Security News

New Locky Variant ‘IKARUSdilapidated’ Strikes Again (Threatpost)
2017-08-30 18:13

For a second time this month, a Locky ransomware variant called IKARUSdilapidated is part of a calculated phishing attack targeting office workers with fake scanned image attachments.

Siemens Fixes Session Hijacking Bug in LOGO!, Warns of Man-in-the-Middle Attacks (Threatpost)
2017-08-30 17:11

Siemens fixed a session hijacking vulnerability in its LOGO! logic module Wednesday but says a second issue, one that could help facilitate a man-in-the-middle attack, has no fix currently.

Spambot Contains ‘Mind-Boggling’ Amount of Email, SMTP Credentials (Threatpost)
2017-08-30 16:10

Researchers accessed the Onliner spambot and found 711 million records, including email addresses, email and password combinations, and SMTP credentials and configuration files.

Google Reminding Admins HTTP Pages Will Be Marked ‘Not Secure’ in October (Threatpost)
2017-08-29 19:12

Google began sending out notices to site owners this month who haven't yet migrated from HTTP to HTTPS warning them that in October their sites will be marked "NOT SECURE."

Researchers Figure Out How to Blind ISPs from Smart Home Device Traffic (Threatpost)
2017-08-29 19:04

Researchers have come up with a way to blind ISPs and attackers in a man-in-the-middle position to network traffic emanating from smart home devices.

Revamped Nukebot Malware Changes Targets, Adds Functions (Threatpost)
2017-08-29 18:54

Researchers warn a retooled ‘Jimmy’ Nukebot no longer steals bankcard data, rather focuses on avoiding detection as it downloads malicious modules.

Telnet Credential Leak Reinforces Bleak State of IoT Security (Threatpost)
2017-08-29 15:22

The disclosure and recent analysis of thousands of leaked telnet credentials paints a bleak picture of the state of IoT security.

DJI Launches Drone Bug Bounty Program (Threatpost)
2017-08-29 13:41

Drone manufacturer DJI announced Monday it was launching a bug bounty program to reward researchers who find vulnerabilities in its drones.

Fraudulent Donations Lead to Disbanding of Hutchins Legal Defense Fund (Threatpost)
2017-08-28 20:59

A legal defense fund established to ease Marcus Hutchins’ attorney costs has been disbanded after a sizable number of fraudulent donations were discovered.

CEOs Resign from Trump’s Cybersecurity Commission (Threatpost)
2017-08-28 20:50

Eight members of the National Infrastructure Advisory Council resigned last week, citing insufficient attention to the growing threats to the cybersecurity by the Trump Administration.