Security News

Rule 41 Opponents Vow to Fight Government’s New Hacking Powers (Threatpost)
2016-12-01 20:17

Opponents of the controversial Rule 41 say they are committed to fighting the government’s expanded powers.

Mozilla Patches Firefox Zero Day Used to Unmask Tor Browser Users (Threatpost)
2016-12-01 17:00

Mozilla released a new version of Firefox on Wednesday to address a zero day vulnerability that was actively being exploited to de-anonymize Tor Browser users.

Gooligan Malware Breaches 1 Million Google Accounts (Threatpost)
2016-12-01 10:00

The Gooligan Android malware steals Google authentication tokens from mobile devices to breach user and corporate accounts.

Microsoft Silently Fixes Kernel Bug That Led to Chrome Sandbox Bypass (Threatpost)
2016-11-30 21:10

Microsoft appears to have silently fixed a two-year-old bug in in Windows Kernel Object Manager that could have allowed for the bypass of privileges in Google's Chrome browser.

Tor Patched Against Zero Day Under Attack (Threatpost)
2016-11-30 17:44

A zero-day vulnerability in Firefox, similar to one created by the FBI in 2013, is actively being exploited in the Tor Project’s anonymizing TorBrowser.

Firefox Scrambles to Patch Zero Day Actively Exploiting Tor Browser (Threatpost)
2016-11-30 17:44

A zero-day vulnerability in Firefox, similar to one created by the FBI in 2013, is actively being exploited in the Tor Project’s anonymizing TorBrowser.

New Cerber Variant Leverages Tor2Web Proxies, Google Redirects (Threatpost)
2016-11-30 12:00

Researchers have discovered that criminals behind the latest Cerber ransomware variant are leveraging Google redirects and Tor2Web proxies in a new and novel way to evade detection.

Netwire RAT is Back, Stealing Payment Card Data (Threatpost)
2016-11-29 20:40

Researchers say they spotted the remote access Trojan Netwire stealing payment card data from one organization.

New Mirai Variant Targets Routers, Knocks 900,000 Offline (Threatpost)
2016-11-29 19:17

Attackers are targeting DSL routers this week with what's being called a potent new variant of the Mirai malware that knocked offline major Internet companies like Twitter and Spotify last month.

PayPal Fixes OAuth Token Leaking Vulnerability (Threatpost)
2016-11-28 20:52

PayPal fixed an issue that could have allowed an attacker to hijack OAuth tokens associated with any PayPal OAuth application. The vulnerability was publicly disclosed on Monday by Antonio Sanso,...