Security News

Exploit Kit Activity Quiets, But Is Far From Silent (Threatpost)
2017-04-14 10:00

Here are the exploit kits to watch for over the next three to six months.

FDA Demands St. Jude Take Action on Medical Device Security (Threatpost)
2017-04-13 18:19

The FDA sent Abbott Laboratories a warning letter citing that it had inadequately addressed the security of the maligned Merlin@home Transmitter.

‘High Risk’ Zero Day Leaves 200,000 Magento Merchants Vulnerable (Threatpost)
2017-04-13 16:51

A popular version of the Magento ecommerce platform is vulnerable to a remote code execution bug, putting as many as 200,000 online retailers at risk.

Netflix’s HTTPS Update Can’t Combat Passive Traffic Analysis Attacks (Threatpost)
2017-04-12 21:04

Academics argue that Netflix's recent upgrade to HTTPS is doing little to protect its users from a passive traffic analysis attack.

Phone Hack Uses Sensors To Steal PINs (Threatpost)
2017-04-12 20:00

University researchers created a browser-based JavaScript that leverages a phone's smart device sensor data to steal PINs.

Office Zero Day Delivering FINSPY Spyware to Victims in Russia (Threatpost)
2017-04-12 18:58

Researchers have learned that the recently patched Office zero day was used to target victims in Russia with FINSPY spyware.

SAP Updates Two-Year-Old Patch for TREX Vulnerability (Threatpost)
2017-04-12 15:18

SAP has issued an updated patch for a code-injection vulnerability affecting the TREX search engine integrated into more than a dozen SAP products.

Microsoft Patches Three Vulnerabilities Under Attack (Threatpost)
2017-04-11 22:19

Microsoft Patch Tuesday fixes 45 vulnerabilities, one being an active zero-day bug used to spread the Dridex banking Trojan.

Adobe Patches 59 Vulnerabilities Across Flash, Reader, Photoshop (Threatpost)
2017-04-11 18:58

Adobe patched 59 vulnerabilities across five different products, including Flash Player, Acrobat/Reader, Photoshop, Adobe Campaign, and its Adobe Creative Cloud App on Tuesday.

Microsoft Patches Word Zero-Day Spreading Dridex Malware (Threatpost)
2017-04-11 18:41

A Microsoft Word zero-day vulnerability is being used to spread the Dridex banking Trojan in attacks that have bypassed mitigation efforts.