Security News

NSF Awards $6M Grants for Internet of Things Security (Threatpost)
2015-08-31 19:41

The National Science Foundation awarded $6 million in grants to fund projects working toward securing networked things.

CoreBot Malware Steals Credentials-For Now (Threatpost)
2015-08-31 15:31

CoreBot is new information-stealing malware in the wild with a modular design that could turn the credential-stealing malware into something much worse.

KeyRaider Malware Steals Certificates, Keys and Account Data From Jailbroken iPhones (Threatpost)
2015-08-31 13:09

Researchers have discovered a new strain of iOS malware dubbed KeyRaider that targets jailbroken devices and has the ability to steal certificates, private keys, and Apple account information. The...

Appeals Court Vacates Lower Court’s Decision on National Security Letters (Threatpost)
2015-08-28 18:32

A federal appeals court has sent back to a lower court an appeal in a lawsuit about the way companies are allowed to publicize information about National Security Letters they receive. The appeal...

Latest APT 28 Campaign Incorporates Fake EFF Spearphishing Scam (Threatpost)
2015-08-28 17:46

An attack that uses the same path names, Java payloads, and Java exploit as one earlier this summer was found leveraging a fake EFF site.

Threatpost News Wrap, August 28, 2015 (Threatpost)
2015-08-28 16:12

Dennis Fisher and Mike Mimoso discuss the quasi-interesting fallout from the Ashley Madison hack, the appeals court decision about the Wyndham data breaches, and Charlie Miller leaving Twitter.

FBI: Social Engineering, Hacks Lead to Millions Lost to Wire Fraud (Threatpost)
2015-08-28 14:35

U.S. businesses are losing millions in fraudulent wire transfers that have their root in email compromises of accounts belonging to top executives.

Google to Pause Flash Ads in Chrome Starting Next Week (Threatpost)
2015-08-28 13:04

Google on Tuesday will begin pausing Flash ads by default in Chrome, a move that is designed mainly to help improve browser speed, but that will also be a security upgrade for users. The company...

BitTorrent Patch Throttles Reflective DDoS Attacks (Threatpost)
2015-08-27 20:21

BitTorrent today announced that a patch has been rolled out in the libuTP protocol used by many of its clients, fixing a vulnerability that allows attackers to carry out distributed reflective...

Adobe Hotfix Patches XXE Vulnerability in ColdFusion (Threatpost)
2015-08-27 18:08

Adobe today pushed out a hotfix to ColdFusion implementations patching a vulnerability it had already patched nine days ago on the LiveCycle Data Services application framework.