Security News

Firefox 51 Begins Warning Users of Insecure HTTP Connections (Threatpost)
2017-01-25 19:30

Firefox 51 includes warnings to users landing on HTTP websites, and patches for nearly a half-dozen critical security vulnerabilities.

Charger Mobile Ransomware Removed from Google Play (Threatpost)
2017-01-25 12:00

Security researchers have identified a new and evasive mobile ransomware strain called Charger on the Google Play app store.

SpyNote RAT Now Disguised As Netflix App (Threatpost)
2017-01-24 20:26

A new version of the SpyNote Trojan is designed to trick Android users into thinking it’s a legitimate Netflix application.

AG Nominee Backs Law Enforcement’s Ability to ‘Overcome’ Encryption (Threatpost)
2017-01-24 17:07

President Trump’s attorney general pick Jeff Sessions says law enforcement should be able to “overcome” encryption in criminal investigations.

St. Louis Public Library Recovers from Ransomware Attack (Threatpost)
2017-01-24 16:40

Services are being restored to the St. Louis Public Library computer system after a ransomware attack impacted access to machines and data at all 17 branches.

Cisco Patches Critical Flaw in WebEx Chrome Plugin (Threatpost)
2017-01-24 13:32

Cisco has fixed a vulnerability in its WebEx extension for Chrome that allowed for remote code execution on computers running the plugin.

Apps Carrying HummingBad Variant Booted From Google Play (Threatpost)
2017-01-24 12:00

Google has removed 20 apps from Google Play that were spreading a variant of the HummingBad Android malware called Hummingwhale.

Apple Patches Critical Kernel Vulnerabilities (Threatpost)
2017-01-23 21:35

Apple released updates across its product lines, including iOS 10.2.1, patching a number of critical code execution vulnerabilities in the kernel, libarchive and WebKit.

Secure Email Service Lavabit Relaunches (Threatpost)
2017-01-23 19:51

Lavabit, the secure email provider that suspended operations back in 2013 after the US government asked for its users SSL keys, relaunched Friday under a new architecture.

Heartbleed Persists on 200,000 Servers, Devices (Threatpost)
2017-01-23 18:31

Almost 200,000 servers are still vulnerable to Heartbleed, the OpenSSL vulnerability patched nearly three years ago.