Security News

Bad Code Library Triggers Devil’s Ivy Vulnerability in Millions of IoT Devices (Threatpost)
2017-07-19 10:00

Tens of millions of products ranging from airport surveillance cameras, sensors, networking equipment and IoT devices are vulnerable to a flaw that allows attacks to remotely gain control over...

Oracle Releases Biggest Update Ever: 308 Vulnerabilities Patched (Threatpost)
2017-07-18 20:47

Oracle's July Critical Patch Update included fixes for 308 vulnerabilities, 165 of which are remotely exploitable.

Oracle E-Business Suite Flaw Allows Downloads of Documents (Threatpost)
2017-07-18 19:45

Oracle today in its Critical Patch Update addressed a critical vulnerability in its Oracle E-Business Suite of business applications that allows for the download of business documents.

CoinDash Hacked During its ICO (Threatpost)
2017-07-18 19:02

Hackers hijacked CoinDash’s initial coin offering Monday, stealing $7.7 million in cryptocurrency from the nascent trading platform.

Privacy Activists Suffer Legal Setback In National Security Letter Case (Threatpost)
2017-07-18 18:34

Cloudflare and network operator Credo Mobile suffered a legal defeat when U.S. appeals court ruled to uphold a gag order on FBI surveillance data.

Botnet Tweeting, Spamming Porn Shut Down (Threatpost)
2017-07-17 21:17

Researchers discovered an active Twitter botnet made up of 38,000 bots, generating 8.5 million tweets and netting over 30 million clicks from its victims.

Cisco Patches Another Critical Ormandy Bug in WebEx Extension (Threatpost)
2017-07-17 20:26

Researchers Tavis Ormandy and Cris Neckar privately disclosed a critical vulnerability in Cisco's WebEx extension for Chrome and Firefox that allows for remote code execution.

FreeRADIUS Update Patches Bugs Static Analysis Tools Missed (Threatpost)
2017-07-17 18:09

FreeRADIUS today released an update that patches a number of vulnerabilities uncovered in a commissioned engagement using a customer fuzzer.

Free Certs Come With a Cost (Threatpost)
2017-07-17 15:44

Leading certificate authority Let’s Encrypt is facing criticism that its rapid growth and eagerness to encrypt internet communications is happening at a cost.

NemucodAES Ransomware, Kovter Click-Fraud Malware Spreading in Same Campaigns (Threatpost)
2017-07-14 16:37

Researchers have spotted malicious email campaigns using Zip archives to spread NemucodAES ransomware and the Kovter click-fraud Trojan, simultaneously distributing both pieces of malware.