Security News

Cisco UCDM Platform Ships With Default, Static Password (Threatpost)
2015-07-02 13:35

A week after admitting that several of its security appliances ship with static SSH keys, Cisco warned customers on Wednesday that its Unified Communications Domain Manager platform has a default,...

Attackers Revive Deprecated RIPv1 Routing Protocol in DDoS Attacks (Threatpost)
2015-07-01 16:45

An advisory from Akamai warns of a recent reflection style DDoS attack in which the deprecated RIPv1 routing protocol was leveraged against targets.

Pinterest Fixes Validation Vulnerability in API (Threatpost)
2015-07-01 16:41

Pinterest recently fixed an issue in the API of its web app that could have allowed remote attackers to compromise emails and carry out session hijacking and phishing attacks.

LifeLock Patches XSS That Could’ve Led to Phishing (Threatpost)
2015-07-01 15:48

Researchers identified a cross-site scripting vulnerability in a page on the LifeLock website that could allow an attacker to create an authentic-looking login page for the service and harvest...

Patched Apple QuickTime Vulnerability Details Disclosed (Threatpost)
2015-07-01 14:09

Researchers at Cisco Talos released details on a use-after-free vulnerability in Apple QuickTime that could lead to remote code execution.

Class-Action Suit Alleges OPM Officials Failed to Protect Employees’ Data (Threatpost)
2015-07-01 14:02

A class-action lawsuit filed by a government employees’ union against the Office of Personnel Management as a result of the massive data breach at OPM that affects more than 18 million people...

OpenDNS Acquisition Gives Cisco Big Security Data (Threatpost)
2015-06-30 19:24

Cisco announced today its intent to acquire big data security company OpenDNS for $635 million in cash.

Vulnerability Forces OPM to Pull Background Check System Offline (Threatpost)
2015-06-30 19:11

The Office of Personnel Management announced yesterday that it is temporarily suspending the system it uses to conduct government background checks.

Five Arrested in Zeus, SpyEye Group Takedown (Threatpost)
2015-06-29 19:33

Authorities in six different countries worked together last week to take down a cybercrime ring which ultimately infected tens of thousands of computers with Zeus and SpyEye malware and made off...

Researcher Says LG App Update Mechanism Doesn’t Verify SSL Cert (Threatpost)
2015-06-29 19:01

Many smartphones manufactured by LG contain a vulnerability that can allow an attacker to replace an APK file with a malicious file of his choice. The problem is the result of several conditions...