Security News

Web.com Loses 93,000 Credit Card Numbers in Breach (Threatpost)
2015-08-19 19:30

Hosting provider Web.com said it was breached last week and hackers made off with payment card and personal data belonging to 93,000 customers.

Inside the Unpatched OS X Vulnerabilities (Threatpost)
2015-08-19 16:19

Italian researcher Luca Todesco explains how exploiting two vulnerabilities in OS X gain enable root access for a hacker. He won't, however, say why he went public with details and exploit code...

Emergency IE Patch Fixes Vulnerability Under Attack (Threatpost)
2015-08-18 22:08

Microsoft released an out-of-band patch for an Internet Explorer vulnerability under attack.

Core Infrastructure Initiative Launches Open Source Security Badge Program (Threatpost)
2015-08-18 20:30

The Core Infrastructure Initiative, which has funded OpenSSL among other open source security projects, announced a badge program that evaluates secure development best practices.

IRS Hack May Implicate Three Times As Many Taxpayers Than Expected (Threatpost)
2015-08-18 18:31

The Internal Revenue Service disclosed this week that following the latest review of its system, 334,000 taxpayers - more than three times the agency’s initial estimate – may be affected by the...

Apple Zero Day Remains Unpatched (Threatpost)
2015-08-18 18:15

A publicly disclosed zero day in current version of Apple OS X remains unpatched.

Adobe Patches XXE Vulnerability in LiveCycle Data Services (Threatpost)
2015-08-18 16:46

Adobe pushed out a hotfix for LiveCycle Data Services patching an XXE vulnerability in BlazeDS.

Reflection DDoS Attacks Abusing RPC Portmapper (Threatpost)
2015-08-18 14:00

Level 3 Communications has discovered a new type of reflection DDoS attack that takes advantage of RPC Portmapper to overwhelm networking services.

Uber to Quadruple Security Staff by 2016 (Threatpost)
2015-08-18 11:00

Ride-sharing company Uber, which has already battled a database compromise and hackers selling stolen accounts this year, announced over the weekend that it will bulk up its security division.

Risky Schneider Electric SCADA Vulnerabilities Remain Unpatched (Threatpost)
2015-08-17 19:11

Vulnerabilities in Schneider Electric SCADA gear remain unpatched close to two weeks after they were disclosed during DEF CON.