Security News

Keylogger Found in Audio Drivers on Some HP Machines (Threatpost)
2017-05-11 15:34

Researchers say an audio driver that comes installed on some HP-manufactured computers can record users keystrokes and store them in a world-readable plaintext file.

ASUS Patches RT Router Vulnerabilities (Threatpost)
2017-05-11 14:15

ASUS updated the firmware in March of a number of its RT routers to address vulnerabilities found within the device’s native web interface.

Session Hijacking, Cookie-Stealing WordPress Malware Spotted (Threatpost)
2017-05-10 20:03

Researchers spotted a strain of cookie stealing malware, injected into a legitimate JavaScript file, masquerading as a WordPress core domain.

Android Permissions Flaw Will Linger Until O Release (Threatpost)
2017-05-10 17:57

Google said a permissions flaw that puts Android users at heightened risk of malware, ransomware and adware attacks will not be fixed until the release of its next mobile OS, Android O.

Microsoft Makes it Official, Cuts off SHA-1 Support in IE, Edge (Threatpost)
2017-05-10 17:09

Yesterday’s Patch Tuesday release also included an update to Microsoft’s Internet Explorer and Edge browsers officially ending support for the SHA-1 hash function.

Cisco Patches IOS XE Vulnerability Leaked in Vault 7 Dump (Threatpost)
2017-05-10 14:10

Cisco released an update that patches a vulnerability in the CMP processing code running in its IOS and IOS XE software in more than 300 of its switches.

Microsoft Plugs Three Zero Day Holes as Part of May Patch Tuesday (Threatpost)
2017-05-09 21:16

Microsoft patched three zero day vulnerabilities actively under attack today as part of its May Patch Tuesday release.

Google’s OSS-Fuzz Finds 1,000 Open Source Bugs (Threatpost)
2017-05-09 20:41

Google said Tuesday that its OSS-Fuzz project has unearthed over 1,000 bugs, a quarter of them potential security vulnerabilities.

Adobe Patches Seven Critical Vulnerabilities in Flash, AEM (Threatpost)
2017-05-09 16:16

Adobe fixed eight vulnerabilities, seven critical, in Flash Player and Adobe Experience Manager (AEM) Forms product as part of its regularly scheduled updates Tuesday morning.

Emergency Update Patches Zero Day in Microsoft Malware Protection Engine (Threatpost)
2017-05-09 13:12

Microsoft released an emergency update for a zero-day vulnerability disclosed by Google in the Microsoft Malware Protection Engine bundled with most versions of Windows.