Security News

Samsung Program Disables Windows Update on PCs (Threatpost)
2015-06-25 18:01

Samsung's update mechanism for Windows PCs and laptops silently disables Windows Update, computing enthusiast Patrick Barker has discovered.

Stored XSS Flaw Patched in Thycotic Secret Server (Threatpost)
2015-06-25 16:07

Thycotic, a maker of access-control and other security products, has patched a stored cross-site scripting vulnerability in one of its products that could enable an attacker to steal a victim's...

Stolen Government Agency Passwords Easy to Find Online (Threatpost)
2015-06-25 15:38

Analysts at Recorded Future said they found stolen credentials from 47 government agencies on a number of paste sites.

Emergency Adobe Flash Patch Fixes Zero Day Under Attack (Threatpost)
2015-06-23 17:12

Adobe released an emergency patch for a Flash zero day used in targeted attacks by APT3, the same group behind 2014's Clandestine Fox attacks.

FBI Says Cryptowall Cost Victims $18 Million Since 2014 (Threatpost)
2015-06-23 16:12

In a little more than a year, consumers affected by the Cryptowall ransomware have reported to the FBI more than $18 million in losses related to infections from the malware. Cryptowall is among...

TCP Vulnerability Haunts Wind River VxWorks Embedded OS (Threatpost)
2015-06-23 14:47

There is a TCP prediction vulnerability in Wind River’s widely deployed VxWorks embedded software that can enable an attacker to disrupt or spoof the TCP connections to and from target devices....

RubyGems Patches Serious Redirection Vulnerability (Threatpost)
2015-06-23 13:55

RubyGems maintainers patched a vulnerability, reported by Trustwave and OpenDNS, that allows RubyGem clients to be redirected to an attacker-controlled gem server.

HP Releases Details, Exploit Code for Unpatched IE Flaws (Threatpost)
2015-06-22 19:11

Researchers at HP's Zero Day Initiative have disclosed full details and proof-of-concept exploit code for a series of bugs they discovered that allow attackers to bypass a key exploit mitigation...

Polish Planes Grounded After Airline Hit With DDoS Attack (Threatpost)
2015-06-22 17:45

Roughly 1,400 passengers were temporarily stranded at Warsaw’s Chopin airport over the weekend after hackers were purportedly able to modify an entire airline’s flight plans.

Google Fixes Handful of Bugs in Chrome (Threatpost)
2015-06-22 16:05

Google has fixed several vulnerabilities in Chrome, including a pair of cross-origin bypasses and a high-risk scheme validation error.