Security News

Embedded Devices Share, Reuse Private SSH Keys, HTTPs Certificates (Threatpost)
2015-11-30 18:15

Thousands of embedded devices share cryptographic keys and certificates, exposing millions of connections to man-in-the-middle attacks.

Data on 5 Million Users Compromised in Breach at Toy Maker VTech (Threatpost)
2015-11-30 18:04

Electronics company VTech, perhaps best known for manufacturing children's toys, announced Monday that information on five million accounts were compromised in a breach this month.

Microsoft Blocking Potentially Unwanted Programs (Threatpost)
2015-11-30 16:33

Microsoft has added opt-in protection for Windows enterprise users that blocks potentially unwanted programs and applications.

Lenovo Patches Vulnerabilities in System Update Service (Threatpost)
2015-11-25 15:00

Lenovo has patched two serious vulnerabilities in Lenovo System Update that can allow hackers elevate privileges and guess admin passwords.

Nuclear Exploit Kit Spreading Cryptowall 4.0 Ransomware (Threatpost)
2015-11-25 12:00

An attacker working off domains belonging to Chinese registrar BizCN has been moving the Cryptowall 4.0 ransomware via the Nuclear Exploit Kit.

United Airlines Slow to Patch Mobile App Vulnerability (Threatpost)
2015-11-24 15:00

A vulnerability reported to United Airlines that could have been exploited to manipulate flight reservations and customer data sat unpatched for almost six months before it was fixed.

Additional Self-Signed Certs, Private Keys Found on Dell Machines (Threatpost)
2015-11-24 12:00

Two more self-signed root certificates and corresponding private keys were found on Dell computers.

Backdoor In A Backdoor Identified in 600,000 Arris Modems (Threatpost)
2015-11-23 21:41

Thousands of cable modems manufactured by the Georgia-based telecom Arris suffer from a series of issues: XSS and CSRF vulnerabilities, hard-coded passwords, and what a researcher is calling a...

Dell Computers Ship with Root Cert, Private Key (Threatpost)
2015-11-23 20:53

Different models of Dell computers have shipped with a preinstalled root certificate and private key, opening the machines up to man-in-the-middle attacks.

Stealthy GlassRAT Spies on Commercial Targets (Threatpost)
2015-11-23 19:58

RSA has uncovered GlassRAT, a spy tool targeting commercial targets that's signed with a stolen certificate from a large developer in China.