Security News

Researcher Finds Method to Bypass Google Password Alert (Threatpost)
2015-05-01 15:47

A security researcher has developed a method–actually two methods–for defeating the new Chrome Password Alert extension that Google released earlier this week. The Password Alert extension is...

Threatpost News Wrap, May 1, 2015 (Threatpost)
2015-05-01 15:38

Dennis Fisher and Mike Mimoso discuss the post-RSA news, including the MySQL bug, the progress of the OpenSSL overhaul and the wildly entertaining House hearing on crypto backdoors.

Dyre Banking Trojan Jumps Out of Sandbox (Threatpost)
2015-05-01 13:48

Researchers at Seculert have found a new version of the Dyre banking malware, one that is adept at avoiding sandbox detection.

Unpatched Router Vulnerability Could Lead to Code Execution (Threatpost)
2015-04-30 18:07

A critical vulnerability in popular household routers such as D-Link and Trendnet could be exploited by attackers to run arbitrary code on devices.

New Spam Campaign Pushing CTB-Locker Ransomware (Threatpost)
2015-04-30 17:28

The SANS Institute reports a new strain of CTB-Locker ransomware moving this week via spam messages.

MySQL Bug Can Strip SSL Protection From Connections (Threatpost)
2015-04-30 14:59

Researchers have identified a serious vulnerability in some versions of Oracle’s MySQL database product that allows an attacker to strip SSL/TLS connections of their security wrapping...

Congress, Crypto and Craziness (Threatpost)
2015-04-30 11:34

A Congressional hearing on encryption and "frontdoors" produced a generous amount of the usual "crazy" from lawmakers and law enforcement.

WordPress Ecommerce Plugin Vulnerability Details Disclosed (Threatpost)
2015-04-29 18:28

Details on a number of unpatched vulnerabilities in a popular WordPress ecommerce plugin called CartPress were disclosed.

A Year Later, XSS Vulnerability Still Exists in eBay (Threatpost)
2015-04-29 18:27

A potentially dangerous XSS vulnerability has existed in eBay for more than a year and it doesn’t appear the company is a rush to fix the issue.

OpenSSL Past, Present and Future (Threatpost)
2015-04-29 17:06

Heartbleed made the world notice what kind of shape OpenSSL development was in from a financial and resources standpoint. In the year since, the project has been funded enough to hire full-time...