Security News

EternalRocks Worm Spreads Seven NSA SMB Exploits (Threatpost)
2017-05-22 17:05

A worm called EternalRocks has been spreading seven Windows SMB exploits leaked by the ShadowBrokers, including EternalBlue, which was used to spread WannaCry.

Jaya Baloo on WannaCry and Defending Against Advanced Attacks (Threatpost)
2017-05-22 13:00

Jaya Baloo, CISO of KPN, the Netherlands’ leading telecommunications provider, talks to Mike Mimoso about the WannaCry ransomware outbreak and how large network providers and enterprises must...

Terror Exploit Kit Evolves Into Larger Threat (Threatpost)
2017-05-19 18:22

The Terror exploit kit has matured into a greater threat and carefully crafts attacks based on a user's browser environment.

Available Tools Making Dent in WannaCry Encryption (Threatpost)
2017-05-19 17:04

Tools are beginning to emerge that can be used to begin the process of recovering files encrypted by WannaCry on some Windows systems.

VMware Patches Multiple Security Issues in Workstation (Threatpost)
2017-05-19 16:47

VMware fixed two bugs in its VMware Workstation late Thursday night, including an insecure library loading vulnerability and a NULL pointer dereference vulnerability.

Threatpost News Wrap, May 19, 2017 (Threatpost)
2017-05-19 13:00

Mike Mimoso and Chris Brook discuss WannaCry, Microsoft's response, the killswitches, a potential link with Lazarus Group, and what the future holds for the ShadowBrokers.

PATCH Act Calls for VEP Review Board (Threatpost)
2017-05-18 20:57

The PATCH Act proposes the formation of a review board that would formalize and make transparent the processes by which the government determines whether it will use or disclose a zero-day vulnerability.

Android Gets Security Makeover With Google Play Protect (Threatpost)
2017-05-18 20:49

Google announces big changes for Android security including new features, a rebranding of old services and an updated UI, all streamlined under a new service called Google Play Protect.

WordPress Fixes CSRF, XSS Bugs, Announces Bug Bounty Program (Threatpost)
2017-05-18 18:17

WordPress fixed six vulnerabilities with version 4.7.5 and announced a bug bounty program with HackerOne this week.

Senate’s Use of Signal A Good First Step, Experts Say (Threatpost)
2017-05-18 16:05

The Senate's use of the end-to-end encrypted messaging app Signal is a good first step in protecting U.S. democratic institutions, but much more needs to be protected.