Security News

D-Link Accidentally Leaks Private Code-Signing Keys (Threatpost)
2015-09-18 14:21

Private keys used to sign D-Link software were included in open-source firmware published by the company.

Apple Addresses Dozens of Vulnerabilities, Embraces Two-Factor Authentication in iOS 9 (Threatpost)
2015-09-17 20:07

Apple pushed out iOS 9 Wednesday, addressing a cornucopia of vulnerabilities, including bugs that could lead to arbitrary code execution, credential leakage, interface spoofing, among other issues.

Details Surface on Patched Bugzilla Privilege Escalation Flaw (Threatpost)
2015-09-17 17:12

Bugzilla users should upgrade to current versions after a privilege escalation vulnerability was reported and patched.

Dennis Fisher On Security,  Journalism, and the Origins of Threatpost (Threatpost)
2015-09-17 17:00

Ryan Naraine hijacks the podcast to talk with Dennis Fisher about the origins of Threatpost, his time as a security reporter, the changes in the industry, and what's next on the horizon.​

Dutch Police Arrest Alleged CoinVault Ransomware Authors (Threatpost)
2015-09-17 13:13

Ransomware has emerged as major threat to consumers and businesses in recent years, and law enforcement agencies and security researchers have taken note. Authorities last year disrupted the...

Schneider Patches Plaintext Credentials Bug in Building Automation System (Threatpost)
2015-09-16 20:15

Schneider Electric has published new firmware for its StruxureWare Building Expert building automation system that patches a remotely exploitable vulnerability.

Google Patches Latest Android Lockscreen Bypass (Threatpost)
2015-09-16 18:06

Google recently patched a lockscreen bypass in its Android-based Nexus phones that was discovered and reported by the University of Texas Information Security Office.

Spam Campaign Continuing to Serve Up Malicious .js Files (Threatpost)
2015-09-16 17:45

A malicious spam campaign that’s been doling out zipped Javascript (.js) files all year remains an issue, the SANS Internet Storm Center warns.

Scan of IPv4 Space for ‘Implanted’ Cisco Routers Finds Fewer Than 100 (Threatpost)
2015-09-16 15:02

A day after researchers detailed a technique that attackers are using to upload malicious firmware images to Cisco routers, academic researchers say they have scanned the entire IPv4 address space...

Bug in iOS and OSX Allows Writing of Arbitrary Files Via AirDrop (Threatpost)
2015-09-16 11:26

There is a major vulnerability in a library in iOS that allows an attacker to overwrite arbitrary files on a target device and, when used in conjunction with other techniques, install a signed app...