Security News

Ubuntu Patches Privilege-Escalation Bug (Threatpost)
2015-06-22 14:16

There is a privilege-escalation vulnerability in several versions of Ubuntu that results from the fact that the operating system fails to check permissions when users are creating files in some...

Trio of Vulnerabilities Patched in Magneto Web App (Threatpost)
2015-06-19 18:44

A trio of vulnerabilities were recently patched in eBay’s Magento e-commerce web application that could have let attackers carry out a handful of exploits.

Threatpost News Wrap, June 19, 2015 (Threatpost)
2015-06-19 13:56

Dennis Fisher and Mike Mimoso discuss the brutal House Oversight Committee hearing on the OPM breach, the Navy soliciting zero days, the LastPass breach, and the Cardinals-Astros hacking story.

Static Encryption Key Found in SAP HANA Database (Threatpost)
2015-06-19 13:00

Researchers from ERPScan said SAP’s HANA in-memory database contains a default static encryption key.

Major Carriers AT&T, Verizon Continue to Lag in EFF Privacy Report (Threatpost)
2015-06-18 17:38

Major telecoms like AT&T and Verizon continue to lag behind in the Electronic Frontier Foundation’s annual “Who Has Your Back” report.

Reddit to Move to HTTPS-Only (Threatpost)
2015-06-18 16:18

In the two years since the details of the NSA’s deep penetration of the Internet infrastructure began to emerge, there has been a major movement afoot among Web companies to encrypt more and more...

Drupal Fixes Critical OpenID Bug (Threatpost)
2015-06-18 13:22

Drupal has patched several vulnerabilities in versions 6 and 7 of the content-management system, including a critical bug that enables an attacker to hijack administrators’ accounts and take...

Of Non-Nexus Devices and the Android Security Rewards Program (Threatpost)
2015-06-18 12:22

Google's decision to limit its Android Security Rewards program to Nexus devices could have security consequences for non-Nexus device users.

‘XARA’ Password Stealing Vulnerabilities Outlined in iOS, OSX (Threatpost)
2015-06-17 19:07

A group of researchers claim that they found a handful of vulnerabilities in both Apple’s OS X and iOS, and cracked the Keychain service that the company uses for apps and sandboxes on OS X.

LinkedIn Goes Public with Its Private Bug Bounty (Threatpost)
2015-06-17 17:00

LinkedIn today announced that since October it has been running a private bug bounty, and to date has patched 65 bugs and paid out $65,000 in rewards.