Security News

Using BitTorrent Vulnerabilities to Launch Distributed Reflective DoS Attacks (Threatpost)
2015-08-17 17:42

Researchers warn several BitTorrent protocols can be leveraged to carry out distributed reflective denial of service (DRoS) attacks.

AT&T Facilitated NSA Surveillance Efforts, Reports (Threatpost)
2015-08-17 16:30

Published reports say that AT&T was the National Security Agency's primary telecommunications partner and facilitated much of its surveillance efforts around telephone and Internet traffic collection.

Threatpost News Wrap, August 14, 2015 (Threatpost)
2015-08-14 16:23

Dennis Fisher and Mike Mimoso talk about the news from Black Hat, car hacking, the Mary Ann Davidson blog post, and the Android security mess.

Apple Patches Critical OS X DYLD Flaw in Monster Update (Threatpost)
2015-08-14 15:34

Apple released hordes of patches for OS X, iOS, Safari and iOS Server, including fixes for the DYLD vulnerability disclosed in July.

OwnStar Attack Now Aimed at BMW, Chrysler, Mercedes Cars (Threatpost)
2015-08-14 13:54

The OwnStar attack that hacker Samy Kamkar revealed late last month can be used against not only GM vehicles, but cars manufactured by Mercedes-Benz, BMW, and Chrysler, as well. The attack allows...

Salesforce Patches XSS on a Subdomain (Threatpost)
2015-08-13 18:27

Salesforce.com patched a cross-site scripting vulnerability on one of its domains that could have led to phishing attacks.

Zero Day in Android’s Google Admin App Can Bypass Sandbox (Threatpost)
2015-08-13 17:53

The Android security team at Google is having a busy month. First the Stagefright vulnerabilities surfaced last month just before Black Hat and now researchers at MWR Labs have released...

Stagefright Patch Incomplete Leaving Android Devices Still Exposed (Threatpost)
2015-08-13 17:00

A Stagefright vulnerability patch is incomplete and Android devices remain exposed. Google has made a new patch open source and will update devices over-the-air next month.

OpenSSH 7.0 Fixes Four Flaws (Threatpost)
2015-08-13 15:23

A new version of OpenSSH has been released, fixing four security vulnerabilities and a number of non-security related bugs. OpenSSH 7.0 includes patches for a use-after-free vulnerability and...

Lenovo Hit With Criticism Over Second Rootkit-Like Utility (Threatpost)
2015-08-13 14:05

Lenovo is under fire again for installing a covert utility on laptops and desktops that some users have compared to a rootkit. The issue stems from a utility called the Lenovo Service Engine, that...