Security News

Few Victims Reporting Ransomware Attacks to FBI (Threatpost)
2017-06-23 17:34

The FBI's Internet Crime Complaint Center (IC3) identified ransomware as one of 2016's top threats, but a relatively small number of attacks were reported.

Threatpost News Wrap, June 23, 2017 (Threatpost)
2017-06-23 15:30

Mike Mimoso and Chris Brook discuss the news of the week, including Citizen Lab's latest report, WannaCry hitting Honda, GhostHook, and Fireball.

NSA Advocates Data Sharing Framework (Threatpost)
2017-06-23 14:04

Fighting attackers needs a new approach that leverages a public-private data sharing framework, enabling immediate and collective responses.

Cisco Patches XXE, DOS, Code Execution Vulnerabilities (Threatpost)
2017-06-22 19:08

Cisco patched three vulnerabilities in three products this week that if exploited, could have resulted in a denial of service, crash and in some instances, arbitrary and remote code execution.

Average Cost of Breach Goes Down For the First Time Ever (Threatpost)
2017-06-22 17:51

The good news is the cost of a data breach is down double-digits, the bad news the size and scope of breaches is creeping up.

Microsoft Says Fireball Threat ‘Overblown’ (Threatpost)
2017-06-22 17:11

Check Point has toned down its initial estimates on the number of Fireball malware infections from 250 million machines and 20 percent of corporate networks to 40 million computers.

Drupal Patches Three Vulnerabilities in Core Engine (Threatpost)
2017-06-22 16:22

Developers with Drupal patched three vulnerabilities, one critical, one being exploited in the wild, in Drupal’s core engine on Wednesday.

GhostHook Attack Bypasses Windows 10 PatchGuard (Threatpost)
2017-06-22 15:25

Researchers at CyberArk have developed a bypass for Windows PatchGuard that leverages Intel's Processor Trace (Intel PT) technology to execute code at the kernel.

NSA-Backed OpenC2.org Aims to Defend Systems at Machine Speed (Threatpost)
2017-06-22 10:00

Security experts, vendors, business and the NSA are developing a standardized language that rather than autonomously understands threats, acts on them.

Microsoft Extends Edge Bug Bounty Program Indefinitely (Threatpost)
2017-06-21 20:50

Microsoft said Wednesday it would extend its Edge bug bounty program indefinitely.