Security News

NIST Calls for Submissions to Secure Data Against Quantum Computing (Threatpost)
2016-12-22 17:33

NIST has made a public plea for submissions for new crypto algorithms that can stand up against quantum computing and protect data.

Siemens Patches Insufficient Entropy Vulnerability in ICS Systems (Threatpost)
2016-12-22 17:28

German industrial giant Siemens has provided a firmware update addressing software vulnerabilities that are found in a popular line of its Desigo PX industrial control hardware.

Congressional Group Says Encryption Backdoors Are a Bad Idea (Threatpost)
2016-12-22 11:00

Members of the bipartisan encryption working group released a year-end report concluding that encryption backdoor laws would do more harm than good.

New Wave of Hailstorm Spam Pelts Inboxes (Threatpost)
2016-12-21 18:12

Spammers are turning to an old technique known as hailstorm to slip past anti-spam and anti-malware filters to deliver Dridex banking malware and Locky ransomware.

Panasonic, IOActive Clash on Vulnerability Report (Threatpost)
2016-12-21 14:00

Panasonic Avionics has pushed back against research released Tuesday by IOActive disclosing vulnerabilities in in-flight entertainment systems.

Wassenaar Renegotiation Will Be in Trump Administration’s Hands (Threatpost)
2016-12-20 20:34

Now that a proposed revision to the Wassenaar Arrangement has been rejected, it will be up to the Trump administration to decide whether to attempt to renegotiate again.

New Decryptor Unlocks CryptXXX v3 Files (Threatpost)
2016-12-20 15:50

Researchers have neutralized the threat of the latest strain of CryptXXX v.3 ransomware, releasing a decryption tool for unlocking files.

Fraudulent Video Ad Bot Rakes in Close to $5 Million Daily (Threatpost)
2016-12-20 14:00

An cybercrime group from Russia earns $3 million to $5 million daily through defrauding major U.S. websites of video ad revenue.

In-Flight Entertainment System Flaws Put Passenger Data at Risk (Threatpost)
2016-12-20 13:10

IOActive researchers disclosed vulnerabilities in Panasonic Avionics In-Flight Entertainment systems that could be abused to manipulate flight data shown to passengers, or steal their personal information.

ShadowBrokers Dump Came from Internal Code Repository, Insider (Threatpost)
2016-12-19 21:43

Researchers at Flashpoint said their analysis of the latest ShadowBrokers dump of NSA tools leads them to believe an insider with access to a code repository stole the data.