Security News

New PHP Releases Fix BACRONYM MySQL Flaw (Threatpost)
2015-07-13 13:30

Several new versions of PHP have been released, all of which contain a number of bug fixes, most notably a patch for the so-called BACKRONYM vulnerability in MySQL. That bug in MySQL is caused by...

Data Breach May Implicate Two Dozen US Zoos (Threatpost)
2015-07-10 18:09

A third party operator of concessions and retail services at zoos from Hawaii to Florida acknowledged this week that it was hit by a data breach earlier this year.

Census Project Identifies Open Source Tools at Risk (Threatpost)
2015-07-10 17:13

The Linux Foundation's Core Infrastructure Initiative announced it was releasing to open source data from the Census Project, which uses metrics identify under-resourced open source projects at risk.

Threatpost News Wrap, July 10, 2015 (Threatpost)
2015-07-10 15:31

Dennis Fisher and Mike Mimoso discuss the Hacking Team hack and the continued fallout from the OPM breach.

U.S. Government Wades Into Vulnerability Disclosure (Threatpost)
2015-07-10 14:57

Security researchers and software vendors have spent decades trying to work out the process of vulnerability disclosure, with limited success. Now the federal government is joining the fray in...

OPM Hack Expands to Include Data of 21.5 Million People (Threatpost)
2015-07-10 13:26

The ever-expanding data breach at the Office of Personnel Management has now spread to include the Social Security numbers and other personal data of a total of 21.5 million people. The new total...

APT Group Exploiting Hacking Team Flash Zero Day (Threatpost)
2015-07-09 18:50

Security company Volexity said that the Wekby APT group, allegedly responsible for hitting Community Health Systems last year, is using the Hacking Team Flash Player zero-day exploit.

OpenSSL Patches Critical Certificate Validation Vulnerability (Threatpost)
2015-07-09 13:44

A high-severity bug in OpenSSL was disclosed today, and it affects only organizations that installed an update released in June, and allows anyone with an untrusted TLS certificate to become a CA.

Bug in Android ADB Backup System Can Allow Injection of Malicious Apps (Threatpost)
2015-07-09 13:16

There’s a severe vulnerability in the way that all versions of Android handle the restoration of backups that can allow an attacker to inject a malicious APK file into the backup archive. The bug...

Ransomware Campaign Alters Variants to Evade Detection (Threatpost)
2015-07-08 20:49

A new, recently uncovered operation has purportedly been mutating versions of ransomware to better avoid getting detected.