Threatpost for B2B

Syndicate content
The First Stop For Security News
Updated: 4 hours 44 min ago

EMET, AV Disclosure Leak Plugged in IE

Tue, 09/09/2014 - 13:40
Microsoft patched a disclosure leak in Internet Explorer that revealed whether EMET or other antimalware protections were running on a compromised computer.

Privacy Vulnerabilities in Popular Android Apps Disclosed

Tue, 09/09/2014 - 12:17
Researchers from the University of New Haven have taken to Youtube this week to publicize vulnerabilities in a dozen Android apps, including Instagram, Vine and OKCupid.

Adobe Patches Host of Memory Bugs in Flash Player

Tue, 09/09/2014 - 11:45
Adobe announced security updates and a new version of Flash Player for Windows, Mac and Linux; the company also announced it was postponing a scheduled update for Reader and Acrobat.

Research Finds No Large Scale Heartbleed Exploit Attempts Before Vulnerability Disclosure

Tue, 09/09/2014 - 10:23
In the days and weeks following the public disclosure of the OpenSSL Heartbleed vulnerability in April, security researchers and others wondered aloud whether there were some organizations–perhaps the NSA–that had known about the bug for some time and had been using it for targeted attacks. A definitive answer to that question may never come, but […]

More 1024-Bit Certificates to Be Deprecated in Firefox

Tue, 09/09/2014 - 07:37
When Mozilla released Firefox 32 last week, the company removed several root certificates from the trust store for the browser. The move wasn’t because the certificates were fraudulent or the CAs that issued them were compromised, but because the certificates use 1024-bit keys. This is the first step in a process that Mozilla officials say […]

Google ‘Sunsetting’ Weak SHA-1 Crypto Algorithm

Tue, 09/09/2014 - 07:26
Google has initiated a process to revoke trust from any certificates that rely on the outdated SHA-1crytpographic hash algorithm.

Home Depot Confirms Breach, Transactions From April On At Risk

Mon, 09/08/2014 - 18:23
Home Depot finally confirmed its payment systems have been breached, but offered little further on whether customer personal data was stolen.

Traffic Networks Company Patches Sensor Vulnerabilities

Mon, 09/08/2014 - 14:23
A company in charge of manufacturing sensors used in traffic control systems has patched a series of previously disclosed bugs that could’ve opened the products up to exploits.

New Timing Attack Could De-Anonymize Google Users

Mon, 09/08/2014 - 14:00
A new timing attack has been disclosed that could de-anonymize Google users under particular conditions. Google acknowledged the issue but said it would fix it because the risk is low.

Salesforce Warns Customers of Dyreza Banker Trojan Attacks

Mon, 09/08/2014 - 13:02
Salesforce.com is warning its customers that the Dyreza banker Trojan is now believed to be targeting some of the company’s users. The Trojan, which has the ability to bypass SSL, typically goes after customers of major banks, but seems to be expanding its reach. Dyreza is relatively new among the banker Trojan crowd and it […]

OpenSSL Publishes its Security Policy

Mon, 09/08/2014 - 11:10
The OpenSSL Project yesterday for the first time made the OpenSSL security policy public.

Israeli Think-Tank Site Serves Sweet Orange Exploit

Mon, 09/08/2014 - 10:14
Drive-by malware downloads have been spotted on the website of a prominent Israel think-tank, the Jerusalem Center for Public Affairs. The attacks seems to target bank credentials.

‘Kyle and Stan’ Malvertising Network Targets Windows and Mac Users

Mon, 09/08/2014 - 10:02
A malvertising network that has been operating since at least May has been able to place malicious ads on a number of high-profile sites, including Amazon and YouTube and serves a unique piece of malware to each victim. The network, dubbed Kyle and Stan by the Cisco researchers who analyzed its activities and reach, comprises […]

Mozilla 1024-Bit Cert Deprecation Leaves 107,000 Sites Untrusted

Fri, 09/05/2014 - 14:03
Data compiled from Rapid7's Project Sonar scan found 107,000 websites running 1024-bit CA certificates that will soon be untrusted as Mozilla announces it will no longer support the shorter, weaker keys.

Threatpost News Wrap, September 5, 2014

Fri, 09/05/2014 - 11:05
Dennis Fisher and Mike Mimoso discuss the Apple iCloud mess, extending its 2FA system to the cloud, and the fallout from the possible Home Depot data breach.

Apple Plans to Extend 2FA to iCloud

Fri, 09/05/2014 - 09:34
In the wake of the iCloud photo theft scandal, Apple’s CEO said the company plans to extend its two-factor authentication system to logins to the iCloud service from mobile device. The change will come when iOS 8.0 comes out later this month. The change will give users the option of enabling a second layer of authentication […]

Verizon to Pay Largest Ever Consumer Privacy Settlement

Thu, 09/04/2014 - 14:24
Verizon pays largest ever consumer privacy settlement to the FCC for depriving customers of information about Verizon’s marketing practices and their personal privacy right to opt-out.

Patch Tuesday Includes Another IE Update; Vuln Disclosures Up

Thu, 09/04/2014 - 14:07
Microsoft announced four bulletins are scheduled for the September Patch Tuesday release, along with new research on public vulnerability disclosures.

Feared Home Depot Breach Sparks More Interest in Backoff PoS Malware

Thu, 09/04/2014 - 12:07
Security experts are digging into point-of-sale malware, Backoff in particular, as speculation rages on about how hackers pulled off the Home Depot data breach.

One in Five Massachusetts Residents Breached in 2013

Thu, 09/04/2014 - 12:04
Roughly one in five Massachusetts residents were affected by a data breach last year, according to numbers released today by the Commonwealth.