist in the content management system Drupal that could lead to code execution and the theft of database credentials via a man-in-the-middle attack, a researcher warns.

13 Brain Test Malicous Apps Booted From Google Play (Threatpost)
2016-01-06 21:01

Researchers at mobile security company Lookout found 13 malicious apps on Google Play that are related to the Brain Test malware family.