Security News

White House Executive Order Declares Cyber National Emergency (Threatpost)
2015-04-07 17:03

New Obama Administration Executive Order declares a cyber-national emergency and research advocates worry that sanctions could chill security research work.

FBI Warns of Phony Sites Offering Government Services (Threatpost)
2015-04-07 15:53

The FBI has warned consumers about a rash of phony websites posing as government services.

Vulnerability Forces Mozilla to Disable Opportunistic Encryption in Firefox (Threatpost)
2015-04-07 14:27

Less than a week after introducing the new opportunistic encryption feature in Firefox, Mozilla has had to disable it because of a security vulnerability in the browser’s implementation of the...

Post-Cryptanalysis, TrueCrypt Alternatives Step Forward (Threatpost)
2015-04-06 18:11

CipherShed and VeraCrypt developers stand ready to step in for TrueCrypt now that the cryptanalysis phase of the audit is complete and no backdoors were discovered.

Linux Australia Hit With Server Breach (Threatpost)
2015-04-06 16:14

Linux Australia, a consortium in charge of organizing Linux conferences across the continent, acknowledged over the weekend it was breached by attackers last month.

Snapchat Publishes First Transparency Report (Threatpost)
2015-04-06 14:58

Snapchat has released its first transparency report, covering a four-month period from November through February, and the data shows that the company didn’t receive any National Security Letters...

SWF Files Injecting Malicious iFrames on WordPress, Joomla Sites (Threatpost)
2015-04-03 16:36

Researchers have seen an uptick in Adobe Flash .SWF files being used to trigger malicious iFrames across websites.

VMware Fixes Java Information Disclosure Vulnerability (Threatpost)
2015-04-03 15:03

VMware has issued an update to a number of its products fixing an information disclosure bug in Oracle's Java runtime environment.

Dyre Banking Malware A Million-Dollar Threat (Threatpost)
2015-04-03 14:12

IBM warns banks and corporate officers of a change to the dangerous Dyre banking Trojan that involves the phone scam used to bypass fraud detection, and a DDoS attack that distracts security teams...

Threatpost News Wrap, April 2, 2015 (Threatpost)
2015-04-03 13:00

Dennis Fisher and Mike Mimoso talk about Google's decision to drop Chinese CA CNNIC from Chrome's trust store, the scope of the malvertising threat and Verizon's super cookie use.