Security News

Mirai Vulnerability Disclosed, But Exploits May Constitute Hacking Back (Threatpost)
2016-10-28 18:17

A buffer overflow found in the Mirai botnet could eliminate its ability to carry out HTTP flood attacks. But exploiting that vulnerability puts defenders in a gray area with regard to hacking back.

Apple Patches iTunes, iCloud for Windows, Xcode Server (Threatpost)
2016-10-28 15:52

Apple addressed vulnerabilities in iTunes and iCloud for Windows, and Xcode Server on Thursday.

Threatpost News Wrap, October 28, 2016 (Threatpost)
2016-10-28 15:22

Mike Mimoso and Chris Brook recap the news of the week, including the storylines around last week's Dyn DDoS attack, Keen Team winning big again at Pwn2Own, and a fake Windows installer.

Cisco Patches Critical Vulnerability in Facility Events Response System (Threatpost)
2016-10-27 21:31

Cisco warns of 16 flaws in its latest security bulletin, mostly impacting its Cisco AsyncOS software used in its Email Security Appliances.

Microsoft Extends Malicious Macro Protection to Office 2013 (Threatpost)
2016-10-27 20:27

Microsoft announced it has extended a feature in Office 2016 that protects against malicious macros to Office 2013.

Dyn DDoS Could Have Topped 1 Tbps (Threatpost)
2016-10-27 18:48

Analysis by DNS provider Dyn hints that more than 1 terabyte per second of traffic may have been used in last week's massive DDoS attack that impacted Internet service on the East Coast.

Keen Lab Takes Down iPhone 6S, Nexus 6P at Mobile Pwn2Own (Threatpost)
2016-10-27 18:42

Hackers with Keen Team identified vulnerabilities in iOS 10.1 and Android Nougat at Mobile Pwn2Own this week.

Windows Atom Tables Can Be Abused for Code Injection Attacks (Threatpost)
2016-10-27 15:31

Attackers can leverage a design weakness in all versions of Windows to carry out code injection attacks that bypass detection by security software.

Joomla Update Fixes Two Critical Issues, 2FA Error (Threatpost)
2016-10-26 18:19

Joomla fixed two critical issues in the content management system and is strongly encouraging users to update their sites immediately.

Remote Code Execution Vulnerabilities Plague LibTIFF Library (Threatpost)
2016-10-26 16:34

Three vulnerabilities, all which can lead to remote code execution, exist in the LibTIFF library.