Security News

Many Commercial Drones ‘Insecure by Design’ (Threatpost)
2017-05-04 19:54

Drones, many readily available on e-commerce shops like Amazon, are plagued by vulnerabilities that could give attackers full root access to the device, read or delete files, or crash the device.

1 Million Gmail Users Impacted by Google Docs Phishing Attack (Threatpost)
2017-05-04 17:34

Researchers said good social engineering and users’ trust in the convenience afforded by the OAUTH mechanism guaranteed Wednesday’s Google Docs phishing attacks would spread quickly.

Blackmoon Banking Trojan Using New Infection Technique (Threatpost)
2017-05-04 17:32

Security researchers say the Blackmoon banking Trojan targeting exclusively South Korean financial institutions has developed a new malware infection technique.

Unpatched WordPress Password Reset Vulnerability Lingers (Threatpost)
2017-05-04 16:46

A zero day vulnerability exists in WordPress Core that in some instances, could allow an attacker to reset a user's password and in turn, gain access to their account.

Google Shuts Down Docs Phishing Spree (Threatpost)
2017-05-03 22:28

Google has removed offending accounts involved in a widespread phishing attack today impersonating Google Docs.

Sabre Corp. Investigating Breach of Reservation System (Threatpost)
2017-05-03 19:44

Travel services company Sabre Corp. said in a SEC filing that its investigating a data breach in its Hospitality Solutions reservation system.

Researcher: ‘Baseless Assumptions’ Exist About Intel AMT Vulnerability (Threatpost)
2017-05-03 19:39

Embedi, which is behind the Intel AMT vulnerability revealed Monday, seeks to clarify "baseless assumptions" being made about the flaw.

Proposed NIST Password Guidelines Soften Length, Complexity Focus (Threatpost)
2017-05-03 17:55

NIST's latest password guidelines focus less on length and complexity of secrets and more on other measures such as 2FA, throttling, and blacklists.

Shamoon Collaborator Greenbug Adopts New Communication Tool (Threatpost)
2017-05-02 21:52

New clues surface on Shamoon’s ability steal credentials ahead of attacks.

IBM: Destroy USBs Infected with Malware Dropper (Threatpost)
2017-05-02 20:07

USB drives shipped with some IBM’s Storwize storage products are infected with malware, and the tech giant advises customers destroy the devices.