Security News

Threatpost’s 2015 Year in Review (Threatpost)
2015-12-24 14:00

With 2015 more or less in the rear view mirror Mike Mimoso and Chris Brook discuss the year in security: Wassenaar, ransomware, mobile threats like Stagefright, Carbanak and Equation Group, and more.

Microsoft to Remove Superfish-Like Programs Starting in March (Threatpost)
2015-12-23 14:01

Microsoft said starting March 31, 2016 it will detect and begin removing programs such as Superfish adware that inject ads into browsers and expose users to SSL interception.

Juniper Backdoor Picture Getting Clearer (Threatpost)
2015-12-22 19:29

Crypto and security experts digging into the Juniper backdoor have determined that attackers have subverted an alleged NSA backdoor in the Dual_EC_DRBG algorithm used in NetScreen firewalls.

Yahoo to Warn Users of State-Sponsored Attacks (Threatpost)
2015-12-22 15:43

Yahoo has announced it will follow in the footsteps of Twitter and Facebook and begin warning users when it believes their accounts have been targeted by a state-sponsored actor.

Oracle Settles with FTC Over ‘Deceptive’ Java Security Updates (Threatpost)
2015-12-22 13:39

Oracle will be required to provide users with a mechanism to uninstall older and vulnerable versions of Java, following a settlement with the Federal Trade Commission.

Juniper Backdoor Password Goes Public (Threatpost)
2015-12-21 21:12

The password protecting one of the two Juniper backdoors was published after it was discovered by researchers at Fox-IT and Rapid7.

Google Announces SHA-1 Deprecation Timeline (Threatpost)
2015-12-21 17:02

Despite recently public concerns over the sunsetting of SHA-1, Google announced it will block new SHA-1 certs in Chrome as of Jan. 1, and all SHA-1 certs possibly by July 1, 2016.

Schneider Electric Patches Buffer Overflow in PLC Line (Threatpost)
2015-12-18 17:09

Automation and energy management company Schneider Electric patched a vulnerability in one of its product lines this week that left a handful of programmable automation controllers at risk of being hacked.

Google Search Rankings Prefer HTTPS by Default (Threatpost)
2015-12-18 14:09

Google announce it would, by default, begin giving HTTPS preference in search engine rankings.

Juniper Finds Backdoor that Decrypts VPN Traffic (Threatpost)
2015-12-17 23:30

Juniper Networks has removed "unauthorized code" capable of decrypting VPN traffic that it found in ScreenOS, which runs many of its enterprise-grade NetScreen firewalls.