Security News

Intermediate CA Caching Could Be Used to Fingerprint Firefox Users (Threatpost)
2017-02-22 18:41

The way Firefox caches intermediate CA certificates could allow for the fingerprinting of users and the leakage of browsing details, a researcher warns.

Data Stealing Malware TeamSpy Resurfaces in Spam Campaign (Threatpost)
2017-02-21 21:08

After a nearly four-year respite, the data-stealing TeamSpy malware has resurfaced in a spam campaign.

OpenSSL Update Fixes High-Severity DoS Vulnerability (Threatpost)
2017-02-21 21:02

US-CERT issues alert to server admins warning of a dangerous OpenSSL vulnerability and urges 1.1.0 users update to version 1.1.0e.

Google Discloses Unpatched Microsoft Vulnerability (Threatpost)
2017-02-21 18:02

Google Project Zero researchers are warning of an unpatched Microsoft vulnerability in the Windows' GDI library that allows attackers to steal sensitive data from program memory.

Rook Security on Online Extortion (Threatpost)
2017-02-21 16:00

Mat Gangwer, CTO, and Tom Gorup, Security Operations Lead, at Rook Security talk to Mike Mimoso about the aggressive rise in online extortion and how it threatens not only data but physical safety.

Windows Botnet Spreading Mirai Variant (Threatpost)
2017-02-21 15:51

A Windows-based botnet is spreading a Mirai variant that is also capable of spreading to Linux systems under certain conditions, Kaspersky Lab researchers said.

Squirrels, Not Hackers, Pose Biggest Threat to Electric Grid (Threatpost)
2017-02-17 17:30

According to Marcus Sachs, CSO with the North American Electric Reliability Corporation, doomsday fears of a cyberattack against the U.S. electric grid are overblown.

SMTP Strict Transport Security Coming Soon to Gmail, Other Webmail Providers (Threatpost)
2017-02-17 15:00

SMTP Strict Transport Security is coming to major webmail providers this year, a Google engineer said at RSA Conference

Divide Between Work, Personal Data on Android Breached (Threatpost)
2017-02-16 18:50

Researchers demonstrate how malicious apps can break into secure Android work containers on EMM managed phones.

Cris Thomas on Cyberwar Rhetoric (Threatpost)
2017-02-16 14:00

Cris Thomas of Tenable Networks, aka Space Rogue of the L0pht, talks to Mike Mimoso during RSA Conference about the rhetoric and hype surrounding cyberwar, as well as a quick trip down memory lane...