Security News

BlackNurse Low-Volume DoS Attack Targets Firewalls (Threatpost)
2016-11-11 14:00

Researchers say BlackNurse attacks are low bandwidth (18Mbps) and can still knock offline many of today’s firewalls.

OpenSSL Patches High-Severity Denial-of-Service Bug (Threatpost)
2016-11-11 12:00

An OpenSSL update released on Thursday patched three vulnerabilities included one rated high severity in TLS connections using the ChaCha20-Poly 1305 ciphersuite.

Signal Audit Reveals Protocol Cryptographically Sound (Threatpost)
2016-11-10 18:39

Academics audited the popular end-to-end encryption app Signal and their findings are encouraging.

Siemens Discloses Local Privilege Escalation Bug in SCADA Gear (Threatpost)
2016-11-10 17:57

Siemens is warning customers of a local privilege escalation vulnerability that leaves over a dozen models of its SCADA equipment open to attack.

Yahoo Tells SEC It Knew About Data Breach in 2014 (Threatpost)
2016-11-10 16:50

Yahoo's latest SEC filing includes confirmation that it knew attackers were on its network in 2014 and stole information on 500 million accounts.

OAuth 2.0 Hack Exposes 1 Billion Mobile Apps to Account Hijacking (Threatpost)
2016-11-10 14:41

Mobile app developers need to be aware of improper OAuth 2.0 implementations that have put one billion mobile apps at risk to takeover.

Phishing Campaign Targets Breach Victims With Locky Ransomware (Threatpost)
2016-11-09 21:53

A phishing campaign is targeting some of the 22 million victims of the massive United States Office of Personnel Management breaches of 2014 and 2015.

Locky Targets OPM Breach Victims (Threatpost)
2016-11-09 21:53

A phishing campaign is targeting some of the 22 million victims of the massive United States Office of Personnel Management breaches of 2014 and 2015.

Google to Red Flag ‘Repeat Offender’ Websites (Threatpost)
2016-11-09 18:05

Google's Safe Browsing program expands to include "Repeat Offender” websites in blacklisting program.

iOS WebView Problem Allows Attackers to Initiate Phone Calls (Threatpost)
2016-11-09 11:00

An issue in iOS WebView that is trivial to exploit can give an attacker the ability to trigger phone calls from a targeted device, researcher Collin Mulliner said.