Security News

Exploit Kit Using CSRF to Redirect SOHO Router DNS Settings (Threatpost)
2015-05-26 15:05

French researcher Kafeine has found an exploit kit delivering cross-site request forgery attacks that focus on SOHO routers and changing DNS settings to redirect to malicious sites.

Synology Fixes File-Takeover Flaw in Cloud Station OS X Client (Threatpost)
2015-05-26 14:46

There is a vulnerability in some versions of Synology’s Cloud Station client for OS X that can enable any user to take over system files and gain complete control of the machine. Cloud Station is...

Threatpost News Wrap, May 22, 2015 (Threatpost)
2015-05-22 16:19

Dennis Fisher and Mike Mimoso talk about the Logjam attack, the proposed Wassenaar export rules on exploits, and the letter to the president decrying crypto back doors.

Sendio Email Platform Patches Remote Security Bypass Vulnerability (Threatpost)
2015-05-22 16:01

Email security vendor Sendio has patched a pair of remotely exploitable security bypass vulnerabilities in its Sendio ESP, or Email Security Platform, product.

eBay Fixes Reflected File Download Flaw (Threatpost)
2015-05-22 15:01

For many years, eBay has been one of the bigger targets for phishers and many other kinds of attackers and they have been honing their tactics and improving them along the way. Much of their...

Shoddy Android Factory Reset Exposes Private Data, Encryption Keys (Threatpost)
2015-05-22 14:18

Researchers from Cambridge University uncovered weaknesses in the Android Factory Reset feature that puts improperly sanitized data at risk.

Ersatz Scheme Deceives Hackers, Protects Stored Passwords (Threatpost)
2015-05-21 18:35

Researchers at Purdue University have developed a scheme that protects stolen passwords from offline cracking.

Charter Communications Fixes Website Data Leak Vulnerability (Threatpost)
2015-05-21 17:54

The internet-cable-television provider Charter Communications recently fixed an issue with its website that was inadvertently leaking the information of tens of thousands of its customers.

Head-Scratching Begins on Proposed Wassenaar Export Control Rules (Threatpost)
2015-05-21 16:59

Experts point out that the proposed Wassenaar rules in the U.S. leave unanswered questions regarding exploit development and the use of commercial penetration testing tools.

1.1 Million Affected by CareFirst BlueCross BlueShield Breach (Threatpost)
2015-05-21 15:02

CareFirst BlueCross BlueShield announced this week that hackers broke into one of its databases and made off with a variety of sensitive customer information.