Security News

Patches Pending for Medical Devices Hit By WannaCry (Threatpost)
2017-05-18 14:18

Companies such as Siemens and Bayer are planning to release patches for medical devices hit by the ransomware WannaCry over the past several days.

APT3 Linked to Chinese Ministry of State Security (Threatpost)
2017-05-17 18:52

Researchers claim that APT3, widely believed to be a China-based threat actor, is directly connected to the Chinese Ministry of State Security (MSS).

Next NSA Exploit Payload Could be Much Worse Than WannaCry (Threatpost)
2017-05-17 17:19

Researchers urge Windows admins to apply MS17-010 before the next attack using the EternalBlue NSA exploit deploys a worse payload than WannaCry ransomware.

DocuSign Phishing Campaign Includes Hancitor Downloader (Threatpost)
2017-05-16 18:38

DocuSign warns of a breach and subsequent theft of email addresses that are part of a phishing campaign that employs malicious macro-laced Word documents.

Apple Patches Pwn2Own Vulnerabilities in Safari, macOS, iOS (Threatpost)
2017-05-16 17:56

Apple fixed 66 vulnerabilities - many found at March's Pwn2Own competition - across seven product lines, including Safari, iTunes, macOS, and iOS, on Monday.

WannaCry Shares Code with Lazarus APT Samples (Threatpost)
2017-05-16 15:45

Experts have confirmed there are similarities between code used by the ransomware WannaCry and the Lazarus APT.

Chrome Browser Hack Opens Door to Credential Theft (Threatpost)
2017-05-16 14:00

Researchers at DefenseCode claim a vulnerability in Google’s Chrome browser allows hackers to steal credentials and launch SMB relay attacks.

ShadowBrokers Planning Monthly Exploit, Data Dump Service (Threatpost)
2017-05-16 12:30

The latest rant from the ShadowBrokers ends with news of a subscription service starting in June that will leak exploits and stolen data to paying customers.

WikiLeaks Reveals Two CIA Malware Frameworks (Threatpost)
2017-05-16 10:39

WikiLeaks released details on what it claims are two frameworks for malware samples dubbed AfterMindnight and Assassin, both allegedly developed by the US Central Intelligence Agency.

OpenVPN Audits Yield Mixed Bag (Threatpost)
2017-05-15 21:12

The results of two audits of the open source software OpenVPN were shared late last week. One found two legitimate vulnerabilities, the other said the service is cryptographically "solid."