Security News

Researchers Uncover New Leads Behind Shamoon2 (Threatpost)
2017-02-24 22:06

Researchers from Arbor Networks' Security Engineering and Response Team (ASERT) say they have unearthed fresh leads on the tools and techniques used in the most recent wave of Shamoon attacks.

Threatpost News Wrap, February 24, 2017 (Threatpost)
2017-02-24 17:00

Mike Mimoso and Chris Brook recap RSA and discuss the news of the week including the impact of Cloudflare's "Cloudbleed" bug, Google breaking SHA-1, and more.

Cloudflare Bug Leaks Sensitive Data (Threatpost)
2017-02-24 15:48

Cloudflare has fixed an issue where its customer traffic was leaking memory that included sensitive information including authentication cookies, POST data and more.

Policy Experts Push To Make Vulnerability Equities Process Law (Threatpost)
2017-02-23 21:37

By making the Vulnerability Equities Process law, advocates of the idea argue there would be more reliability, transparency and accountability in the process of government vulnerability disclosure.

First Practical SHA-1 Collision Attack Arrives (Threatpost)
2017-02-23 18:17

Researchers unveiled the first-ever practical collision attack the cryptographic hash function SHA-1.

Impact of New Linux Kernel DCCP Vulnerability Limited (Threatpost)
2017-02-23 16:11

Existing mitigations and limitations around a newly disclosed Linux kernel vulnerability in the DCCP module mute the potential impact of local attacks.

Java, Python FTP Injection Attacks Bypass Firewalls (Threatpost)
2017-02-23 14:19

Newly disclosed FTP injection vulnerabilities in Java and Python that are fueled by rather common XML External Entity (XXE) flaws allow for firewall bypasses.

Publicly Disclosed Windows Vulnerabilities Await Patches (Threatpost)
2017-02-23 13:00

Microsoft's delayed release of its February security bulletins leaves users exposed to a pair of already publicly disclosed vulnerabilities.

Criminals Monetizing Attacks Against Unpatched WordPress Sites (Threatpost)
2017-02-22 21:46

Sites still vulnerable to a REST API endpoint flaw in WordPress are now being targeted by attackers trying to turn a profit.

Google Upspin Secure File-Sharing Released to Open Source (Threatpost)
2017-02-22 18:44

New file-sharing protocols and interfaces called Upspin have been released to open source. Built by Google, Upspin returns access control and data security to the user.