Security News

IHG Confirms Second Credit Card Breach Impacting 1,000-Plus Hotels (Threatpost)
2017-04-18 18:15

InterContinental Hotels Group said on Friday that it found malware designed to access payment card data at more than 1,000 of its hotels.

Facebook Delegated Account Recovery SDKs Published for Java, Ruby Apps (Threatpost)
2017-04-18 17:45

At F8 today, Facebook released SDKs and documentation for the integration of Delegated Account Recovery into Java, NodeJS and Ruby applications.

Low-Cost Ransomware Service Discovered (Threatpost)
2017-04-18 12:23

A new ransomware-as-a-service called Karmen appeals to ransomware newbies with a low price, easy setup and developer updates.

Wave of Java-Based RATs Target Tax Filers (Threatpost)
2017-04-17 19:13

A rash of Java-based remote access Trojans is targeting tax filers with bogus IRS attachments.

ShadowBrokers’ Windows Zero-Days Already Patched (Threatpost)
2017-04-17 18:06

Microsoft eased some anxiety over the latest ShadowBrokers dump of Windows zero days with news most of the vulnerabilities had already been patched.

VMWare Fixes Critical RCE in vCenter Server (Threatpost)
2017-04-17 16:05

VMware patched a critical vulnerability in its vCenter Server platform late last week that could have let an attacker execute arbitrary code in some scenarios.

ShadowBrokers Expose NSA Access to SWIFT Service Bureaus (Threatpost)
2017-04-14 21:08

The latest ShadowBrokers dump includes exploits that allowed the NSA to target SWIFT data managed by outsourced service bureaus in the Middle East.

Google Making Life Difficult for Ransomware to Thrive on Android (Threatpost)
2017-04-14 14:00

At the Kaspersky Lab Security Analyst Summit, Android Security Team malware analyst Elena Kovakina explained Google’s strategy for countering ransomware on Android.

Threatpost News Wrap, April 14, 2017 (Threatpost)
2017-04-14 13:00

Mike Mimoso, Tom Spring, and Chris Brook recap Infiltrate Con in Miami last week, and Kaspersky Lab's Security Analyst Summit in St. Maarten

Stories From Two Years in an IoT Honeypot (Threatpost)
2017-04-14 12:00

A researcher at this year's Security Analyst Summit staged a series of honeypots at his friends’ houses to record IoT traffic, exploit attempts and other statistics.