Security News

Sundown Exploit Kit ‘Larger Threat Than People Realize’ (Threatpost)
2016-11-02 11:00

Cisco Talos identified the Sundown exploit kit as an up-and-coming contender that may soon rival RIG in terms of size and volume.

Microsoft Says Russian APT Group Behind Zero-Day Attacks (Threatpost)
2016-11-01 21:50

Microsoft said Russian APT group Sofacy, which has ties to the country’s military intelligence operations, has been using Windows kernel and Adobe Flash zero day vulnerabilities in targeted attacks.

Google to Distrust WoSign, StartCom Certs in 2017 (Threatpost)
2016-11-01 17:58

Google announced Monday that it will distrust certificates issued by WoSign and StartCom when in it ships Chrome 56 in January 2017.

New IoT Botnet Malware Borrows From Mirai (Threatpost)
2016-11-01 16:48

IoT devices are being infected by new DDoS malware called Linux/IRCTelnet that borrows heavily from Aidra, Bashlite and Mirai.

Phony Android Flash Player Installs Banking Malware (Threatpost)
2016-11-01 15:32

Researchers have found a phony Flash Player download for Android that installs banking malware and steals banking credentials.

Google Reveals Windows Kernel Zero Day Under Attack (Threatpost)
2016-10-31 21:00

Google today disclosed the existence of a Windows zero-day vulnerability under attack. The flaw was reported to Microsoft 10 days ago; Microsoft says the disclosure puts users at risk.

Nymaim Dropper Updates Delivery, Obfuscation Methods (Threatpost)
2016-10-31 19:57

A variant of the Nymaim dropper has surfaced, and it includes new delivery methods, obfuscation techniques, and the use of PowerShell to download payloads.

ShadowBrokers Dumps Lists of Equation Group Hacked Servers (Threatpost)
2016-10-31 17:50

The Shadowbrokers dumped lists of hacked servers compromised by the Equation Group and allegedly used in its campaigns.

WhatsApp Blasted by EU Data Protection Group Over Facebook Sharing (Threatpost)
2016-10-31 17:45

The Article 29 Working Party, an EU privacy coalition urges WhatsApp to clarify that user information shared between the company and Facebook is compliant with data protection laws on the books in Europe.

Google to Make Certificate Transparency Mandatory By 2017 (Threatpost)
2016-10-29 10:00

In a move to bolster security for the Chrome browser, Google sets a date for making Certificate Transparency mandatory for website owners.