Security News

Fireball Malware Infects 250 Million Computers Worldwide (Threatpost)
2017-06-02 12:00

A massive malware campaign has already infected 250 million Windows and Mac OS computers worldwide.

Insecure Backend Databases Blamed for Leaking 43TB of App Data (Threatpost)
2017-06-01 18:53

More than 1,000 mobile apps are leaking personal information via unsecured backend platforms such as MongoDB, MySQL and others.

Crowdfunding Effort to Buy ShadowBrokers Exploits Shuts Down (Threatpost)
2017-06-01 16:38

A crowdfunding effort to buy a subscription to the ShadowBrokers' Monthly Dump Service of stolen exploits and data was shut down citing legal and ethical concerns.

OneLogin Breach Compromised Customer Data, Ability to Decrypt Encrypted Data (Threatpost)
2017-06-01 16:29

A breach at OneLogin appears to have compromised customer data, including the ability to decrypt encrypted data.

Hack Department of Homeland Security Act Would Bring Bug Bounty Program to DHS (Threatpost)
2017-05-31 20:25

Senators introduced a bill last week to establish a bug bounty pilot program within the Department of Homeland Security.

Patches Available for Linux Sudo Vulnerability (Threatpost)
2017-05-31 17:55

A high-severity vulnerability in sudo has been patched in a number of Linux distributions; the flaw allows local attackers to elevate privileges to root.

Cisco, Netgear Readying Patches for Samba Vulnerability (Threatpost)
2017-05-31 17:51

Cisco is prepping fixes for two of its products affected by last week's Samba vulnerability. Netgear has also pushed out a fix for NAS devices that were affected.

New Machine Learning Behind Early Phishing Detection in Gmail (Threatpost)
2017-05-31 17:00

Google announced today new security features in Gmail, including the news that it will enhance early phishing detection in Gmail through dedicated machine learning.

Privacy Issue Fixed in Yopify Ecommerce Notification Plugin (Threatpost)
2017-05-31 13:05

Ecommerce sites using the Yopify plugin were leaking customers’ names, locations and purchases.

FreeRADIUS Update Resolves Authentication Bypass (Threatpost)
2017-05-30 18:39

Developers behind FreeRADIUS, an open source implementation of the networking protocol RADIUS, are encouraging users to update to address an authentication bypass found in the server.