Security News

Google Unveils Cryptographic Library Test Suite Wycheproof (Threatpost)
2016-12-19 20:15

Google on Monday announced Project Wycheproof, a collection of unit tests designed to help check for weaknesses in cryptographic algorithms.

Stolen Yahoo Data Sold to Spammers, One Government Client (Threatpost)
2016-12-19 18:42

Experts at InfoArmor said the stolen database of 1 billion Yahoo accounts has been sold multiple times for at least $300,000 each time.

Insecure NAS Device Exposes 350 Ameriprise Investment Accounts (Threatpost)
2016-12-19 17:18

A trove of data belonging to Ameriprise Financial was found earlier this month and included Social Security number, decryption keys and confidential internal company documents.

SQL Injection Attack is Tied to Election Commission Breach (Threatpost)
2016-12-17 14:00

A hacker offered to sell an unpatched system vulnerability in the U.S. Election Assistance Commission website on the Dark Web for “thousands” of dollars.

Remote Code Execution Bug Found in Ubuntu Quantal (Threatpost)
2016-12-16 16:14

A remote code execution bug in Ubuntu Desktop was patched; the vulnerability affected all default installations of Quantal version 12.10 and later.

Nagios Core Patches Root, RCE Vulnerabilities (Threatpost)
2016-12-16 16:00

Nagios Core has been updated to take care of two critical vulnerabilities that can be pinned together to attack servers hosting the open source IT infrastructure monitoring software.

Tales of WordPress Plugin Insecurity Overblown, Researchers Say (Threatpost)
2016-12-16 15:00

The insecurity of WordPress plugins has been well documented, especially over the last year, but in the grand scheme of things, it's not as bad as it seems, experts claim.

Threatpost News Wrap, December 16, 2016 (Threatpost)
2016-12-16 14:00

Mike Mimoso and Chris Brook discuss the news of the week including Yahoo's latest breach announcement, a DDoS-for-hire crackdown, hackers seeking help with Mirai, and some new Adobe patches.

DNSChanger Exploit Kit Hijacks Routers, Not Browsers (Threatpost)
2016-12-15 18:56

An exploit kit called DNSChanger is attacking routers, not browsers, through a malvertising campaign.

Microsoft, Google to Block Flash by Default in Edge, Chrome (Threatpost)
2016-12-15 18:46

Microsoft followed Google's lead and said it will soon block Flash Player by default in the Edge browser.