Security News

iOS, OS X Library AFNetwork Patches MiTM Vulnerability (Threatpost)
2015-03-27 18:56

Until yesterday, a popular networking library for iOS and OS X, used by several apps like Pinterest and Simple was susceptible to SSL man-in-the-middle (MiTM) attacks.

Slack Discloses Breach of Its User Profile Database, Implements 2FA (Threatpost)
2015-03-27 18:49

Collaboration providers Slack disclosed that a database storing its user profile information has been breached. The break-in has been stopped, and Slack announced that it has implemented...

FBI Pleads For Crypto Subversion in Congressional Budget Hearing (Threatpost)
2015-03-27 17:49

FBI Director James Comey pleads with Congress to create a law that would allow law enforcement access to encrypted mobile communications on Android and Apple devices.

GitHub Hit With DDoS Attack (Threatpost)
2015-03-27 15:54

A large-scale DDoS attack, apparently emanating from China, has been hammering the servers at GitHub over the course of the last 12 hours, periodically causing service outages at the code-sharing...

Threatpost News Wrap, March 27, 2015 (Threatpost)
2015-03-27 15:50

Dennis Fisher and Mike Mimoso discuss the news of the week, including the Android app-replacement vulnerability, the Windows privilege escalation bug and the Yahoo transparency report and the...

Schneider Electric Patches Easily Exploitable Bugs in HMI Products (Threatpost)
2015-03-27 15:01

There are a series of vulnerabilities related to credentials and authentication in two of Schneider Electric's HMI products, and an attacker who exploits them may be able to run arbitrary code.

Hotel Internet Gateways Patched Against Remote Exploit (Threatpost)
2015-03-26 18:50

A critical vulnerability in a popular hotel and convention center Internet gateway from AntLabs called InnGate has been patched. The flaw allows attackers read and write access to the devices from...

MIT Researchers Debut Debugger for Integer Overflows (Threatpost)
2015-03-26 18:38

Students from M.I.T. have devised a new way to scour raw code for integer overflows.

U.S. Government Requests for Yahoo User Data Drop (Threatpost)
2015-03-26 17:17

Yahoo received nearly 5,000 requests for user data from the United States government in the last six months of 2014 and disclosed some content in nearly 25 percent of those cases.

Denial of Service and Memory Vulnerabilities Patched in Cisco IOS (Threatpost)
2015-03-26 16:15

Cisco released its semiannual set of patches for its Cisco IOS router and switch operating system. The patches address 16 vulnerabilities.