Security News

Google Fixes 30 Vulnerabilities, Five High Severity, in Chrome 59 (Threatpost)
2017-06-06 17:36

Google fixed 30 vulnerabilities, including five high severity issues, in the latest version of Chrome, Chrome 59, on Monday.

NSA’s EternalBlue Exploit Ported to Windows 10 (Threatpost)
2017-06-06 15:15

Researchers have ported the EternalBlue exploit to Windows 10, meaning that any unpatched version of Windows can be affected by the NSA attack.

QakBot Returns, Locking Out Active Directory Accounts (Threatpost)
2017-06-05 20:28

QakBot, a worm-like, information-stealing strain of malware is back and locking users out of their Active Directory accounts.

40,000 Subdomains Tied to RIG Exploit Kit Shut Down (Threatpost)
2017-06-05 19:16

GoDaddy, along with researchers from RSA Security and other companies, shut down tens of thousands of illegal established subdomains tied to the RIG Exploit Kit.

53 Percent of Enterprise Flash Installs are Outdated (Threatpost)
2017-06-05 19:10

More than half of enterprises are exposing themselves to unnecessary risk by running out-of-date versions of Flash.

Jaff Malware Probe Uncovers Link to Cybercrime Marketplace (Threatpost)
2017-06-03 12:00

Researchers have discovered a shared backend infrastructure between the Jaff ransomware and a black market carder shop.

EternalBlue Exploit Spreading Gh0st RAT, Nitol (Threatpost)
2017-06-02 18:32

FireEye said threat actors are using the NSA's EternalBlue exploit of the same Microsoft SMBv1 vulnerability as WannaCry to spread Nitol and Gh0st RAT.

SSH Configuration on Nexpose Servers Allowed Weak Encryption Algorithms (Threatpost)
2017-06-02 16:46

Rapid7 warned this week that its Nexpose appliances were shipped with a SSH configuration that could have let obsolete algorithms be used for key exchange.

Threatpost News Wrap, June 2, 2017 (Threatpost)
2017-06-02 14:30

Mike Mimoso and Chris Brook discuss the news of the week, including the ShadowBrokers crowdfunding attempt, errors in WannaCry, a new Wikileaks dump, last week's Samba vulnerability, and the...

WikiLeaks Dumps CIA Patient Zero Windows Implant (Threatpost)
2017-06-02 13:00

Pandemic is a Windows implant built by the CIA that turns file servers into Patient Zero on a local network, infecting machines requesting files with Trojanized replacements.