Security News

ColdFusion Hotfix Resolves XSS, Java Deserialization Bugs (Threatpost)
2017-04-25 16:36

Adobe released an important security hotfix for several versions of Coldfusion, resolving two bugs, Tuesday morning.

Zimperium Acquisition Program Publishes Exploits for Patched Android Bugs (Threatpost)
2017-04-25 14:30

Exploits for patched Android elevation of privilege vulnerabilities were published through the Zimperium N-Days Exploit Acquisition Program.

Hyundai Patches Leaky Blue Link Mobile App (Threatpost)
2017-04-25 13:05

Hyundai Motor America patched its Blue Link mobile app after researchers found a cleartext encryption key that could be use to expose user and vehicle information.

Hard Target: Fileless Malware (Threatpost)
2017-04-25 11:00

Researchers say fileless in-memory malware attacks have become a major nuisance to businesses and have become even harder to detect and defend.

Original XPan Ransomware Returns, Targets Brazilian SMBs (Threatpost)
2017-04-25 10:00

Brazilian cybercriminals are using the original version of the XPan ransomware, targeting small to medium-sized business based in Brazil with the malware.

NSA’s DoublePulsar Kernel Exploit In Use Internet-Wide (Threatpost)
2017-04-24 19:59

Scans show tens of thousands of Windows servers infected with the DoublePulsar kernel exploit leaked by the ShadowBrokers 10 days ago.

Locky Ransomware Roars Back to Life Via Necurs Botnet (Threatpost)
2017-04-24 18:53

The first large scale Locky campaign in months has been detected via the Necurs botnet.

No Fix for SquirrelMail Remote Code Execution Vulnerability (Threatpost)
2017-04-24 17:52

SquirrelMail suffers from a remote code execution vulnerability that could let attackers execute arbitrary commands on the target and compromise the remote system.

SMSVova Spyware Hiding in ‘System Update’ App Ejected From Google Play Store (Threatpost)
2017-04-22 12:00

An Android app that falsely claimed to be a tool for keeping smartphones up-to-date with the latest version of the OS was found surreptitiously tracking the physical location of it users using...

Skype Fixes ‘SPYKE’ Credential Phishing Remote Execution Bug (Threatpost)
2017-04-21 20:00

Microsoft fixed a bug in Skype last month that could have allowed an attacker to execute code on the system it was running on, phish Skype credentials and crash the application.