Security News

First Let’s Encrypt Free Certificate Goes Live (Threatpost)
2015-09-15 19:17

Let's Encrypt hit a major milestone today when its first free and automated cert went live.

WordPress Patches Serious Shortcodes Core Engine Vulnerability (Threatpost)
2015-09-15 19:10

WordPress upgraded to 4.3.1, patching a pair of vulnerabilities in the core engine, including a cross-site scripting issue enabled by a vulnerability in shortcodes.

CoreBot Adds New Capabilities, Transitions to Banking Trojan (Threatpost)
2015-09-15 17:20

As many researchers expected it would, CoreBot, the credential-stealing malware that first surfaced last month, has added a bevy of new capabilities and reinvented itself as a robust banking Trojan.

Attackers Replacing Firmware on Cisco Routers (Threatpost)
2015-09-15 13:38

Cisco routers are built into the fabric of the Internet and enterprise networks, a fact that makes them highly attractive targets for attackers. Researchers at FireEye have come across attacks...

DARPA Protecting Software From Reverse Engineering Through Obfuscation (Threatpost)
2015-09-14 17:44

Researchers with a DARPA-led team are looking into new ways to combat reverse engineering by using obfuscation to tidy up shoddy commercial and government security.

New Debian Releases Fix PHP, VirtualBox Bugs (Threatpost)
2015-09-14 17:35

The maintainers of Debian have released new versions of the operating system to fix several vulnerabilities, including a number of bugs in PHP and an unspecified flaw in Oracle’s VirtualBox...

Installation of Tor Relays in Library Attracts DHS Attention (Threatpost)
2015-09-14 13:52

The Tor Project recently started a program to help libraries install Tor relays as a way to protect the privacy of patrons and other Internet users. The program didn’t get too far, however, as the...

Researchers Outline Vulnerabilities in Yahoo, PayPal, Magento Apps (Threatpost)
2015-09-11 17:07

Researchers recently discovered a smattering of vulnerabilities in web applications and mobile applications belonging to companies like Yahoo, PayPal, Magento, and Shopify that could have led to...

Series of Buffer Overflows Plague Many Yokogawa ICS Products (Threatpost)
2015-09-11 13:19

There is a series of stack buffer overflows in nearly 20 ICS products manufactured by Japanese vendor Yokogawa that can lead to remote code execution. The bugs affect a long list of the company’s...

Gary McGraw on Scalable Software Security and Medical Device Security (Threatpost)
2015-09-11 13:11

Dennis Fisher talks to Gary McGraw about the challenges of scaling software security programs, the FTC’s security programs, and the current push for better security in medical devices.