Security News

Bypassing ASLR in 60 Milliseconds (Threatpost)
2016-10-20 14:31

An academic paper demonstrates a new ASLR bypass executed through a side-channel attack against the branch target buffer in an Intel Haswell CPU.

Mobile Applications Leak Device, Location Data (Threatpost)
2016-10-20 13:48

A study finds risky apps leave mobile devices open to SMS denial-of-service attack and remote SIM card rooting.

FruityArmor APT Group Used Recently Patched Windows Zero Day (Threatpost)
2016-10-20 11:00

The FruityArmor APT group was using one of the Windows zero days patched by Microsoft last week to escape sandboxes and carry out targeted attacks.

Skyping and Typing the Latest Threat to Privacy (Threatpost)
2016-10-19 18:10

A research paper explains how attackers can use recordings of keystroke sounds captured in a Skype conversation to guess what's being typed.

Oracle Fixes 253 Vulnerabilities in Last CPU of 2016 (Threatpost)
2016-10-19 17:39

Oracle fixed 253 vulnerabilities across 76 different products with its quarterly Critical Patch Update.

Adult FriendFinder Vulnerability Leaves Millions Exposed (Threatpost)
2016-10-19 17:12

Security experts are reporting popular adult website Adult FriendFinder has been compromised by hackers who have gained access to the site's backend servers.

Mirai Bots More Than Double Since Source Code Release (Threatpost)
2016-10-19 13:00

Level 3 Communications said the Mirai botnet has recruited close to 500,000 IoT devices since the malware’s source code was released.

FruityArmor APT Group Used Windows Zero Day to Escape Sandboxes (Threatpost)
2016-10-19 11:00

The FruityArmor APT group was using one of the Windows zero days patched by Microsoft last week to escape sandboxes and carry out targeted attacks.

Experts ‘Outraged’ by Warrant Demanding Fingerprints to Unlock Smartphones (Threatpost)
2016-10-18 20:58

Legal scholars say the government is testing the limits of the Fifth Amendment in a landmark search warrant case.

Attackers Hiding Stolen Credit Card Numbers in Images (Threatpost)
2016-10-18 20:14

Researchers say attackers are embedding malicious code in poorly configured Magento sites that hides stolen payment card data in images.