Security News

ROPEMAKER Exploit Allows for Changing of Email Post-Delivery (Threatpost)
2017-08-23 17:53

An exploit dubbed ROPEMAKER relies on taking advantage of email design functionality, namely by remotely changing CSS in HTML-based emails after they've been sent.

Business Email Compromise Campaign Harvesting Credentials in Numerous Industries (Threatpost)
2017-08-23 17:02

Flashpoint warns of a new business email compromise campaign targeting organizations in various industries with the aim of harvesting credentials.

Neptune Exploit Kit Dropping Cryptocurrency Miners Through Malvertisements (Threatpost)
2017-08-22 21:51

Researchers say the Neptune, or Terror exploit kit has been spreading Monero cryptocurrency miners via malvertisements.

Android Spyware Linked to Chinese SDK Forces Google to Boot 500 Apps (Threatpost)
2017-08-22 17:28

More than 500 Android mobile apps have been removed from Google Play after it was discovered that an embedded advertising SDK called Igenix could be leveraged to quietly install spyware on devices.

Foxit to Fix PDF Reader Zero Days by Friday (Threatpost)
2017-08-22 16:33

Foxit Software says it will fix two vulnerabilities in its PDF reader products that could be triggered through its JavaScript API to execute code.

Fuze Patches TPN Handset Vulnerabilities (Threatpost)
2017-08-22 12:05

VoIP vendor Fuze earlier this year patched three vulnerabilities that exposed user account information and enabled unauthorized authentication.

Industrial Cobots Might Be The Next Big IoT Security Mess (Threatpost)
2017-08-22 12:00

Researchers at IOActive are sounding an early alarm on the security of industrial collaboration robots, or cobots. These machines work side-by-side with people and contain vulnerabilities that...

Facebook Awards $100K to Researchers for Credential Spearphishing Detection Method (Threatpost)
2017-08-21 18:28

Researchers who identified a real-time way to detect credential spearphishing attacks in enterprise settings won $100,000 from Facebook last week.

Meeting and Hotel Booking Provider’s Data Found in Public Amazon S3 Bucket (Threatpost)
2017-08-21 15:13

Personal and business data belonging to Boston area meeting and hotel booking provider Groupize was discovered in a publicly accessible Amazon Web Services S3 bucket, which has since been locked down.

Vendor Exposes Backup of Chicago Voter Roll via AWS Bucket (Threatpost)
2017-08-18 17:55

Voter registration data belonging to the entirety of Chicago’s electoral roll—1.8 million records—was found a week ago in an Amazon Web Services bucket.