Security News

Latest Tax Scams Include Phishing Lures, Malware (Threatpost)
2017-03-21 15:54

Microsoft warns this year’s crop of tax scams use social engineering attacks based on fear to spread banking Trojans and collect personal info.

Local Windows Admins Can Hijack Sessions Without Credentials (Threatpost)
2017-03-20 18:50

A researcher has published a method by which a local admin can hijack any other Windows sessions without the need for credentials.

Mozilla Patches Pwn2Own Zero Day in Firefox (Threatpost)
2017-03-20 17:50

Mozilla patched a zero day uncovered at Pwn2Own in Firefox in 22 hours on Friday.

Cisco Warns of Critical Vulnerability Revealed in ‘Vault 7’ Data Dump (Threatpost)
2017-03-20 17:20

Cisco said an unpatched critical vulnerability exposed by WikiLeaks' Vault 7 release of CIA documents could give an attacker full control of the targeted switches and routers.

Jon Oberheide on Perimeter Security (Threatpost)
2017-03-20 14:35

Mike Mimoso talks to Duo Security co-founder and CTO Jon Oberheide at RSA Conference about Google's BeyondCorp security model, enforcing perimeter security, how endpoint security has evolved...

VM Escape Earns Hackers $105K at Pwn2Own (Threatpost)
2017-03-17 18:12

Hackers pulled off a VM escape and took down Adobe Flash, Microsoft Windows and Edge, Apple Safari and macOS, and Mozilla Firefox at Pwn2Own 2017.

Vulnerability Disclosed in Ubquiti Networks Admin Interface (Threatpost)
2017-03-17 16:49

Researchers at SEC Consult disclosed a command injection vulnerability in Ubiquiti Networks gear for ISPs after a private disclosure to the vendor in November went unresolved.

Threatpost News Wrap, March 17, 2017 (Threatpost)
2017-03-17 15:00

Mike Mimoso and Chris Brook discuss the news of the week, including Pwn2Own 2017, Microsoft's silence around February's Patch Tuesday, and a nasty SAP bug.

GitHub Code Execution Bug Fetches $18,000 Bounty (Threatpost)
2017-03-17 13:00

GitHub awarded $18,000 to a researcher after he came across a remote code execution bug in the company’s enterprise management console.

US-CERT Warns HTTPS Inspection May Degrade TLS Security (Threatpost)
2017-03-17 10:00

Security tools that proxy and inspect HTTPS traffic create a blindspot for network administrators trying to determine whether communication between clients and servers is secure.