Security News

Two New Edge Exploits Integrated into Sundown Exploit Kit (Threatpost)
2017-01-10 16:28

Two recently published proof-of-concept exploits targeted Microsoft Edge were recently integrated into the Sundown Exploit Kit.

MongoDB Attacks Jump From Hundreds to 28,000 In Just Days (Threatpost)
2017-01-09 22:50

Security researchers report a massive uptick in the number of MongoDB databases hijacked and held for ransom.

St. Jude Medical Patches Vulnerable Cardiac Devices (Threatpost)
2017-01-09 22:18

St. Jude Medical patched the Merlin@home Transmitter, addressing flaws made public last year in a controversial disclosure by MedSec Holdings and Muddy Waters.

Hello Kitty Database of 3.3 Million Breached Credentials Surfaces (Threatpost)
2017-01-09 19:41

A database of 3.3 million Hello Kitty users tied to a 2015 breach surfaced over the weekend exposing thousands of minors to potential credential theft.

Gaming Network ESEA Breached, 1.5M Profiles Leaked (Threatpost)
2017-01-09 19:26

Data purportedly belonging to 1.5 million members of the video gaming community ESEA, or the E-Sports Entertainment Association League, was leaked over the weekend.

US Voting Systems Deemed Critical Infrastructure (Threatpost)
2017-01-09 17:46

The Department of Homeland Security has designated the U.S. voting infrastructure as critical infrastructure.

Google Patches Android Custom Boot Mode Vulnerability (Threatpost)
2017-01-06 21:03

IBM's X-Force security team discovers a high-risk vulnerability in the Android platform opening phones up to DoS and elevation of privilege vulnerabilities.

Threatpost News Wrap, January 6, 2017 (Threatpost)
2017-01-06 17:00

Mike Mimoso and Chris Brook discuss the news of the week, including on this week's U.S. Senate Committee on Armed Service hearing, the Burlington Electric 'Hack', FireCrypt, and Security Without Borders.

Experts Warn of Novel PDF-Based Phishing Scam (Threatpost)
2017-01-05 22:05

Security experts are warning of an active phishing campaign that utilizes PDF attachments in a novel ploy to harvest email credentials from victims.

FTC: D-Link Failed to Secure Routers, IP Cameras (Threatpost)
2017-01-05 21:57

The FTC alleged Thursday that D-Link neglected to adequately secure its wireless routers and IP cameras, putting its consumers at risk.