Security News

Jessy Irwin on Password Security, Opsec and User Education (Threatpost)
2015-09-09 12:00

Dennis Fisher talks with Jessy Irwin of 1Password about her path into the security world, the many security challenges in the education sector, the password-security problem, and security jewelry.

Microsoft Patches Graphics Component Flaw Under Attack (Threatpost)
2015-09-08 19:19

Microsoft patched a vulnerability in its graphics component present in Windows, Office and Lync that has been publicly attacked,

TLS Implementations Vulnerable to RSA Key Leaks (Threatpost)
2015-09-08 19:09

A number of TLS software implementations contain vulnerabilities that allow hackers with minimal computational expense to learn RSA keys.

Alleged Gozi Co-Author Pleads Guilty As Alleged Citadel, Dridex Attackers Arrested (Threatpost)
2015-09-08 19:01

The author behind one strain of banking malware, Gozi, has plead guilty and is awaiting sentencing while two other men, apparently responsible for developing the banking malware Citadel and...

Adobe Patches Two Shockwave Player Vulnerabilities (Threatpost)
2015-09-08 16:43

A new version of Adobe Shockwave Player patches two memory corruption vulnerabilities that could lead to remote code execution.

eBay Fixes XSS Flaw in Subdomain (Threatpost)
2015-09-08 15:41

There was a cross-site scripting vulnerability in an eBay domain that could have allowed an attacker to steal users’ session cookies and take over their accounts. The company has removed the...

Government Releases Policy on Vulnerability Discovery and Disclosure (Threatpost)
2015-09-08 13:38

After more than a year if legal wrangling, the federal government has agreed to hand over its policy on vulnerability use and disclosure. The government had said that the policy was classified and...

Attacker Compromised Mozilla Bug System, Stole Private Vulnerability Data (Threatpost)
2015-09-04 19:45

Security experts constantly tell users not to reuse passwords on multiple accounts, but the message often falls on deaf ears. Now, officials at Mozilla are finding that advanced users don’t always...

Feds Change Policy to Require Warrant for Use of Stingrays (Threatpost)
2015-09-04 13:50

The Department of Justice has established a new policy that requires federal law enforcement agents–and state and local agencies working with the department–to obtain search warrants in order to...

Threatpost News Wrap, September 4, 2015 (Threatpost)
2015-09-04 13:00

Dennis Fisher and Mike Mimoso talk about the potential US sanctions against China over cyberespionage, the browser vendors dumping RC4, the trouble at Mobile Pwn2Own and more security news of the week.