Security News

Ugly Password Gaffe Plagues Cryptkeeper Encryption App (Threatpost)
2017-01-31 18:02

Debian developers are recommending that the Cryptkeeper Linux encryption app be pulled from the distribution after a universal password was found.

Nicolas Brulez on Malware Reverse Engineering Tips and Tricks (Threatpost)
2017-01-31 15:01

Kaspersky Lab Principal Security Researcher Nico Brulez talks with Ryan Naraine about his upcoming SAS 2017 training on the ins and outs of malware reverse engineering and how attendees can...

Nested, Targeted Attacks Built for Reconnaissance (Threatpost)
2017-01-31 12:00

Researchers say NATO members were targeted for reconnaissance over the holidays by attacks using malicious OLE objects.

NATO Members Targeted by Unique Macro Malware (Threatpost)
2017-01-31 12:00

Researchers say NATO member were targeted over the holidays by macro malware that used advanced utilized an advanced workflow and was able to avoid analysis.

Hundreds of Thousands of Netgear Routers Vulnerable to Password Bypass (Threatpost)
2017-01-30 21:48

Hundreds of thousands–potentially more than one million–Netgear routers are susceptible to a pair of vulnerabilities that can lead to password disclosure.

Facebook Tackles Account Recovery with Delegated Recovery Protocol (Threatpost)
2017-01-30 20:56

Facebook's Delegated Recovery delegates account-recovery permissions to third-party accounts controlled by the user. GitHub is the program's first partner.

Telemarketing Firm Leaks 400,000 Recorded Calls (Threatpost)
2017-01-30 19:22

Credit card data and personal information in the form of recorded telephone sales pitches and sales confirmations were leaked online by telemarketer.

Many Android VPN Apps Breaking Privacy Promises (Threatpost)
2017-01-30 17:25

Academics studying 283 Android VPN apps quantified a number of problems associated with native platform support for VPN clients through the BIND_VPN_SERVICE.

Cisco Warns of Critical Flaw in Teleconferencing Gear (Threatpost)
2017-01-28 14:15

Cisco Systems is warning customers of a critical vulnerability affecting three of its TelePresence MCU platform models.

WordPress 4.7.2 Update Fixes XSS, SQL Injection Bugs (Threatpost)
2017-01-27 20:19

WordPress fixed three security issues, including a XSS and SQL injection, with WordPress 4.7.2 this week.