Security News

Pentagon Subcontractor Inadvertently Leaks 11 Gigs of Sensitive Data (Threatpost)
2017-01-03 20:40

A security researcher claims that data belonging to doctors deployed in the United States Special Operations Command was left unsecured online.

FBI-DHS Report Links Fancy Bear to Election Hacks (Threatpost)
2016-12-30 19:30

Joint report “Grizzly Steppe” implicates Russian hacking group Fancy Bear in U.S. election-related hacking.

PHPMailer, SwiftMailer Updates Resolve Critical Remote Code Execution Vulnerabilities (Threatpost)
2016-12-29 19:20

Critical remote code execution vulnerabilities in PHPMailer and SwiftMailer, libraries used to send emails via PHP, were patched this week.

Threatpost 2016 Year in Review (Threatpost)
2016-12-29 16:30

Threatpost writers recap 2016's biggest news stories, including the proliferation of IoT botnets, ransomware, the FBI vs. Apple story, and more.

Four New Normals for 2017 (Threatpost)
2016-12-28 14:00

Ransomware, insecure connected devices, bug bounties and governments buying bugs: All four ceased to be novelties in 2016; they’re all new normals for cybersecurity.

Android Trojan Switcher Infects Routers via DNS Hijacking (Threatpost)
2016-12-28 09:00

A new Android Trojan, Switcher, uses victims' devices to infect WiFi routers and funnel users of the network to malicious sites.

PHPMailer Bug Leaves Millions of Websites Open to Attack (Threatpost)
2016-12-27 18:22

A critical PHPMailer bug tied to the way websites handle email and feedback forms is leaving millions of websites hosted on popular web-publishing platforms such as WordPress, Drupal and Joomla...

Clever Facebook Hack Reveals Private Email Address of Any User (Threatpost)
2016-12-23 22:19

A bug bounty hunter earned $5,000 for a Facebook hack that allowed him to bypass security protection and access any Facebook user's true email address.

Cisco Warns of Critical Flaw in CloudCenter Orchestrator Systems (Threatpost)
2016-12-23 17:06

Cisco is warning customers of a privilege escalation flaw in Cisco CloudCenter Orchestrator systems that could allow an attacker to gain root privileges on affected systems.

Apple Delays App Transport Security Deadline (Threatpost)
2016-12-23 14:21

Apple extended the deadline of Dec. 31 for developers adopt App Transport Security standards for applications submitted to the App Store.