Security News

Samy Kamkar’s ProxyGambit Picks Up for Defunct ProxyHam (Threatpost)
2015-07-17 12:29

Hardware hacker Samy Kamkar has developed an anonymization device called ProxyGambit that improves upon ProxyHam, the device that was supposed to be unveiled at DEF CON.

Office, Java Patches Erase Latest APT 28 Zero Days (Threatpost)
2015-07-16 17:46

iSight Partners provides details on an Office zero day patched this week that was used by the prolific APT 28 gang.

Google to Expand Use of Safe Browsing to Stop Unwanted Software (Threatpost)
2015-07-16 17:40

Google is expanding the use of its Safe Browsing mechanism to warn users about a broader variety of unwanted software, in addition to the warnings they see regarding phishing pages, malware, and...

TotoLink Routers Plagued By XSS, CSRF, RCE Bugs (Threatpost)
2015-07-16 16:53

A slew of routers manufactured in China are fraught with vulnerabilities, some which have existed in products for as long as six years.

Authentication Bypass Bug Hits Siemens Energy Automation Device (Threatpost)
2015-07-16 13:26

An authentication bypass vulnerability in a Siemens device that’s used in energy automation systems could allow an attacker to gain control of the device. The vulnerability is in the Siemens SICAM...

New RC4 Attack Dramatically Reduces Cookie Decryption Time (Threatpost)
2015-07-15 18:27

A paper, expected to be presented at USENIX, describes new attacks against RC4 that make plaintext recovery times practical and within reach of hackers.

Feds Detail Shutdown of Darkode Cybercrime Forum (Threatpost)
2015-07-15 16:36

Officials worldwide culminated an 18 month effort this week to takedown Darkode, a cybercrime forum where hackers fraternized and shared malware, credit card information and more.

Security Support Ends For Remaining Windows XP Machines (Threatpost)
2015-07-15 15:19

Microsoft ended security support for existing Microsoft Security Essentials customers running Windows XP, a little more than a year after support officially ended

Coalition of Security Companies Forms to Oppose Wassenaar Rules (Threatpost)
2015-07-15 15:06

A large group of security companies have formed a coalition to oppose the proposed rules from the Department of Commerce that would regulate the export of so-called intrusion software, a broad...

Oracle Patches Java Zero Day (Threatpost)
2015-07-15 13:44

Oracle has released its quarterly patch update, which includes fixes for nearly 200 vulnerabilities. The most notable bug fixed in this release is the Java zero day that’s been used in an ongoing...