Security News

Google Releases Password Alert Extension for Chrome (Threatpost)
2015-04-29 16:14

Google is rolling out a new extension for Chrome that will monitor users’ logins and warn them if they enter a Google password on a non-Google page, a move designed to help protect users against...

Macro-Enabled Malware Making a Comeback (Threatpost)
2015-04-29 14:28

Malware that uses macros as part of its infection method has been around for more than a decade, and was one of the first major techniques to drive changes at software vendors such as Microsoft....

How I Got Here: Jennifer Leggio (Threatpost)
2015-04-29 12:54

Dennis Fisher talks with Jennifer Leggio, a longtime player in security PR and marketing, about her start as an obituary writer in Southern California, her move into tech in the Bay Area, what she...

Criminal Group Using Dynamic Gate System to Infect with Fiesta EK (Threatpost)
2015-04-28 18:47

Criminal group is utilizing a changing series of Internet protocol addresses, domains and gates in order to infect its victims with the Fiesta exploit kit.

SendGrid Admits Broader Hack of Email Service (Threatpost)
2015-04-28 18:31

Email delivery service provider SendGrid admitted that hackers had accessed several internal systems, refuting reports earlier this month that the attack was an isolated incident.

WordPress Patches Zero-Day Vulnerability (Threatpost)
2015-04-28 17:12

WordPress quickly turned around a patch for a stored cross-site scripting zero-day vulnerability in the CMS' core engine.

Authentication Vulnerabilities Identified in Projector Firmware (Threatpost)
2015-04-28 15:42

The manufacturer of a popular projector found primarily in classrooms is neglecting to address several authentication bugs that exist in the device that could open it up to hacks.

Mozilla to Remove Turkish CA From Firefox Trust Store (Threatpost)
2015-04-28 14:15

Mozilla is removing a Turkish root CA from the Firefox trust store, not because of a compromise or a mistakenly issued certificate, but because the certificate authority hasn’t lived up to the...

New Utility Decrypts Data Lost to TeslaCrypt Ransomware (Threatpost)
2015-04-27 18:38

Cisco published an analysis of TeslaCrypt and a decryptor tool that recovers files lost to the ransomware.

Details on WordPress Zero Day Disclosed (Threatpost)
2015-04-27 15:56

A Finnish researcher has disclosed details on an unpatched stored cross-site scripting vulnerability in the WordPress core engine.