Security News

Hackers Make New Claim in San Francisco Transit Ransomware Attack (Threatpost)
2016-11-28 20:30

The San Francisco Municipal Transport Agency says it has contained a ransomware attack, but now it faces new unsubstantiated claims by attackers who say they have 30GB of the agency’s data.

Uber Portal Leaked Names, Phone Numbers, Email Addresses, Unique Identifiers (Threatpost)
2016-11-23 15:00

Vulnerabilities in UberCENTRAL, a portal used by businesses to facilitate rides, could have leaked the names, phone numbers, email addresses, and unique IDs.

InPage Zero Day Used in Attacks Against Banks (Threatpost)
2016-11-23 14:00

Banks in Asia and Africa have been targeted with exploits for a zero-day vulnerability in InPage publishing software popular in Arabic-speaking nations.

Microsoft Cutting Off SHA-1 Support in February for Edge, IE 11 (Threatpost)
2016-11-22 18:23

Microsoft confirmed Feb. 14, 2017 is the cutoff date for SHA-1 support in its Microsoft Edge and Internet Explorer 11 browsers.

Exploit Code Released for NTP Vulnerability (Threatpost)
2016-11-22 15:30

NTP 4.2.8p9 includes a patch for a vulnerability that could crash ntpd with a single malformed packet.

WordPress Plugins Leave Black Friday Shoppers Vulnerable (Threatpost)
2016-11-22 14:55

Researchers found a third of the top WordPress e-commerce plugins contain severe vulnerabilities tied to XSS cross-site scripting, SQL injection and file manipulation flaws.

DoD Publishes Vulnerability Disclosure Policy (Threatpost)
2016-11-22 13:57

In the wake of the Pentagon and Army bug bounties, the government continues to engage researchers with the publication of the DoD’s vulnerability disclosure program.

Backdoor Found in Firmware of Some Android Devices (Threatpost)
2016-11-21 20:20

Attackers could exploit over-the-air updates in three million Android devices to remotely execute commands with root privileges via a man-in-the-middle (MiTM) attack.

Office 365 Vulnerability Identified Bogus Microsoft.com Email as Valid (Threatpost)
2016-11-21 19:07

An email scam tricked Yandex email recipients into thinking phishing emails were certified legit and from the Microsoft.com domain.

Credentials Accessible in Siemens-Branded CCTV Cameras (Threatpost)
2016-11-21 17:10

A firmware update is available for Siemens-branded IP-based CCTV cameras that patches a vulnerability that puts admin credentials at risk.