Security News

Siemens RUGGEDCOM NMS Equipment Vulnerable to CSRF, XSS (Threatpost)
2017-02-28 21:59

Siemens line RUGGEDCOM NMS products suffers from vulnerabilities that could allow an attacker to perform administrative actions.

Dridex Trojan Gets A Major ‘AtomBombing’ Update (Threatpost)
2017-02-28 20:17

Dridex has undergone a massive update and now sports a new injection method for evading detection based on the technique known as AtomBombing.

Unpatched SMB Zero Day Easily Exploitable (Threatpost)
2017-02-28 18:44

Researchers claim the unpatched SMB zero day that affects Windows can be exploited a number of ways.

Children’s Voice Messages Leaked in CloudPets Database Breach (Threatpost)
2017-02-28 17:22

Voice messages from children sent through an internet-connected toy called CloudPets were stolen from an exposed MongoDB database, which has been wiped clean and the data held for ransom.

Torvalds Downplays SHA-1 Threat to Git (Threatpost)
2017-02-28 15:21

The ramifications of the recent SHA-1 collision attack have extended to Git and the Apache Subversion repository, both of which rely on the outdated and vulnerable hashing algorithm.

Boeing Notifies 36,000 Employees Following Breach (Threatpost)
2017-02-27 20:48

A Boeing employee inadvertently leaked the personal information of 36,000 of his co-workers late last year when he emailed a company spreadsheet to his non-Boeing spouse.

Google Discloses Another ‘High Severity’ Microsoft Bug (Threatpost)
2017-02-27 18:50

Google’s security researchers disclosed details of an unpatched Microsoft vulnerability in its Edge and Internet Explorer browsers.

Katie Moussouris on Bug Bounty Programs, Hack the Army, and Wassenaar (Threatpost)
2017-02-27 15:15

Katie Moussouris on how bug bounty programs have gone mainstream, the success of Hack the Pentagon and Hack the Army, and where things stand with the Wassenaar Arrangement.

Google Releases E2EMail to Open Source (Threatpost)
2017-02-27 14:19

Google’s E2EMail Chrome extension brings OpenPGP encryption to Gmail users.

Necurs Botnet Learns New DDoS Trick (Threatpost)
2017-02-27 12:00

Researchers say Necurs malware has been updated with a module that adds SOCKS/HTTP proxy and DDOS capabilities to this malware.