Security News

Apple Patches 100+ Vulnerabilities in OS X, Safari, iOS (Threatpost)
2015-10-01 15:04

Apple pushed out its latest operating system, El Capitan, yesterday, and while it boasts many security fixes, the update fails to address the outstanding vulnerability in Gatekeeper that came to...

HTTPS Available as Opt-In for Blogspot (Threatpost)
2015-10-01 15:00

Google announced that it has made HTTPS available as an opt-in for its Blogspot blog-publishing service.

Stagefright 2.0 Vulnerabilities Affect 1 Billion Android Devices (Threatpost)
2015-10-01 11:00

Researchers at Zimperium have reported two new Stagefright vulnerabilities affecting one billion Android devices.

Suspicious Windows 7 Update Actually an Accidental Microsoft ‘Test’ Update (Threatpost)
2015-09-30 19:22

A mysterious Windows 7 update that led to speculation Windows Update was compromised, was actually a test update accidentally published by Microsoft.

Unsupported Honeywell Experion PKS Vulnerable to Public Attacks (Threatpost)
2015-09-30 15:21

Unsupported versions of Honeywell distributed control system software are vulnerable to publicly available remote exploits.

Apple Gatekeeper Bypass Opens Door for Malicious Code (Threatpost)
2015-09-30 13:10

Researcher Patrick Wardle will demonstrate a Mac OS X Gatekeeper bypass that exploits a weakness in the Apple OS that allows signed apps to execute malicious code.

Apple Goes All-In on Privacy (Threatpost)
2015-09-29 18:12

Apple has polished its privacy policy, with new messaging about the sanctity of its users' security and privacy.

Dyreza Trojan Targeting IT Supply Chain Credentials (Threatpost)
2015-09-29 15:37

The Dyreza, or Dyre, Trojan has been spotted phishing credentials in attacks against the IT supply chain.

SAP Patches 12 SQL Injection, XSS Vulnerabilities in HANA (Threatpost)
2015-09-29 15:32

SAP patched a dozen holes in its in-memory management system HANA that could have led to SQL injections, cross-site scripting (XSS) errors, and memory corruption vulnerabilities.

VeraCrypt Patched Against Two Critical TrueCrypt Flaws (Threatpost)
2015-09-28 19:29

Two privilege escalation vulnerabilities in the last TrueCrypt build were discovered by James Forshaw of Google Project Zero, and patched in VeraCrypt.