Security News

Fileless Malware Campaigns Tied to Same Attacker (Threatpost)
2017-03-16 18:00

Two recent fileless malware campaigns targeting financial institutions, government agencies and other enterprises have been linked to the same attack group.

Hackers Take Down Reader, Safari, Edge, Ubuntu Linux at Pwn2Own 2017 (Threatpost)
2017-03-16 16:32

On the first day of Pwn2Own 2017 hackers poked holes in Adobe Reader, Apple Safari, Microsoft Edge, and Ubuntu Linux.

Intel, Microsoft Announce New Bug Bounties (Threatpost)
2017-03-15 20:59

Intel and Microsoft announced bug bounties, paying $30,000 and $15,000 respectively for critical vulnerabilities.

WhatsApp, Telegram Vulnerabilities Exposed Users to Account Takeover (Threatpost)
2017-03-15 18:35

WhatsApp and Telegram patched vulnerabilities in the last week that could have let an attacker take over a user's account.

FSB Officers, Criminal Hackers Indicted in Yahoo Breach (Threatpost)
2017-03-15 17:32

The Department of Justice indicted four individuals, including two Russian FSB officers, for their roles in the Yahoo breach.

JSON Libraries Patched Against Invalid Curve Crypto Attack (Threatpost)
2017-03-15 15:46

JSON libraries using the JWE specification to create, sign and encrypt access tokens have been patched against an attack that allows for the recovery of a private key.

Where Have All The Exploit Kits Gone? (Threatpost)
2017-03-15 13:30

For a long time, exploit kits were the most prolific malware distribution vehicle available to attackers. Where did they go and what’s replaced them?

Google Eliminates Android Adfraud Botnet Chamois (Threatpost)
2017-03-14 19:40

Google removed a family of malicious apps, Chamois, from its Play marketplace recently that were found manipulating ad traffic.

Patch Tuesday Returns; Microsoft Quiet on Postponement (Threatpost)
2017-03-14 19:26

Microsoft released 18 security bulletins, eight rated critical. The company also patched publicly disclosed vulnerabilities that surfaced since last month’s postponement of Patch Tuesday.

Adobe Fixes Six Code Execution Bugs in Flash (Threatpost)
2017-03-14 16:39

Adobe fixed seven vulnerabilities, six that could lead to code execution, in Flash Player on Tuesday.