Security News

Threatpost News Wrap, December 8, 2016 (Threatpost)
2016-12-09 14:00

Mike Mimoso and Chris Brook discuss the news of the week, including the latest Linux bug, Sony closing backdoors in cameras, and Google's new open source fuzzer.

Yahoo Mail XSS Bug Worth Another $10K to Researcher (Threatpost)
2016-12-09 13:00

Finnish security researcher Jouko Pynnonen found a second stored cross-site scripting vulnerability in Yahoo Mail in less than a year, both of which earned him $10,000 bug bounties.

Researchers Question Security in AMD’s Upcoming Zen Chips (Threatpost)
2016-12-08 18:22

Two German researchers are calling into question the security afforded by AMD’s Secure Encrypted Virtualization feature debuting in the chip maker's upcoming Zen server chips.

OpenVPN to Undergo Cryptographic Audit (Threatpost)
2016-12-08 17:19

Matthew D. Green, PhD, a well-known cryptographer and researcher at Johns Hopkins University, will carry out an audit of OpenVPN.

New Call to Regulate IoT Security By Design (Threatpost)
2016-12-08 16:27

A D.C. think tank recommends regulations that mandate IoT security by design before attacks infiltrate critical infrastructure, financial and health care organizations.

Old Linux Kernel Code Execution Bug Patched (Threatpost)
2016-12-08 14:15

A local, race condition vulnerability in the af_packet implementation in Linux was patched this week. The bug allows a local attacker to execute code or crash a server.

Solar Power Firm Patches Meters Vulnerable to Command Injection Attacks (Threatpost)
2016-12-08 13:30

Locus Energy has patched 100,000 of its residential and commercial power meters that were vulnerable to command injection attacks and code execution.

Zeus Variant ‘Floki Bot’ Targets PoS Data (Threatpost)
2016-12-07 20:26

Researchers have observed an uptick in attacks against US, Canadian and Brazilian banks and insurance firms using the banking malware Floki Bot.

Buffer Overflow in BSD libc Library Patched (Threatpost)
2016-12-07 19:55

The BSD libc library was updated recently to address a buffer overflow vulnerability that could have allowed an attacker to execute arbitrary code.

Critical Vulnerability Patched in Roundcube Webmail (Threatpost)
2016-12-07 15:00

Open source webmail provider Roundcube was patched against a vulnerability that could be trivially exploited to run code on servers or access email accounts.