Security News

Bug Hunters Prefer Communication Over Compensation (Threatpost)
2016-12-15 15:30

Results of a NTIA survey published today show that researchers prefer open communication with vendors over financial compensation when it comes to vulnerability disclosure.

Code Reuse a Peril for Secure Software Development (Threatpost)
2016-12-15 15:00

Open source and third-party software bugs haunt even the best developers’ projects, despite the industry’s best efforts to avoid them.

Yahoo Discloses Data From 1 Billion Accounts Stolen in 2013 (Threatpost)
2016-12-15 00:16

Yahoo disclosed today that attackers in 2013 stole data associated with more than 1 billion accounts. CISO Bob Lord said this incident is "distinct" from a 2014 attack in which 500 million...

Mirai Giving DDoS-as-a-Service Industry a Boost (Threatpost)
2016-12-14 19:12

Activity on a number of Dark Web hacker forums indicates that while people are downloading the Mirai malware source code, they need help setting it up.

Google Discloses Contents of Eight National Security Letters (Threatpost)
2016-12-14 18:57

Google Tuesday disclosed the contents of eight National Security Letters it received between 2010 and 2015, becoming the latest company under reforms afforded by the USA Freedom Act to do so.

Apple Fixes 97 Vulnerabilities Across macOS, iTunes, Safari, iCloud (Threatpost)
2016-12-14 18:04

Apple released a massive update for macOS Sierra on Tuesday to address 72 vulnerabilities in the operating system.

Flash Player Bug An Eavesdropper’s Delight (Threatpost)
2016-12-14 17:21

Details have surfaced on another patched Flash Player flaw that is a potential privacy nightmare.

Law Enforcement Targets Users of DDoS-For-Hire Services (Threatpost)
2016-12-14 12:16

Law enforcement from more than a dozen countries last week carried out a series of operations designed to crack down on DDoS-for-hire services.

Zcash Spurs Rash of Malicious Mining Software (Threatpost)
2016-12-13 22:42

Hackers are mining Zcash cryptocurrency surreptitiously on PCs infected with cleverly named programs such as system.exe, taskmngr.exe and svchost.exe.

Beta Firmware Updates Available for Vulnerable Netgear Routers (Threatpost)
2016-12-13 21:25

Netgear has built beta firmware updates for its Nighthawk routers vulnerable to a command injection attack disclosed last week.