Security News

Privilege Escalation Flaw Patched in Schneider Wonderware (Threatpost)
2017-03-10 14:00

Schneider Electric patched a vulnerability in the Tableau Server running in its Wonderware analytics and visualization platform that could allow an attacker to elevate privileges.

Zero Days Have Staying Power (Threatpost)
2017-03-10 12:00

A look at 200 zero day vulnerabilities reveals key details on longevity, value and how long it takes to create one after a software vulnerability has been identified.

Hundreds of Thousands of Vulnerable IP Cameras Easy Target for Botnet, Researcher Says (Threatpost)
2017-03-09 21:59

A researcher claims that almost 200,000 shoddily made IP cameras could be an easy target for attackers looking to spy, brute force them or steal their credentials.

Attacks Heating Up Against Apache Struts 2 Vulnerability (Threatpost)
2017-03-09 17:25

Apache administrators are urged to immediately upgrade the Struts 2 web application framework to address a remote code execution flaw under public attack.

Senator Demands Answers About CloudPets Breach (Threatpost)
2017-03-08 20:41

A U.S. senator from Florida sent Spiral Toys CEO Mark Meyers a letter demanding answers about the recent CloudPets breach.

Confide Updates App After Critical Security Issues Are Raised (Threatpost)
2017-03-08 19:03

The makers of the popular messaging app Confide said Wednesday it has patched multiple security vulnerabilities that could have allowed hackers to intercept messages sent using its secure...

Firefox 52 Expands Non-Secure HTTP Warnings, Enables SHA-1 Deprecation (Threatpost)
2017-03-08 17:36

The latest version of Firefox expands non-secure HTTP warnings, enables SHA-1 deprecation by default, and removes support for NPAPI.

Comey Talks Strong Crypto, Silent on WikiLeaks (Threatpost)
2017-03-08 16:02

FBI Director James Comey revived old rhetoric on strong encryption during a keynote at the Boston Conference on Cyber Security. He did not address the leak of CIA hacking tools or Russia during his talk.

WordPress 4.7.3 Patches Half-Dozen Vulnerabilities (Threatpost)
2017-03-07 20:40

WordPress released version 4.7.3 which patches six vulnerabilities including one that could be chained with the REST API Endpoint vulnerability.

Unpatched Western Digital Bugs Leave NAS Boxes Open to Attack (Threatpost)
2017-03-07 18:58

Western Digital NAS owners were warned of critical flaws in the company’s My Cloud line of hardware that opened up data stored on those devices to attack.