Security News

Threatpost News Wrap, April 21, 2017 (Threatpost)
2017-04-21 15:20

Mike Mimoso and Chris Brook discuss the news of the week, including last Friday's ShadowBrokers dump - how Microsoft learned of the vulnerabilities, how they were patched by Oracle, along with...

Google Pleads for Better Cross-Border Exchange of Digital Evidence (Threatpost)
2017-04-21 14:30

Google asked for MLAT reform, and released its biannual Transparency Report revealing it received a record number of government requests for user data.

Mirai and Hajime Locked Into IoT Botnet Battle (Threatpost)
2017-04-21 13:26

A white hat hacker is believed responsible for the Hajime IoT botnet because its main objective appears to be to secure IoT devices vulnerable to the notorious Mirai malware.

Google Fixes Unicode Phishing Vulnerability in Chrome 58, Firefox Standing Pat (Threatpost)
2017-04-20 18:32

Google fixed a vulnerability that could've let an attacker carry out phishing attacks with Unicode domains in Chrome but Mozilla is holding off - for now.

20 Linksys Router Models Vulnerable To Attack (Threatpost)
2017-04-20 16:38

Researchers say more than 100,000 Linksys routers in use today could be vulnerable to 10 flaws found in 20 separate router models made by the company.

Stuxnet LNK Exploits Still Widely Circulated (Threatpost)
2017-04-20 16:15

Endpoints are still encountering exploits for the LNK vulnerability, one of the principal infection mechanisms used by the Stuxnet worm.

Drupal Closes Access Bypass Vulnerability in Core Engine (Threatpost)
2017-04-20 13:57

Drupal released a point update for its core engine to patch a critical access bypass vulnerability.

Microsoft Touts New Phone-Based Login Mechanism (Threatpost)
2017-04-19 20:08

Microsoft announced this week its giving users a new way to sign into their accounts without long and complicated passwords.

Patched Flaw in Bosch Diagnostic Dongle Allowed Researchers to Shut Off Engine (Threatpost)
2017-04-19 16:58

Two vulnerabilities were identified in Bosch’s Drivelog Connect OBD-II dongle and smartphone app that allowed researchers to shut off the engine of a vehicle.

Record Oracle Patch Update Addresses ShadowBrokers, Struts 2 Vulnerabilities (Threatpost)
2017-04-19 11:20

Oracle released a record 299 patches, including a fix for a Solaris vulnerability disclosed by the ShadowBrokers, and another for the recently disclosed Apache Struts 2 flaw.