Security News

Tor Cloud Shut Down Amid Lack of Support (Threatpost)
2015-05-11 19:01

The Tor Project is discontinuing its Tor Cloud Project in the face of mounting bugs and a lack of human and financial resources.

MacKeeper Patches Remote Code Execution Zero Day (Threatpost)
2015-05-11 17:39

The MacKeeper OS X and iOS performance and security utility has been patched against a remote code execution zero day vulnerability.

Elasticsearch Honeypot Snares 8,000 Attacks Against RCE Vulnerability (Threatpost)
2015-05-11 17:18

Hackers are exploiting a remote code execution vulnerability in Elasticsearch, according to one researcher who published logs from a honeypot he built showing 8,000 attempts to exploit the bug.

Court’s Ruling a ‘Clear Signal’ About Mass Surveillance Programs, Experts Say (Threatpost)
2015-05-11 15:16

The ruling last week by the Second Circuit Court of Appeals that the NSA’s years-long bulk collection of phone metadata is illegal is a “clear signal” that courts are moving in the direction of...

Threatpost News Wrap, May 8, 2015 (Threatpost)
2015-05-08 16:12

Dennis Fisher and Mike Mimoso talk about the end of the Patch Tuesday era for most Microsoft customers, the appeals court ruling on Section 215 metadata collection and Dennis’s idea for a security...

WordPress Sites Backdoored, Leaking Credentials (Threatpost)
2015-05-08 15:37

Zscaler has discovered a number of WordPress sites that have been backdoored and sending credentials to a hacker-controlled website.

Rockwell Automation Patches Buffer Overflow in ICS App (Threatpost)
2015-05-08 15:09

There is a stack buffer overflow in a Rockwell Automation application that’s used to enable communications in industrial control applications used in manufacturing, energy, water,and other...

Security Updates Coming for Adobe Reader, Acrobat (Threatpost)
2015-05-08 13:50

Adobe released pre-notification of security updates coming next week for its Reader and Acrobat products. The updates will address critical vulnerabilities in both products, Adobe said.

Weak Homegrown Crypto Dooms Open Smart Grid Protocol (Threatpost)
2015-05-07 18:58

Researchers in Europe have published research examining weak, homegrown cryptography used in the Open Smart Grid Protocol.

Cisco Patches Remote Code Execution Bugs in UCS Central (Threatpost)
2015-05-07 18:21

Cisco has patched a critical input validation vulnerability in its UCS Central software.