Security News

VUPEN Launches New Zero-Day Acquisition Firm Zerodium (Threatpost)
2015-07-24 13:46

In the weeks since the Hacking Team breach, the spotlight has shone squarely on the small and often shadowy companies that are in the business of buying and selling exploits nd vulnerabilities....

Several Critical Flaws Patched in Drupal Module (Threatpost)
2015-07-23 17:27

There are several critical vulnerabilities in a middleware layer used in Drupal, including both cross-site scripting and cross-site request forgery bugs, that can be exploited remotely. The...

WordPress Patches Critical XSS Vulnerability in All Builds (Threatpost)
2015-07-23 17:08

WordPress rolled out a new version of its content management system this morning that addresses a nasty cross-site scripting (XSS) vulnerability that could ultimately lead to site compromise.

Chris Valasek on Car Hacking (Threatpost)
2015-07-23 17:05

Dennis Fisher talks with Chris Valasek of IOActive about the new research he did with Charlie Miller on remotely hacking a Jeep, how the disclosure process worked, what auto makers can do to...

Four Zero Days Disclosed in Internet Explorer (Threatpost)
2015-07-23 13:14

As if all of the vulnerabilities in Flash and Windows discovered in the Hacking Team document cache and the 193 bugs Oracle fixed last week weren’t enough for organizations to deal with, HP’s Zero...

Bartalex Variants Spotted Dropping Pony, Dyre Malware (Threatpost)
2015-07-22 18:54

Some strains of Bartalex malware, a macro-based malware that first surfaced earlier this year, are dropping Pony malware and the Dyre banking Trojan.

EFF Hopeful Car Hacking Demo Could Help Yield DMCA Exemption (Threatpost)
2015-07-22 18:03

The latest car hacking research from Charlie Miller and Chris Valasek has elicited a broad spectrum of reactions: admiration for the skill; outrage at the danger the demo may have put drivers; and...

Hacking Team Claims It Always Sold ‘Strictly Within the Law’ (Threatpost)
2015-07-22 14:39

Hacking Team officials are disputing reports that the company sold its surveillance and intrusion software to oppressive regimes in countries that were under sanction. The company said it sold its...

Google Patches 43 Bugs in Chrome (Threatpost)
2015-07-22 13:23

A new version of Google Chrome is available, and it contains patches for 43 security vulnerabilities, many of them in the high-risk category. Two of the more serious vulnerabilities fixed in...

Class Action Suit Against Neiman Marcus Over Data Breach Revived (Threatpost)
2015-07-21 20:05

It turns out that Neiman Marcus, one of many retailers that announced it suffered a data breach last year, will indeed face a class action lawsuit which claims the upscale department store failed...