Security News

Mozilla Bug Bounty Payouts Going Up (Threatpost)
2015-06-10 18:44

Mozilla announced that it has increased rewards for vulnerabilities submitted to its bug bounty program, and that for the first time it will pay for some bugs whose severity is rated moderate.

Microsoft Brings HSTS to Windows 7 and 8.1 (Threatpost)
2015-06-10 15:47

Microsoft announced it has added HTTP Strict Transport Security (HSTS) to Internet Explorer 11 on Windows 8.1 and Windows 7, in addition to its native inclusion in Microsoft Edge on Windows 10.

Congress Looking Into Restricting Power of Government-Owned CAs (Threatpost)
2015-06-10 14:50

As the debate over potential government interference with encryption technologies rages in countries around the world, Congress is now going down a different path, asking technology companies...

Mail Bug on iOS, OSX, Opens Door to Phishing Attacks (Threatpost)
2015-06-10 13:54

A bug in the standalone mail client for both iOS and OSX could allow an attacker to load external HTML and make it easy to carry out convincing phishing attacks on unsuspecting users.

New APT Duqu 2.0 Hits High-Value Victims, Including Kaspersky Lab (Threatpost)
2015-06-10 12:05

The Duqu attackers, who are considered by researchers to be at the top of the food chain of APT groups and are responsible for attacking certificate authorities and perhaps spying on Iran’s...

Apple Pushing Developers Toward HTTPS Connections From Apps (Threatpost)
2015-06-09 19:13

Apple is encouraging developers who create apps for iOS to begin moving their apps to an HTTPS-only model as soon as possible in an effort to thwart eavesdropping on insecure, plaintext HTTP...

Critical IE Update One of Eight Microsoft Security Bulletins (Threatpost)
2015-06-09 18:19

Microsoft released two critical bulletins—eight overall—as part of the June 2015 Microsoft Patch Tuesday security updates. One of the critical bulletins patches 24 vulnerabilities in Internet Explorer.

Banking Malware Vawtrak Spotted Using Tor2Web (Threatpost)
2015-06-09 16:27

Developers behind the banking Trojan Vawtrak have begun obscuring some of their servers with Tor2Web, a move that’s added another level of difficulty when it comes to uncovering their activity.

Adobe Patches 13 Vulnerabilities in Flash Player (Threatpost)
2015-06-09 15:39

Adobe’s monthly patch release features just an update for Flash Player, addressing 13 security vulnerabilities that expose the software to remote attacks.

Federal Agencies to Move to HTTPS-Only Connections (Threatpost)
2015-06-09 15:36

Following the lead of many major Web services, the White House on Monday announced that it would move all of the federal government’s public sites and services to HTTPS-only. Tony Scott, the...