Security News

Amazon Patches Certificate Vulnerabilities in Fire Phones (Threatpost)
2015-06-29 17:31

Amazon patched three vulnerabilities in its Fire Phone, two of which allow for silent certificate installations.

Searches for Pirated Content Lead to Pain and Little Gain (Threatpost)
2015-06-29 14:07

People love to try and get something for nothing, especially on the Internet where there’s all kinds of things available for nothing. But a lot of those free things are illegal and attackers have...

Magnitude Kit Exploiting Flash Zero Day, Dropping Cryptowall (Threatpost)
2015-06-29 13:53

Exploits for the recently patched Adobe Flash Player zero-day have appeared in the Magnitude Exploit Kit and are leading to Cryptowall ransomware infections.

Samsung to Patch Windows Update Issue Within Days (Threatpost)
2015-06-26 20:53

Samsung said today it will no longer automatically disable Windows updates on PCs and laptops it manufactures and will release a patch "within a few days."

IETF Officially Deprecates SSLv3 (Threatpost)
2015-06-26 18:50

The IETF, in RFC7568, declared SSLv3 "not sufficiently secure" and prohibited its use. SSLv3 fallbacks were to blame for the POODLE and BEAST attacks.

New Chrome Extension Blocks BeEF Attacks (Threatpost)
2015-06-26 17:48

An engineer has come up with a new way to help combat BeEF, or browser exploit framework attacks.

NIST Drops Weak Dual_EC RNG From Official Recommendations (Threatpost)
2015-06-26 17:35

NIST officially has removed the controversial and compromised Dual_EC_DRBG from its list of recommended algorithms for generating random numbers.

Threatpost News Wrap, June 26, 2015 (Threatpost)
2015-06-26 16:44

Dennis Fisher and Mike Mimoso talk about the Cisco default SSH keys, more details of the OPM data breach, the Adobe 0-day and why we never hear about bad APT groups, only the really good ones.

Cisco SSH Key Flaw Has Echoes of Earlier Vulnerabilities (Threatpost)
2015-06-26 13:31

When Cisco released a patch for several of its security appliances Thursday that eliminated the presence of hard-coded SSH host and private keys, the advisory had a distinct air of familiarity...

Default SSH Key Found in Many Cisco Security Appliances (Threatpost)
2015-06-25 19:02

Many Cisco security appliances contain default, authorized SSH keys that can allow an attacker to connect to an appliance and take almost any action he chooses.