Security News

WordPress REST API Bug Could Be Used in Stored XSS Attacks (Threatpost)
2017-03-14 15:43

The recently patched REST API Endpoint vulnerability in WordPress could be leveraged to pull off stored cross-site scripting attacks.

SAP Patches Critical HANA Vulnerability That Allowed Full Access (Threatpost)
2017-03-14 12:56

SAP patched a critical vulnerability in its cloud-based business platform HANA today that if exploited, could allow for a full system compromise, without authentication.

38 Android Devices Infected with Malware Preinstalled in Supply Chain (Threatpost)
2017-03-13 20:48

Researchers at Check Point found and remediated malware on 38 Android devices that were infected somewhere along the supply chain.

Credit Card Scrapers Continue to Target Magento (Threatpost)
2017-03-13 18:52

Researchers said last week they came across a malicious function that was snuck into a module in Magento in order to steal credit card information.

March Android Security Update Breaks SafetyNet, Android Pay (Threatpost)
2017-03-13 18:01

Google has re-issued its over-the-air Android security update after Nexus 6 users reported that the patches broke the SafetyNet API and features such as Android Pay no longer worked.

Telepresence Robots Patched Against Data Leaks (Threatpost)
2017-03-13 15:59

Double Robotics telepresence robots were patched against vulnerabilities that leaked device data and session keys and tokens.

Cody Pierce on Exploit Development (Threatpost)
2017-03-13 14:27

Mike Mimoso talks to Cody Pierce, director of vulnerability research and prevention with Endgame, at RSA Conference 2017 about how attackers are changing their techniques in the face of mitigations.

Google Chrome 57 Browser Update Patches ‘High’ Severity Flaws (Threatpost)
2017-03-10 16:43

Google paid out $38,000 in bounty rewards tied to flaws it fixed with a Chrome 57 browser update.

Apache Attack Traffic Dropping, Limited to Few Sources (Threatpost)
2017-03-10 16:07

While probes looking for vulnerable Apache Struts 2 deployments continue, malicious traffic has tapered off, researchers at Rapid7 said.

Threatpost News Wrap, March 10, 2017 (Threatpost)
2017-03-10 16:00

Mike Mimoso and Chris Brook discuss the news of the week including a rash of new IP camera backdoors, James Comey's talk at Boston College, hacking back vs. active defense, and the DOJ dropping...