Security News

Mobile WireX DDoS Botnet ‘Neutralized’ by Collaboration of Competitors (Threatpost)
2017-08-28 19:44

A large botnet of Android devices called WireX is responsible for large-scale application-layer DDoS attacks against businesses in the hospitality, porn and gambling industries.

Anonymous Messaging App Sarahah to Halt Collection of User Data With Next Update (Threatpost)
2017-08-28 17:27

The anonymous messaging app Sarahah says it plans to remove a feature that uploads users contacts, including phone numbers and email addresses to the company’s servers, in the next update.

Race is On To Notify Owners After Public List of IoT Device Credentials Published (Threatpost)
2017-08-26 12:20

A list of device IPs and credentials has gone viral since Thursday, kicking off an effort by researchers to notify the owners of these connected devices before they're hacked.

Defray Ransomware Seen Targeting Education, Healthcare Industry (Threatpost)
2017-08-25 19:21

Defray, a new, although small strain of ransomware, was spotted by researchers targeting comapnies in the education and healthcare verticals.

Threatpost News Wrap, August 25, 2017 (Threatpost)
2017-08-25 15:30

The news of the week is discussed, including the AWS S3 leaks, Zerodium's bounty on messaging app zero days, Ropemaker, and cobot vulnerabilities.

Cryptocurrency Mining Malware Hosted in Amazon S3 Bucket (Threatpost)
2017-08-25 14:00

Attackers are using an exploit kit to spread the Zminer executable that downloads a cryptocurrency miner hosted in an Amazon S3 bucket.

Security Lacking in Previous AppleAVEDriver iOS Kernel Extension (Threatpost)
2017-08-25 10:00

An obscure Apple kernel extension patched in iOS 10.3.3 was originally built without security measures in place, according to the researcher who privately disclosed the flaws.

Adware Spreading Via Social Engineering, Facebook Messenger (Threatpost)
2017-08-24 18:15

Attackers have taken to Facebook Messenger with a combination of social engineering and malicious JavaScript to spread adware.

Deprecated, Insecure Apple Authorization API Can Be Abused to Run Code at Root (Threatpost)
2017-08-24 14:32

An insecure Apple authorization API is used by numerous popular third-party application installers and can be abused by attackers ro run code as root.

Zerodium Offers $500K for Secure Messaging App Zero Days (Threatpost)
2017-08-23 18:32

Zerodium announced new $500,000 payouts for zero days in secure messaging apps such as Signal, WhatsApp and others.