Security News

OPM Breach Dates Back to December (Threatpost)
2015-06-17 16:04

The attack on the Office of Personnel Management that was disclosed earlier this month began as early as December 2014 and likely was the end result of a social engineering attack that enabled the...

Plaintext Credentials Threaten RLE Wind Turbine HMI (Threatpost)
2015-06-17 14:01

A week after disclosing a cross-site request forgery vulnerability in small wind turbines manufactured by a company called XZERES, a security researcher has discovered a serious bug in the...

Samsung’s Swift Keyboard Update Mechanism Exposes 600M Devices (Threatpost)
2015-06-17 13:08

Attackers sitting on a network can intercept Swift keyboard updates from Samsung, inject code, and potentially take remote control of millions of Android mobile devices.

FBI Investigating Alleged Attack on Houston Astros (Threatpost)
2015-06-16 18:49

In one of the more bizarre alleged hacking stories to emerge recently, federal authorities are investigating whether employees of the St. Louis Cardinals hacked into systems belonging to the...

Information-Stealing Stegoloader Malware Hides in Images (Threatpost)
2015-06-16 16:03

Dell SecureWorks said a new version of the Stegoloader malware uses steganography to hide itself from detection.

Google Launches Android Security Rewards For Nexus Devices (Threatpost)
2015-06-16 14:03

Google today launched the Android Security Rewards program, a bug bounty for Android Nexus 6 and Nexus 9 devices.

Amazon Transparency Report Shows Few Requests For User Data (Threatpost)
2015-06-16 13:23

Amazon has released its first transparency report, and for a company as large as Amazon, there is surprisingly little in the way of detail or explanation in the report. The company reported that...

LastPass Network Breached; Calls for Master Password Reset (Threatpost)
2015-06-15 20:36

Cloud-based password manager LastPass said its network has been breached and attackers stole personal information as well as salts and hashes.

Hill Debates Course of Action on China Cyberespionage (Threatpost)
2015-06-15 18:29

The U.S.-China Economic and Security Review Commission tackled China and cyberespionage today in a D.C. hearing.

Duqu 2.0 Attackers Used Stolen Foxconn Certificate to Sign Driver (Threatpost)
2015-06-15 15:21

The attackers behind the recently disclosed Duqu 2.0 APT have used stolen digital certificates to help sneak their malware past security defenses, and one of the certificates used in the attacks...