Security News

Dridex Returns With Windows UAC Bypass Method (Threatpost)
2017-01-27 18:56

Dridex banking malware returns with a new bypass technique that allows the malware to execute without triggering a Windows UAC alert to the user.

Google to Operate its Own Root CA (Threatpost)
2017-01-27 17:07

Google announced that it will operate its own root Certificate Authority, stood up by the acquisition of two root CAs from GlobalSign.

Threatpost News Wrap, January 27, 2017 (Threatpost)
2017-01-27 07:00

The Star Wars Twitter botnet, the return of Lavabit, a critical Cisco Webex flaw, and the St. Louis Library ransomware story are discussed.

Facebook Touts ‘Safer’ Security Key Login (Threatpost)
2017-01-26 19:38

Facebook is letting users tie a physical security key to their account as an added layer of security.

Bill Calls for Study of Cybersecurity Standards for Cars (Threatpost)
2017-01-26 18:55

A bipartisan bill was introduced this week in the House calling for the NHTSA to conduct a study that would determine appropriate cybersecurity standards for motor vehicles.

Uber.com Backup Bug Nets Researcher $9K (Threatpost)
2017-01-26 16:16

A researcher earned $9K for identifying a XXE vulnerability in third party backup software used by Uber.

Google to Block .js Attachments in Gmail (Threatpost)
2017-01-26 14:53

Citing security concerns, Google announced that it will soon block JavaScript (.js) file attachments in Gmail.

High-Severity Chrome Vulnerabilities Earn Researcher $32K in Rewards (Threatpost)
2017-01-26 14:00

Researcher Mariusz Mlynski found and disclosed four high-severity vulnerabilities in Chrome’s Blink rendering engine, earning himself $32,000 through the Chrome Rewards program.

Half of Ransomware Victims Pay Criminals’ Demands to Recover Data (Threatpost)
2017-01-26 12:00

A Ponemon Institute report on ransomware revealed 48 percent of businesses surveyed paid a ransom in exchange for getting their data back.

Default Credentials Found in Schneider Electric Wonderware Historian (Threatpost)
2017-01-25 20:11

ICS-CERT warns of default credentials in Schneider Electric Wonderware Historian that can be abused to compromise Historian databases.