Security News

New Google Tools Help Devs Improve Content Security Policy Protection (Threatpost)
2016-09-27 15:44

Google released CSP Evaluator and CSP Mitigator to aid developers in building better Content Security Policy protections for web applications.

Sofacy APT Targeting OS X Machines with Komplex Trojan (Threatpost)
2016-09-26 21:19

APT gang Sofacy is targeting Mac OS X users with a Trojan that allows an attacker to execute remote commands on infected systems.

Questions Mount Around Yahoo Breach (Threatpost)
2016-09-26 19:58

Crypto company Venafi points out potential holes in Yahoo's processes and policies around cryptography and digital certificates, any of which could have been exploited in the breach to move data...

Hancitor Downloader Abusing APIs, PowerShell Commands (Threatpost)
2016-09-26 18:22

Developers behind the malicious downloader Hancitor have bolstered the malware again, this time with new delivery approaches that make it more difficult to detect.

MarsJoke Ransomware Targets .EDU, .GOV Agencies (Threatpost)
2016-09-26 16:18

Researchers have identified a new ransomware strain that spoofs tracking services via spam messages and contain URLs that link to malicious files.

OpenSSL Fixes Critical Bug Introduced by Latest Update (Threatpost)
2016-09-26 14:45

OpenSSL’s most recent update introduced a critical vulnerability in the crypto library, forcing an emergency update today.

OpenSSL Patches High-Severity OCSP Bug, Mitigates SWEET32 Attack (Threatpost)
2016-09-23 19:47

OpenSSL patched a high-severity vulnerability in its deployment on the Online Certificate Status Protocol, and also mitigated the SWEET32 attack.

Researchers Find ‘Severe’ Password Security Hole with iOS 10 Backups (Threatpost)
2016-09-23 17:32

Security firm claims to have found a new weakness in Apple’s iOS 10 that makes it possible to crack password-protected local backups of data for iOS 10 devices.

Threatpost News Wrap, September 23, 2016 (Threatpost)
2016-09-23 16:59

The massive Yahoo breach, this week's Security of Things Forum, Mamba ransomware, and Google Allo are discussed.

Medical Devices Should Withstand Rigor, Expert Says (Threatpost)
2016-09-23 14:37

In a keynote at the Internet of Things Forum Dr. Kevin Fu said that medical devices should be subjected to rigor so patients can make clinically relevant decisions.