Security News

Researchers Disrupt Angler Exploit Kit Ecosystem, Derail $30M Ransomware Campaign (Threatpost)
2015-10-06 19:00

Researchers took a big step towards eradicating the Angler exploit kit, disrupting a large ransomware campaign connected to the kit that purportedly netted a hacker behind it more than $60 million...

Canceled Talk Re-Ignites Controversy Over Legitimate Security Research (Threatpost)
2015-10-06 17:02

Citing vendor pressure, a researcher pulled a talk at HITB GSEC Singapore on the security of IP-enabled surveillance cameras.

Targeted Attack Exposes OWA Weakness (Threatpost)
2015-10-06 14:54

A targeted attack has been uncovered in which hackers were able to burrow onto the corporate network and steal thousands of username-password combinations via Outlook Web Access.

Google Pushes Stagefright 2.0 Patches to Nexus Devices (Threatpost)
2015-10-05 20:34

Google's latest monthly over-the-air update for its Nexus Android devices include patches for the most recent vulnerabilities in Stagefright.

YiSpecter iOS Malware Abuses Apple Enterprise Certs to Push Adware (Threatpost)
2015-10-05 16:49

New iOS malware called YiSpecter abuses Apple-issued enterprise developer certificates and private APIs to push adware onto devices in China and Taiwan.

Scottrade Breach Affects 4.6 Million Customers (Threatpost)
2015-10-05 16:43

Scottrade has begun warning customers that as a result of a breach, their names and street addresses - and potentially Social Security numbers - may have been stolen from its system.

Threatpost News Wrap, October 2, 2015 (Threatpost)
2015-10-02 15:44

Mike Mimoso and Chris Brook talk about the week in news--the latest Gatekeeper bypass in OS X, Stagefright 2.0, that accidental Windows Update, and Apple's privacy initiative.

Experian Breach Spills Data on 15 Million T-Mobile Customers (Threatpost)
2015-10-02 13:43

A massive data breach at the credit-reporting agency Experian could wind up having major implications for 15 million T-Mobile customers.

WordPress Jetpack Plugin Patched Against Stored XSS Vulnerability (Threatpost)
2015-10-02 13:20

The popular Jetpack WordPress plugin was updated this week in order to patch a critical stored cross-site scripting vulnerability.

Dridex Banking Malware Back in Circulation (Threatpost)
2015-10-01 23:15

After its alleged developer was arrested, Dridex banking Trojan infections were nil for close to two months. That all changed today.