Security News

Cisco Warns of High Severity Bug in NetFlow Appliance (Threatpost)
2017-03-02 20:27

Cisco is warning of a flaw that creates conditions susceptible to a DoS attack in its NetFlow Generation Appliance.

132 Google Play Apps Booted For Malicious IFrames (Threatpost)
2017-03-02 18:03

Google removed 132 apps infected with malicious iFrames from its Google Play store.

Keys for Dharma Ransomware Released (Threatpost)
2017-03-02 16:34

Decryption keys for the Dharma strain of ransomware have been released.

Cloudbleed Triggered 1.2M Times, Damage Kept to Minimum (Threatpost)
2017-03-02 16:25

Cloudflare said it could not find evidence of malicious exploitation of the Cloudbleed vulnerability, even though the bug was triggered 1.2 million times.

Yahoo Tells SEC Executives Failed to Act on Breach (Threatpost)
2017-03-02 14:55

Yahoo said in its latest SEC filing that executives and legal reps failed to act sufficiently on the information they had about breaches that exposed more than 1 billion account records.

Google reCaptcha Bypass Technique Uses Google’s Own Tools (Threatpost)
2017-03-02 12:00

A proof of concept bypass of Google's CAPTCHA verification system uses Google's own web-based tools to pull off the skirting of the system.

CloudPets Notifies California AG of Data Breach (Threatpost)
2017-03-01 20:40

Spiral Toys has filed a breach notification with the California Attorney General's office informing them of the CloudPets data breach.

Slack Fixes Cross-Origin Token Theft Bug (Threatpost)
2017-03-01 19:58

The cloud-based collaboration tool Slack was quick to fix a bug earlier this month that could have let an attacker steal a user’s private Slack token.

Robots Rife With Cybersecurity Holes (Threatpost)
2017-03-01 16:47

IOActive Labs released a report Wednesday warning that consumer, industrial, and service robots in use today have serious security vulnerabilities.

Million-Plus WordPress Sites Exposed by Vulnerable Plugin (Threatpost)
2017-03-01 12:00

The popular NextGEN Gallery WordPress plugin was recently patched to address a “severe” SQL injection vulnerability that put website databases at risk.