Security News

Audit Concludes No Backdoors in TrueCrypt (Threatpost)
2015-04-02 17:50

Auditors performing a cryptanalysis of TrueCrypt found four vulnerabilities, but zero backdoors in the popular open source encryption software.

Google Report Lauds Android Security Enhancements (Threatpost)
2015-04-02 17:22

Google's first Android Security Report puts some hard data behind the effectiveness of the security enhancements it has put into the OS.

Google Awards $5k Bounty for YouTube Video Delete Bug (Threatpost)
2015-04-02 15:23

A Russian security researcher discovered that he could delete any video on YouTube by sending a simple POST request in YouTube's Creator Studio.

Google Drops Trust in Chinese Certificate Authority CNNIC (Threatpost)
2015-04-02 11:59

Google has taken the unusual step of completely removing trust from Chrome for the Chinese certificate authority CNNIC in the wake of an incident in which certificates issued by the CA were...

Little Change in Online Behavior Following Snowden Revelations (Threatpost)
2015-04-01 19:15

Pew Research Center survey finds that most Americans have done little or nothing to change their online behaviors nearly two years after the first NSA spying revelations emerged.

Students Build Open Source Web-Based Threat Modeling Tool (Threatpost)
2015-04-01 19:00

Students at St. Mary's University in Canada released to open source a web-based threat modeling tool called Seasponge that they hope will provide an alternative to Microsoft's free tool.

Critical Vulnerabilities Affect JSON Web Token Libraries (Threatpost)
2015-04-01 18:58

Critical vulnerabilities exist in several JSON Web Token (JWT) libraries – namely the JavaScript and PHP versions – that could let an attacker bypass the verification step.

Verizon Allows Opt Out of UIDH Mobile Supercookie (Threatpost)
2015-04-01 17:30

Verizon Wireless has made a change that now allows customers to opt out of the ad-targeting program that relies on the so-called supercookie identifier that was inserted into Web requests users...

Multicast DNS Vulnerability Could Lead to DDOS Amplification Attacks (Threatpost)
2015-04-01 14:54

DHS warned of a serious vulnerability in Multicast DNS devices whereby leaked system information could be leveraged in a DDoS amplification attack.

Mozilla Adds Opportunistic Encryption for HTTP in Firefox 37 (Threatpost)
2015-04-01 14:41

Mozilla has released Firefox 37, and along with the promised addition of the OneCRL certificate revocation list, the company has included a feature that enables opportunistic encryption on...