Security News

‘HoeflerText’ Popups Target Browsers With RAT and Locky Ransomware (Threatpost)
2017-09-01 20:45

A malware campaign utilizing bogus “HoeflerText” popup warnings is back in full swing targeting Google Chrome and Firefox browsers with Locky ransomware attacks and the NetSupport Manager RAT.

Threatpost News Wrap, September 1, 2017 (Threatpost)
2017-09-01 15:30

The Onliner spambot, Google's forthcoming Not Secure warnings for Chrome, the WireX botnet, Sarahah privacy and more are discussed.

No Fix Planned For LabVIEW Bug, Says National Instruments (Threatpost)
2017-09-01 14:00

Researchers identified a vulnerability in National Instruments' LabVIEW software that will not receive patch by the vendor.

US Government Site Was Hosting Ransomware (Threatpost)
2017-09-01 13:00

As recently as Wednesday afternoon, a U.S. government website was hosting a malicious JavaScript downloader that led victims to installations of Cerber ransomware. The malware link has since been...

Session Hijacking Bug Exposed GitLab Users Private Tokens (Threatpost)
2017-08-31 21:00

GitLab, the popular web-based Git repository manager, fixed a vulnerability recently that could have opened its users up to session hijacking attacks.

Bugs in Arris Modems Distributed by AT&T Vulnerable to Trivial Attacks (Threatpost)
2017-08-31 18:58

Trivially exploitable vulnerabilities in several Arris home modems, routers and gateways distributed to consumers and small businesses through AT&T’s U-verse service have been discovered.

FDA Recalls 465K Pacemakers Tied to MedSec Research (Threatpost)
2017-08-31 17:26

Abbott Laboratories releases software fixes for pacemakers that could allow an attacker to wirelessly access the devices and steal personal data, drain the battery and disrupt normal...

Reflected XSS Bug Patched in Popular WooCommerce WordPress Plugin (Threatpost)
2017-08-31 13:30

Automattic has patched a reflected cross-site scripting vulnerability in the WooCommerce WordPress plugin.

Intel Confirms Its Much-Loathed ME Feature Has A Kill Switch (Threatpost)
2017-08-30 21:43

A previously undocumented kill switch for a remote management feature baked into many Intel chips can be switched off.

Turla APT Used WhiteBear Espionage Tools Against Defense Industry, Embassies (Threatpost)
2017-08-30 19:18

The Turla APT's WhiteBear toolset was used to attack defense organizations as recently as June, and diplomatic targets in Europe, Asia and South America during most of 2016.