Security News

PageFair Hack Serves Up Fake Flash Update to 500 Sites (Threatpost)
2015-11-03 17:43

500 sites that use the free analytics service PageFair may have been compromised over the weekend.

Vulnerability Identified in Genomic Data Sharing Network (Threatpost)
2015-11-02 21:08

A vulnerability in a network that processes genomic data could pave the way to some global genomic databases being hacked.

Latest EMET Bypass Targets WoW64 Windows Subsystem (Threatpost)
2015-11-02 20:29

Researchers have developed a bypass for Microsoft's EMET exploit mitigations by targeting a design limitation of the WoW64 subsystem that provides backwards compatibility for 32-bit applications...

Monthly Android Security Update Patches More Stagefright Vulnerabilities (Threatpost)
2015-11-02 20:10

Google released its monthly over-the-air Android security update to Nexus devices, patching another handful of vulnerabilities related to Stagefright.

Malicious Android App Impersonates Microsoft Word Doc (Threatpost)
2015-10-30 18:08

A malicious data-stealing Android app that impersonates a Microsoft Word document has already infected several hundred users, primarily in China.

Threatpost News Wrap, October 30, 2015 (Threatpost)
2015-10-30 15:00

Mike Mimoso and Chris Brook discuss the news of the week: The latest Xen vulnerability, CISA passing the Senate, a researcher challenging that Weak DH paper, and more.

Xen Patches 7-Year-Old VM Escape Hypervisor Vulnerability (Threatpost)
2015-10-30 12:47

Xen patched a seven-year-old vulnerability that allows an attacker to escape a guest virtual machine and attack the host operating system.

Web Hosting Service 000webhost Hacked, Information of 13 Million Leaked (Threatpost)
2015-10-29 17:07

Web hosting service 000webhost told customers that 13.5 customer usernames, plaintext passwords, email addresses, IP addresses, and names were exposed in a breach.

Rockwell Patches Serious ‘FrostyURL’ PLC Vulnerability (Threatpost)
2015-10-29 12:00

Rockwell Automation has patched a handful of vulnerabilities in its Allen-Bradley MicroLogix programmable logic controllers

Fewer IPsec VPN Connections at Risk from Weak Diffie-Hellman (Threatpost)
2015-10-28 19:01

A researcher challenges a conclusion in a recent academic paper on weak Diffie-Hellman implementations that claims 66 percent of IPsec VPN connections are at risk.