Security News

Facebook, Researcher at Odds Over Messenger Issue (Threatpost)
2017-01-19 15:46

Facebook dismisses a researcher who says multimedia content sent via Facebook Messenger can be intercepted by a third party under certain conditions.

Android Scoring System Roots Out Malicious, Harmful Apps (Threatpost)
2017-01-19 15:00

Google this week explained how it weighs potentially harmful Android apps using the Verify Apps malware scanner and a scoring system it calls Dead or Insecure.

Justine Bone on St. Jude Vulnerabilities and Medical Device Security (Threatpost)
2017-01-19 14:00

MedSec CEO Justine Bone talks to Mike Mimoso about the St. Jude Medical vulnerabilities, the considerations her company and Muddy Waters made in short selling St. Jude stock, and the current state...

Carbanak Using Google Services for Command and Control (Threatpost)
2017-01-18 21:25

Carbanak has surfaced again with new campaigns using Google hosted services such as Forms and Sheets as command and control channels.

Docker Patches Container Escape Vulnerability (Threatpost)
2017-01-18 19:26

Docker has patched a privilege escalation vulnerability that could lead to container escapes, allowing a hacker to affect operations of a host from inside a container.

Oracle Patches 270 Vulnerabilities in Year’s First Critical Patch Update (Threatpost)
2017-01-18 18:26

Oracle patched 270 vulnerabilities, many remotely exploitable, across 45 different products as part of its quarterly Critical Patch Update (CPU) on Tuesday.

Spora Ransomware Offers Victims Unique Payment Options (Threatpost)
2017-01-18 12:00

Researchers are keeping close tabs on a new ransomware strain called Spora that offers victims unique payment options.

New RCE Flaws Found in Samsung Smartcam (Threatpost)
2017-01-17 21:54

Samsung Smartcam devices are vulnerable to remote takeover via a malicious firmware update, researchers with the former GTVHacker group said.

Vulnerabilities Leave iTunes, App Store Open to Script Injection (Threatpost)
2017-01-17 21:02

Researchers say iTunes and Apple's App Store suffer from a persistent input validation and mail encoding web vulnerability. If exploited, it could allow an attacker to inject their own malicious script.

Router Vulnerabilities Disclosed in July Remain Unpatched (Threatpost)
2017-01-17 17:05

Command injection vulnerabilities and accessible default admin credentials in home routers distributed by Thailand’s largest broadband provider remain unpatched despite private disclosures to the...