Security News

Joomla Update Patches Critical SQL Injection Vulnerability (Threatpost)
2015-10-23 12:56

Joomla released a new version of its CMS Thursday, 3,4,5, that addresses a critical SQL injection vulnerability that could have let attackers gain access to data in the backend of any site running...

Novel NTP Attacks Roll Back Time (Threatpost)
2015-10-22 18:21

Researchers at Boston University have published new attacks against the Network Time Protocol (NTP) that jeopardize the security of numerous online activities.

Custom Google App Engine Tweak Still Leads to Java Sandbox Escapes (Threatpost)
2015-10-22 13:06

Researchers at Security Explorations say a change implemented by Google to the Java security model as its implemented in the Google App Engine leads to sandbox escapes.

Apple Patches Include iOS 9.1 Update, Pangu Jailbreak Fix (Threatpost)
2015-10-21 21:27

Apple on Thursday fixed scores of vulnerabilities in OS X, iOS, Safari, iTunes, and even the company’s smart watch operating system, watchOS. Chief among the fixes was a patch for two issues the...

Google Moving Gmail to Strict DMARC Implementation (Threatpost)
2015-10-21 18:09

Google said it will move gmail.com to a policy of rejecting any messages that don’t pass the authentication checks spelled out in the DMARC specification.

Oracle Quarterly Security Update Patches 154 Vulnerabilities (Threatpost)
2015-10-21 11:29

Oracle patched 154 vulnerabilities in 54 different products as part of its regularly scheduled Critical Patch Update Tuesday.

Microsoft Opens .NET Core, ASP.NET Bug Bounties (Threatpost)
2015-10-20 19:36

Microsoft opened a bounty for the .NET Core and ASP.NET Beta, paying out up to $15,000 for eligible vulnerabilities.

Let’s Encrypt Hits Another Free HTTPS Milestone (Threatpost)
2015-10-20 19:30

Let's Encrypt hit a milestone last night when it received the cross-signatures necessary to render its beta-and free-certificates trusted by all browsers.

Juan Andres Guerrero-Saade on the Dangers of APT Security Research (Threatpost)
2015-10-20 18:17

Juan Andres Guerrero-Saade from Kaspersky Lab’s Global Research & Analysis Team (GReAT) joins Ryan Naraine on the podcast to discuss the “identity crisis” in the anti-malware industry and the...

Academics Find Critical Flaws in Self-Encrypting Hardware Drives (Threatpost)
2015-10-20 18:04

Some consumer-grade, self-encrypting external hard drives from Western Digital are littered with security vulnerabilities that render their encryption an afterthought.