Security News

Open Databases a Juicy Extortion Target (Threatpost)
2017-02-13 16:00

A sudden wave of attacks against insecure databases resulting in ransom demands points to wave of data hijacking attacks.

Threatpost News Wrap, February 13, 2017 (Threatpost)
2017-02-13 14:00

RSA 2017 is previewed and last week's report on iOS apps being vulnerable to interception attacks, macro malware coming to MacOS, and new Uber open source module are discussed.

1.5M Unpatched WordPress Sites Hacked Following Vulnerability Disclosure (Threatpost)
2017-02-10 16:45

WordPress security experts said that 1.5M sites have been defaced following the disclosure of a silently fixed content injection vulnerability.

High Severity BIND Vulnerability Can Lead to A Crash (Threatpost)
2017-02-09 18:13

The Internet Systems Consortium patched the BIND domain name system this week, addressing a remotely exploitable vulnerability it said could lead to a crash.

CryptoShield Infections from RIG EK Picking Up (Threatpost)
2017-02-09 16:06

Researchers have spotted an increase in CryptoShield ransomware infections coming from the RIG Exploit Kit used by EITest delivery campaigns.

Dino Dai Zovi on Securing Linux in Modern Workloads (Threatpost)
2017-02-09 14:45

Security researcher Dino Dai Zovi talks about a new company he cofounded called Capsule8 that will help IT organizations counter threats to Linux infrastructures.

Fileless Memory-Based Malware Plagues 140 Banks, Enterprises (Threatpost)
2017-02-08 21:37

Attackers have been using fileless malware to hide in the memory of enterprises, steal data, and vanish without a trace.

Valve Patches Trivial XSS Bug in Steam (Threatpost)
2017-02-08 17:00

A cross-site scripting vulnerability on the Steam gaming platform has been patched. The flaw could be exploited by simply viewing a crafted profile.

Uber Debuts SSH Key Authentication Module (Threatpost)
2017-02-08 15:30

Developers at Uber have unveiled a new module to help users enable the continuous re-authentication of SSH keys.

Consortium Publishes Manifesto on Autonomous Vehicle Security (Threatpost)
2017-02-08 14:00

A new industry consortium publishes a manifesto it hopes will foster cooperation on the security of autonomous vehicles.