Threatpost for B2B

Syndicate content
The First Stop For Security News
Updated: 21 hours 53 min ago

Government Requests for Facebook User Data Increasing

Wed, 11/05/2014 - 13:16
Facebook’s latest transparency report shows that U.S law enforcement agencies requested more user information from the social network in the first six months of this year than ever before.

NSA Director Says Agency Shares Vast Majority of Bugs it Finds

Wed, 11/05/2014 - 11:01
When the National Security Agency discovers a new vulnerability that looks like it might be of use in penetrating target networks, the agency considers a number of factors, including how popular the affected software is and where it’s typically deployed, before deciding whether to share the new bug. The agency shares most of the bugs […]

New Variant of Backoff Malware Tougher to Detect

Tue, 11/04/2014 - 16:15
The new Backoff variant ROM has tweaks that help the malware better evade detection and hinder the analysis process.

AirHopper Program Decodes Radio Signals to Steal from Air-Gapped Computers

Tue, 11/04/2014 - 13:51
Researchers have developed malware called AirHopper that decodes radio frequencies emitted from a computer monitor, video card or cable, in order to steal data from an air-gapped machine.

Hacking Team Defends Spyware, Attacks Researchers’ Methods

Tue, 11/04/2014 - 13:30
Hacking Team joins the choir of critics, including GCHQ and the FBI, rallying against anti-surveillance and privacy advocates, who, they say, aid criminals and terrorists.

Linksys Patches (Most) Routers Running SMART Wi-Fi Firmware

Tue, 11/04/2014 - 10:53
Linksys released updates for routers running its SMART Wi-Fi firmware, patching vulnerabilities leading to credential theft and information disclosure. Two popular models, however, remain unpatched.

Google Releases Nogotofail Tool to Test Network Security

Tue, 11/04/2014 - 10:02
The last year has produced a rogues’ gallery of vulnerabilities in transport layer security implementations and new attacks on the key protocols, from Heartbleed to the Apple gotofail flaw to the recent POODLE attack. To help developers and security researchers identify applications that are vulnerable to known SSL/TLS attacks and configuration problems, Google is releasing a […]

Smartphone Owners Lack Motivation to Adequately Lock Devices

Tue, 11/04/2014 - 09:55
A new study examines how many device owners choose to leave their phones locked versus unlocked – and why.

American Express Brings Tokenization to Payment Cards

Mon, 11/03/2014 - 16:27
American Express announced its new American Express Token Service which brings tokenization to payment card transactions.

BlackEnergy Malware Plug-Ins Leave Trail of Destruction

Mon, 11/03/2014 - 13:27
Researchers at Kaspersky Lab discovered a cache of Windows and Linux plug-ins for the BlackEnergy malware that, in addition to data theft, allow it to target Cisco routers and even destroy hard drives it infects.

Facebook Creates .Onion Site; Now Accessible Via Tor Network

Fri, 10/31/2014 - 10:34
UPDATE - Facebook has entered the hidden services with a new .onion site that will let Tor Network users sign into the world's (second) most populace social network.

Google Working on Tool to Gather Stats While Preserving Privacy

Fri, 10/31/2014 - 09:30
Google is working on a new system that enables the company to collect randomized information about the way that users are affected by unwanted software on their machines, without gathering identifying data about the users. The system is known as RAPPOR (Randomized Aggregatable Privacy-Preserving Ordinal Response) and Google currently is testing it in Chrome. The […]

Android 5.0 Lollipop Upgrades Encryption, Application Control

Thu, 10/30/2014 - 13:12
The Lollipop version of Android enhances its use of SE Linux, bringing application enforcement to the kernel level, and turns on device encryption by default.

AOL Releases Transparency Report, Lobbies for USA FREEDOM Act

Thu, 10/30/2014 - 11:09
AOL claims it received between 0-999 FISA court orders and between 0-999 National Security Letters between January and June in its latest transparency report.

Assume ‘Every Drupal 7 Site Was Compromised’ Unless Patched By Oct. 15

Thu, 10/30/2014 - 08:08
The maintainers of the Drupal content management system are warning users that any site owners who haven't patched a critical vulnerability in Drupal Core disclosed earlier this month should consider their sites to be compromised.

Popular Science Website Infected, Serving Malware

Thu, 10/30/2014 - 06:00
The website of Popular Science magazine was found infecting users with malware via the RIG exploit kit.

Microsoft Plans to Disable SSLv3 in IE, All Online Services

Wed, 10/29/2014 - 13:56
Microsoft is planning to disable support for the weak SSLv3 protocol in Internet Explorer at some undetermined point in the future.

Microsoft Warns of Crowti Ransomware

Wed, 10/29/2014 - 13:20
Researchers with Microsoft have spotted a spike in Crowti, a ransomware similar to Cryptolocker that encrypts files on victims’ machines and then asks for payment to unlock them.

Facebook Open Sources Host Monitoring Tool, Increases Internet Defense Prize

Wed, 10/29/2014 - 12:00
Facebook announced that it has released a host monitoring tool it developed to open source, and that it will increase its Internet Defense Prize payouts to $300,000 in 2015.

Dyreza Banker Trojan Attackers Exploiting CVE-2014-4114 Windows Flaw

Wed, 10/29/2014 - 10:29
The Dyreza Trojan is exploiting the recently disclosed CVE-2014-4114 vulnerability in Windows that was first used by the Sandworm attackers.