Security News

New Clues Surface on Shamoon 2’s Destructive Behavior (Threatpost)
2017-03-27 20:51

Researchers report new connections between Magic Hound and Shamoon 2, along with descriptions of how the Disttrack malware component of campaigns moves laterally within infected networks.

APT29 Used Domain Fronting, Tor to Execute Backdoor (Threatpost)
2017-03-27 20:14

APT29, a/k/a Cozy Bear, has used Tor and a technique called domain fronting in order to secure backdoor access to targets for nearly two years running.

Fileless UAC Bypass Uses Windows Backup and Restore Utility (Threatpost)
2017-03-27 16:13

Researcher Matt Nelson disclosed another Windows UAC bypass, this one abusing the sdclt.exe backup and restore utility to execute a payload without triggering an alert.

Experts Doubt Hackers’ Claim Of Millions Of Breached Apple Credentials (Threatpost)
2017-03-25 12:00

Security experts say they are skeptical that a group called Turkish Crime Family actually possess a cache of hundreds of millions of Apple iCloud account credentials.

Privacy Advocates Vow to Fight Rollback of Broadband Privacy Rules (Threatpost)
2017-03-24 17:59

Privacy activists say rolling-back ISP privacy rules means health, financial and browsing habits can be used, shared and sold to the highest bidder without consent.

Instagram Adds Two-Factor Authentication (Threatpost)
2017-03-24 17:46

Instagram became the latest in a long line of services over the years to offer users two-factor authentication.

Threatpost News Wrap, March 27, 2017 (Threatpost)
2017-03-24 14:45

The latest Wikileaks dump of Apple hacking tools, the LastPass vulnerabilities, and a new Android security report are discussed.

Adware Apps Booted from Google Play (Threatpost)
2017-03-24 13:37

More than a dozen apps removed from Google Play store after it was determined they were overly aggressive adware.

WikiLeaks Dump Shows CIA Interdiction of iPhone Supply Chain (Threatpost)
2017-03-23 19:46

Today's WikiLeaks Vault 7 Dark Matter release shows the CIA's capabilities to attack and persist on Apple iPhone and Mac firmware and an apparent interdiction of the iPhone supply chain.

Cisco Patches Critical IOx Vulnerability (Threatpost)
2017-03-23 19:24

Cisco Systems patched a critical vulnerability that could give an attacker root privileges to software running on two of its IoT router models.