Security News

Siemens Patches Authentication Bypass Flaw in SiPass Server (Threatpost)
2017-07-14 16:37

Siemens patches four vulnerabilities, including a critical authentication bypass flaw, in its SiPass integrated access control server.

Cisco Patches Publicly Disclosed SNMP Vulnerabilities in IOS, IOS XE (Threatpost)
2017-07-14 15:01

Cisco patched nine publicly disclosed remote code execution vulnerabilities in the SNMP subsystem running in its IOS and IOS XE software.

Threatpost News Wrap, July 14, 2017 (Threatpost)
2017-07-14 14:00

Mike Mimoso and Chris Brook discuss the news of the week, including the Verizon breach, the Oracle session hijacking attack, a Telegram-based hacking tool, and a free EternalBlue scanner.

Scanner Shows EternalBlue Vulnerability Unpatched on Thousands of Machines (Threatpost)
2017-07-13 18:35

Data collected from the freely available scanner called EternalBlues shows that tens of thousands of computers remain vulnerable to the SMBv1 vulnerability that spawned WannaCry and ExPetr.

Attackers Using Automated Scans to Takeover WordPress Installs (Threatpost)
2017-07-13 18:24

Attackers have been carrying out WPSetup attacks, taking advantage of users who have installed WordPress but not yet configured it.

Google Changes How it Analyzes Misbehaving Mobile Apps (Threatpost)
2017-07-13 15:12

Google has a new machine-learning algorithm it uses to compare new apps to known secure apps, improving the way it classifies submissions to Google Play.

Experts Warn Too Often AWS S3 Buckets Are Misconfigured, Leak Data (Threatpost)
2017-07-13 13:00

An analysis of Amazon Web Services storage containers reveals troubling trend of misconfigured S3 buckets that leak data.

Third Party Exposes 14 Million Verizon Customer Records (Threatpost)
2017-07-12 19:02

Data belonging to 14 million Verizon customers was exposed by a partner, which misconfigured a repository storing the personal information it had access to.

New Point-of-Sale Malware LockPoS Hitches Ride with FlokiBot (Threatpost)
2017-07-12 18:56

Botnets distributing FlokiBot point-of-sale malware are back in business spewing a new malware dubbed LockPoS.

Uber Patches Authentication Bypass Vulnerability on Custom SSO Solution (Threatpost)
2017-07-12 16:36

Uber patched an authentication bypass vulnerability in its homegrown SSO solution that allowed attackers to take over subdomains and steal session cookies.