Security News

Vulnerabilities Identified in Two WordPress Plugins (Threatpost)
2015-05-07 16:38

Two vulnerabilities in two different WordPress plugins - an Arbitrary Variable Overwrite vulnerability in eShop, and an XSS vulnerability in Jetpack - were identified this week.

Appeals Court Rules NSA Metadata Collection Not Authorized by Section 215 (Threatpost)
2015-05-07 14:58

The United States Court of Appeals for the Second Circuit ruled Thursday that the Patriot Act does not authorize the bulk collection of phone records by the NSA. The ruling undermines the key...

Apple Fixes WebKit Vulnerabilities in Safari Browser (Threatpost)
2015-05-07 14:49

Apple has issued a series of bulletins for its Safari browser fixing various security vulnerabilities in its WebKit rendering engine.

Lenovo Patches Vulnerabilities in System Update Service (Threatpost)
2015-05-06 18:20

IOActive researchers disclosed details on three patched vulnerabilities in Lenovo's System Update mechanism.

NSA Whistleblowers, Civil Liberties Groups Urge Congress to Oppose USA Freedom Act (Threatpost)
2015-05-06 18:15

As the expiration date for the controversial Section 215 of the Patriot Act draws near, the voices opposing a renewal of the surveillance powers the measure grants the NSA are growing louder. The...

Patch Tuesday Facelift End of an Era (Threatpost)
2015-05-06 17:10

Microsoft's introduction of Windows Update for Business puts an end to Patch Tuesday security updates as we know them.

Google Research Reveals Profitable, Pervasive Ad Injector Ecosystem (Threatpost)
2015-05-06 14:36

More than five percent of all unique IP addresses accessing Google sites included some kind of ad injector software, and there are more than 50,000 of those injector browser extensions in use...

Vulnerability-Riddled Drug Pumps Open to Takeover (Threatpost)
2015-05-05 18:34

Hospira's Lifecare PCA3 Drug Infusion pumps are susceptible to multiple remotely exploitable vulnerabilities that could not only brick the device but allow an attacker to run commands and put...

Microsoft LAPS Tool Tackles Common Local Admin Password Problem (Threatpost)
2015-05-05 17:23

Experts are concerned that Microsoft's new Local Administrator Password Solution only partially addresses the problem of identical passwords on computers in a domain.

ICU Project Overflow Vulnerabilities Patched (Threatpost)
2015-05-05 15:21

Buffer and integer overflow vulnerabilities have been patched in the ICU Project ICU4C library, used in hundreds of open source and enterprise software packages.