Security News

Password Breaches Fueling Booming Credential Stuffing Business (Threatpost)
2017-05-24 21:49

The market for automated credential stuffing tools is growing fast, because of a record number of breaches.

Android Overlay and Accessibility Features Leave Millions at Risk (Threatpost)
2017-05-24 18:05

Researchers warn two features, not flaws, in Android can be used together to open devices up to attack.

Twitter Flaw Could Have Allowed Attacker to Tweet From Any Account (Threatpost)
2017-05-24 16:30

Twitter fixed a flaw in its Twitter Ads service could have allowed an attacker to tweet as any user.

Malware Network Communication Provides Better Early Warning Signal (Threatpost)
2017-05-24 15:10

An academic paper to be presented today at IEEE posits that analysis of network signals provides a better early warning of malware than infections than current practices.

Subtitle Hack Leaves 200 Million Vulnerable to Remote Code Execution (Threatpost)
2017-05-23 21:33

Attackers can remotely execute code on targeted systems via specially crafted subtitle files for videos.

Google Elevates Security in Android O (Threatpost)
2017-05-23 20:13

Android O, due in the third quarter, figures to elevate the security of the mobile OS with new features focused on improved third-party patching, a new permission model and hardening of existing features.

Yahoo Retires ImageMagick After Bugs Leak Server Memory (Threatpost)
2017-05-23 18:00

Researcher Chris Evans reported a new bug and showed how also used a previously known flaw in ImageMagick to leak Yahoo server data and steal images and authentication secrets.

Apple Receives First National Security Letter, Reports Spike in Requests for Data (Threatpost)
2017-05-23 17:06

Apple revealed this week that it received at least one National Security Letter from the U.S. government for user data during the last six months of 2016

Trump’s Cybersecurity Boss Talks Priorities (Threatpost)
2017-05-22 21:25

The country's top cybersecurity boss said the country is headed the wrong way when it comes to cybersecurity.

Verizon Patches XSS Issues in its Messaging Client (Threatpost)
2017-05-22 19:25

Verizon patched late last year persistent- DOM-based cross-site scripting vulnerabilities in its Message+ messaging client that could allow an attacker to control a user's session.