Security News

XcodeGhost Malware Stirring Up More Trouble (Threatpost)
2015-09-23 13:37

Researchers found a weakness in XcodeGhost that puts it at risk for man-in-the-middle attacks.

Bypass Developed for Microsoft Memory Protection, Control Flow Guard (Threatpost)
2015-09-22 19:00

A researcher at Bromium is expected at DerbyCon to disclose a memory corruption mitigation bypass of Microsoft Control Flow Guard.

Federal CISOs Propose New Efforts to Shore Up Cybersecurity (Threatpost)
2015-09-22 17:55

With many government departments still reeling when it comes to security, several federal CISOs brought up a handful of new ideas at last week’s Billington Cybersecurity Summit in Washington, D.C...

Model Assesses Readiness to Accept Outside Vulnerability Reports (Threatpost)
2015-09-22 16:12

HackerOne released a free model that assesses an organization’s readiness to accept outside vulnerability reports.

Apple watchOS2 Includes Host of Code-Execution Patches (Threatpost)
2015-09-21 21:22

Apple watchOS2 arrived with a host of security patches, including fixes for more than a dozen code-execution bugs.

South Korean Child Monitoring App Beset by Vulnerabilities, Privacy Issues (Threatpost)
2015-09-21 19:40

A South Korean child monitoring app is so fraught with vulnerabilities that security researchers warn it could lead to the compromise of users’ accounts, disclosure of minors' information, and a...

XcodeGhost iOS Malware Contained (Threatpost)
2015-09-21 17:00

iOS apps infected with the XcodeGhost malware have been removed from the App Store and three command domains communicating with infected apps have been shut down.

Adobe Patches 23 Critical Vulnerabilities in Flash Player (Threatpost)
2015-09-21 16:14

Adobe has released a Flash Player update that addresses 23 critical vulnerabilities in the software, many which can lead to code execution.

Zerodium Hosts Million-Dollar iOS 9 Bug Bounty (Threatpost)
2015-09-21 14:20

Exploit vendor Zerodium will host a month-long million-dollar bug bounty focused on Apple iOS 9.

Google Details Plans to Disable SSLv3 and RC4 (Threatpost)
2015-09-18 15:01

As expected, Google formally announced its intent to move away from the stream cipher RC4 and the protocol SSLv3 this week, citing a long history of weaknesses in both.