Security News

Attackers Embracing Steganography to Hide Communication (Threatpost)
2015-11-18 14:42

Encouraged by patterns carried out on a larger scale recently, researchers believe digital steganography has arrived as a legitimate way to hide communication.

Chimera Ransomware Operation Shut Down (Threatpost)
2015-11-18 13:30

Researchers believe the Chimera ransomware operation has been shut down, and that it never could live up to its promise of publishing victims’ data online.

Adobe Pushes Hotfix for ColdFusion (Threatpost)
2015-11-17 19:45

Adobe patched vulnerabilities in ColdFusion, LiveCycle Data Services and Premiere Clip for iOS.

Patched Libpng Vulnerabilities Have Limited Scope (Threatpost)
2015-11-17 18:12

Most applications, including Firefox, are not vulnerable to a pair of memory corruption vulnerabilities patched in the libpng PNG reference library.

Google to Warn Recipients of Unencrypted Gmail Messages (Threatpost)
2015-11-16 20:44

Google announced it will begin rolling out warnings in the coming months to inform users if they've received a message through a non-encrypted connection.

Attackers Can Use SAP to Bridge Corporate, Operational ICS Networks (Threatpost)
2015-11-16 19:34

Research presented during Black Hat Europe demonstrates how attackers can abuse business applications connected to ICS and SCADA gear.

CSRF Flaw Patched in Popular Spring Social Core Library (Threatpost)
2015-11-13 16:08

Spring Social, a popular Java library used for social authentication, patched a risky cross-site request forgery vulnerability.

Researchers Discover Two New Strains of POS Malware (Threatpost)
2015-11-13 14:30

Two new and different strains of point of sale malware have come to light, including one that’s gone largely undetected for the past five years.

One BadBarcode Spoils Whole Bunch (Threatpost)
2015-11-13 13:48

At PacSec 2015, researchers demonstrated attacks using poisoned barcodes scanned by numerous keyboard wedge barcode scanners to open a shell on a machine and virtually type control commands.

Tor: FBI Paid CMU $1 Million to De-Anonymize Users (Threatpost)
2015-11-12 20:15

The Tor Project accuses the FBI of paying Carnegie Mellon University $1 million to attack Tor hidden services and uncloak users of the anonymity network.