Security News

Starwood Hotel Chain Hit By Point of Sale Malware (Threatpost)
2015-11-23 16:35

Starwood Hotels and Resorts, a company that owns and operates approximately 1,200 hotels across North America, announced last week that a handful of point of sale systems at its hotels were hit by malware.

VMware Patches Pesky XXE Bug in Flex BlazeDS (Threatpost)
2015-11-20 21:36

VMware patched a number of its products vulnerability to an XML External Entities vulnerability in the Apache Flex BlazeDS product integrated into VMware.

German Government Audits TrueCrypt (Threatpost)
2015-11-20 17:39

The German government published the results of its audit of open source disk encryption package TrueCrypt and gave it a relative clean bill of health.

Department of Education Lambasted Over Database Vulnerabilities (Threatpost)
2015-11-20 12:29

The Department of Education was told this week that its failed to heed repeated warnings that its systems contain multiple weaknesses.

FBI Warns Public Officials of Doxing Threat (Threatpost)
2015-11-19 20:31

An FBI advisory warns law enforcement and government officials they could be the targets of hacktivists and doxing.

VirusTotal Adds Sandbox Execution for OS X Apps (Threatpost)
2015-11-19 16:00

Google-owned online malware scanner VirusTotal this week announced the availability of sandbox execution for Mac OS X apps.

LinkedIn Fixes Persistent XSS Vulnerability (Threatpost)
2015-11-19 14:00

LinkedIn fixed a persistent cross site scripting vulnerability in its site this week that could have spread a worm on the service's help forums.

Carnegie Mellon Says It Was Subpoenaed-And Not Paid-For Research On Breaking Tor (Threatpost)
2015-11-18 19:55

Carnegie Mellon University implied in a statement that it received a subpoena requesting its research on breaking Tor hidden services, and also implied it was not paid $1 million for the work as...

Microsoft Cracks Down on Toolbars, Unsigned DLLs with Edge Update (Threatpost)
2015-11-18 19:51

Microsoft claims a recent update to Edge prevents the loading of unsigned DLLs without consent, something that should make it more difficult for an attacker to compromise the browser.

Inside the Conficker-Infected Police Body Cameras (Threatpost)
2015-11-18 16:00

A Florida integrator who discovered the Conficker worm lurking in body cameras meant for police use takes Threatpost inside the story, including a frustrating disclosure with a disbelieving manufacturer.